
GRC Analyst
Posted 21 hours ago

Posted 21 hours ago
This is a fully remote position, open to applicants in United States.
• Design, configure, and oversee control frameworks and risk workflows within the GRC platform.
• Establish and uphold control procedures that align with internal policies, HIPAA, HITRUST, PCI, SOC 2, NIST, and other relevant frameworks.
• Develop and maintain control libraries, which include narratives, ownership assignments, testing frequency, and evidence requirements.
• Monitor and revise risk registers, covering risk tracking, scoring, and prioritization.
• Propel automation for control testing, evidence collection, attestations, and remediation processes.
• Track policy review cycles and ensure documentation is current.
• Lead information security risk assessments across IT, operational, and third-party domains.
• Conduct control walkthroughs and tests of operating effectiveness; document results and identify control gaps.
• Collaborate with internal teams and external auditors during audits and assessments.
• Maintain control mappings and compliance documentation.
• Prepare reports, dashboards, and metrics on control effectiveness, risk status, and compliance gaps.
• Assist in internal and external audits by gathering evidence, coordinating responses, and tracking remediation efforts.
• Manage audit findings, corrective action plans, and remediation timelines.
• Guide risk assessments and document vulnerabilities, threats, findings, and supporting evidence.
• Partner with stakeholders on risk mitigation strategies while tracking progress and ownership.
• Develop, monitor, and report on KRIs and KPIs.
• Apply risk scoring methodologies, including likelihood, impact, and residual risk calculations.
• Escalate significant risks and control deficiencies to management and governance committees.
• Oversee the development and lifecycle management of information security policies, procedures, standards, and guidelines.
• Direct policy review and approval workflows.
• Assess third-party vendors for security and compliance risks, utilizing SOC reports, security questionnaires, and contracts.
• Track vendor risk assessments, reassessment cycles, and risk ratings.
• Develop and monitor vendor remediation action plans.
• Support risk reviews for vendor onboarding and offboarding.
• Enhance GRC processes and workflows.
• Monitor industry trends, emerging threats, and GRC best practices.
• Advocate for automation and integration initiatives.
• Guide program assessments and maturity benchmarking.
• Perform additional assigned duties.
• A Bachelor’s degree in information security, cybersecurity, computer science, information technology, business administration, or a closely related field is required; equivalent experience may substitute for a degree.
• A minimum of 5 years of relevant experience in governance, risk, and compliance functions within IT or information security.
• Experience with AuditBoard (now known as Optro) is highly preferred.
• CISA certification is preferred.
• CRISC certification is preferred.
• CISM certification is preferred.
• Other relevant certifications, such as CompTIA Security+ or ISO 27001 Lead Auditor, are preferred.
• Previous experience in implementing, managing, or auditing security policies and procedures is required.
• Familiarity with HIPAA, NIST CSF, SOC 2, HITRUST, and other compliance frameworks is essential.
• Prior experience conducting risk assessments and supporting risk management activities is necessary.
• Exceptional written and verbal communication skills, encompassing the ability to convey technical concepts and compliance requirements to both technical and non-technical stakeholders.
• Ability to juggle multiple priorities, work independently, and collaborate across cross-functional teams.
• Must be a resident of the United States; US Anesthesia Partners does not employ candidates residing in California, Hawaii, or Alaska.
• Eligibility for an annual bonus (not guaranteed; contingent on company and individual performance).
• Reasonable accommodations for individuals with disabilities.
Tessera Labs
US Anesthesia Partners
Knowledge Services
Get handpicked remote jobs straight to your inbox weekly.