
GRC Analyst
Posted 23 hours ago

Posted 23 hours ago
This is a fully remote position, open to applicants in United States.
• Design, configure, and govern control frameworks and risk workflows within the GRC platform.
• Establish and uphold control procedures that are in line with internal policies, HIPAA, HITRUST, PCI, SOC 2, NIST, and other relevant frameworks.
• Develop and sustain control libraries, encompassing narratives, ownership assignments, testing frequency, and evidence requirements.
• Monitor and refresh risk registers, which include risk tracking, scoring, and prioritization.
• Propel automation workflows for control testing, evidence collection, attestations, and remediation.
• Track policy review cycles and ensure documentation is current.
• Lead information security risk assessments in IT, operational, and third-party domains.
• Conduct control walkthroughs and effectiveness testing; document outcomes and identify any gaps.
• Collaborate with internal teams and external auditors during audits and assessments.
• Maintain regulatory documentation and control mappings.
• Prepare reports, dashboards, and metrics regarding control effectiveness, risk status, and compliance gaps.
• Map controls to regulatory and framework requirements to minimize duplicative testing.
• Collect audit evidence, coordinate stakeholder responses, and manage remediation until closure.
• Oversee audit findings, corrective action plans, and remediation timelines within the GRC platform.
• Guide risk assessments, document vulnerabilities and threats, and keep supporting evidence up to date.
• Partner with stakeholders on risk mitigation strategies, their progress, and ownership.
• Develop, monitor, and report on KRIs and KPIs.
• Apply consistent risk-scoring methodologies, including likelihood, impact, and residual-risk calculations.
• Escalate significant risks and control deficiencies to management and governance committees.
• Lead the lifecycle management of information security policies, procedures, standards, and guidelines.
• Direct policy review and approval workflows.
• Evaluate third-party vendors for security and compliance risks.
• Track vendor risk assessments, reassessment cycles, and risk ratings.
• Develop and oversee vendor remediation action plans.
• Support risk reviews during vendor onboarding and offboarding.
• Enhance GRC processes and workflows through automation and integration.
• Keep abreast of GRC industry trends, emerging threats, and best practices.
• Guide program assessments and maturity benchmarking.
• Perform other assigned duties.
• Bachelor's degree in information security, cybersecurity, computer science, information technology, business administration, or a closely related field required; equivalent experience may be accepted in place of a degree.
• 4+ years of relevant experience in information security, compliance, or GRC may replace the degree requirement.
• Minimum of 5 years of pertinent experience in governance, risk, and compliance functions within IT or information security.
• Experience with AuditBoard (currently named Optro) is highly preferred.
• CISA certification is preferred.
• CRISC certification is preferred.
• CISM certification is preferred.
• Other relevant certifications, such as CompTIA Security+ or ISO 27001 Lead Auditor, are preferred.
• Prior experience in implementing, managing, or auditing security policies and procedures is required.
• Familiarity with HIPAA, NIST CSF, SOC 2, HITRUST, and other compliance frameworks is essential.
• Previous experience conducting risk assessments and supporting risk management activities is important.
• Excellent written and verbal communication skills are necessary, including the ability to convey technical concepts and compliance requirements to both technical and non-technical stakeholders.
• Ability to manage multiple priorities, work independently, and collaborate across cross-functional teams is crucial.
• Must reside in the United States; USAP does not hire candidates residing in California, Hawaii, or Alaska.
• Annual bonus eligibility; bonuses are determined by company and individual performance and are not guaranteed.
• Reasonable accommodations for individuals with disabilities.
• Equal employment opportunity protections.
US Anesthesia Partners
Tessera Labs
Knowledge Services
Get handpicked remote jobs straight to your inbox weekly.