GRC Analyst

atUS Anesthesia PartnersRemoteUS flagUnited StatesFull-timeRiskMid-levelSenior$80.9k – $137.6k/year

Posted 21 hours ago

This is a fully remote position, open to applicants in United States.

📋 Description

• Design, configure, and oversee control frameworks and risk workflows within the GRC platform.

• Establish and uphold control procedures that align with internal policies, HIPAA, HITRUST, PCI, SOC 2, NIST, and other relevant frameworks.

• Develop and maintain control libraries, which include narratives, ownership assignments, testing frequency, and evidence requirements.

• Monitor and revise risk registers, covering risk tracking, scoring, and prioritization.

• Propel automation for control testing, evidence collection, attestations, and remediation processes.

• Track policy review cycles and ensure documentation is current.

• Lead information security risk assessments across IT, operational, and third-party domains.

• Conduct control walkthroughs and tests of operating effectiveness; document results and identify control gaps.

• Collaborate with internal teams and external auditors during audits and assessments.

• Maintain control mappings and compliance documentation.

• Prepare reports, dashboards, and metrics on control effectiveness, risk status, and compliance gaps.

• Assist in internal and external audits by gathering evidence, coordinating responses, and tracking remediation efforts.

• Manage audit findings, corrective action plans, and remediation timelines.

• Guide risk assessments and document vulnerabilities, threats, findings, and supporting evidence.

• Partner with stakeholders on risk mitigation strategies while tracking progress and ownership.

• Develop, monitor, and report on KRIs and KPIs.

• Apply risk scoring methodologies, including likelihood, impact, and residual risk calculations.

• Escalate significant risks and control deficiencies to management and governance committees.

• Oversee the development and lifecycle management of information security policies, procedures, standards, and guidelines.

• Direct policy review and approval workflows.

• Assess third-party vendors for security and compliance risks, utilizing SOC reports, security questionnaires, and contracts.

• Track vendor risk assessments, reassessment cycles, and risk ratings.

• Develop and monitor vendor remediation action plans.

• Support risk reviews for vendor onboarding and offboarding.

• Enhance GRC processes and workflows.

• Monitor industry trends, emerging threats, and GRC best practices.

• Advocate for automation and integration initiatives.

• Guide program assessments and maturity benchmarking.

• Perform additional assigned duties.


⛳️ Requirements

• A Bachelor’s degree in information security, cybersecurity, computer science, information technology, business administration, or a closely related field is required; equivalent experience may substitute for a degree.

• A minimum of 5 years of relevant experience in governance, risk, and compliance functions within IT or information security.

• Experience with AuditBoard (now known as Optro) is highly preferred.

• CISA certification is preferred.

• CRISC certification is preferred.

• CISM certification is preferred.

• Other relevant certifications, such as CompTIA Security+ or ISO 27001 Lead Auditor, are preferred.

• Previous experience in implementing, managing, or auditing security policies and procedures is required.

• Familiarity with HIPAA, NIST CSF, SOC 2, HITRUST, and other compliance frameworks is essential.

• Prior experience conducting risk assessments and supporting risk management activities is necessary.

• Exceptional written and verbal communication skills, encompassing the ability to convey technical concepts and compliance requirements to both technical and non-technical stakeholders.

• Ability to juggle multiple priorities, work independently, and collaborate across cross-functional teams.

• Must be a resident of the United States; US Anesthesia Partners does not employ candidates residing in California, Hawaii, or Alaska.


🏝️ Benefits

• Eligibility for an annual bonus (not guaranteed; contingent on company and individual performance).

• Reasonable accommodations for individuals with disabilities.

People also viewed

Tessera Labs21 hours ago

Technical GRC Analyst – Compliance & Assurance

BR flagBrazil OnlyFreelanceRisk$50k – $60k/year
ApplyView job
US Anesthesia Partners23 hours ago

GRC Analyst

US flagUnited States OnlyFull-timeRisk$80.9k – $137.6k/year
ApplyView job
dv011 day ago

Data Governance Lead

US flagUnited States OnlyFull-timeRisk$190k – $220k/year
ApplyView job
Knowledge Services1 day ago

Data Governance Training, Adoption & Literacy Coordinator

US flagNorth Dakota OnlyFreelanceRisk
ApplyView job
ICON plc1 day ago

Risk Surveillance Lead

GB flagUnited Kingdom, +2 more countriesFull-timeRisk
ApplyView job
Raona1 day ago

Consultor/a de Adopción y Gobernanza de IA

AR flagArgentina OnlyFull-timeRisk
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers