
GRC/IT Compliance Analyst
Posted Aug 14

Posted Aug 14
This is a fully remote position, open to applicants in California, +5 more states.
• Develop and implement a new enterprise risk assessment platform to enhance compliance workflows.
• Regularly monitor and update the risk platform to address changing threats and regulatory standards.
• Engage in risk analysis and feature development activities to proactively pinpoint risks associated with regulated products.
• Consistently assess and review internal controls for opportunities for enhancement.
• Perform user access audits for applications and services.
• Periodically evaluate policies and procedures to ensure adherence to best practices and compliance frameworks.
• Assist in managing and drafting documents for FDA regulatory submissions.
• Collaborate closely with Information Security leadership and cross-functional teams to advance GRC initiatives and guarantee ongoing monitoring of security controls.
• Report directly to the Director of Information Security.
• 5–7 years of experience in security or compliance analysis, IT risk assessment, risk management, or IT/IS general-controls assurance/advisory.
• BS degree in Management Information Systems, Computer Science, Accounting with ITGC experience, Engineering, Cybersecurity, Bio-Medical Engineering, or a related discipline.
• Experience with GRC software implementation.
• Knowledge of FDA regulatory submissions and SaMD regulations.
• Familiarity with enterprise risk management frameworks, risk identification, and qualitative/quantitative risk assessment methodologies.
• Previous experience in a startup environment.
• Experience in Agile/Scrum settings and integrating security/compliance within the SDLC.
• Strong comprehension of internal controls necessary for ISO 27001, HITRUST, and SOC 2 compliance frameworks.
• Exceptional verbal and written communication skills for addressing security matters with internal stakeholders.
• CISA, CISM, CISSP, CRISC, or similar certifications are advantageous.
• Experience in the digital healthcare sector is a plus.
• Familiarity with open-source GRC tools such as CISO Advisor or Eramba is a bonus.
• Eligible for a XX% target annual bonus.
• Stock options.
• Paid benefits.
• Employee perks.
• Remote work arrangement.
• Access to Cleerly offices in Denver, Colorado; New York, New York; Dallas, Texas; and Lisbon, Portugal.
• Travel opportunities for some team meetings and cross-functional projects.
Johnson & Johnson
Vynca
Johnson & Johnson
Empower
Get handpicked remote jobs straight to your inbox weekly.