Senior GRC Analyst

atAya HealthcareRemoteUS flagUnited StatesFull-timeRiskSenior$105k – $135k/year

Posted 16 hours ago

This is a fully remote position, open to applicants in United States.

📋 Description

• Take ownership of designated GRC projects, compliance deliverables, and process enhancements from initial planning to final execution

• Facilitate the daily operations and ongoing enhancement of Aya’s enterprise GRC initiative

• Develop and refine scalable workflows that convert regulatory and framework requirements into control activities and operational duties

• Assist with ensuring compliance with SOC 2 and ISO/IEC 27001:2022, including readiness assessments, audit preparation, evidence coordination, control testing, auditor support, and remediation tracking

• Establish control ownership, traceability, documentation, and evidence requirements

• Transition manual or spreadsheet-based compliance activities to automated, system-driven processes

• Enhance automated evidence collection, control testing, issue and remediation tracking, dashboards, and reporting

• Conduct reviews of controls, risk assessments, evidence evaluations, and compliance gap analyses

• Oversee remediation efforts, follow up with control owners, identify delivery risks, and escalate issues as necessary

• Create and maintain dashboards, metrics, and reports that communicate compliance status, trends, exceptions, risks, and remediation progress

• Collaborate with ServiceNow platform and engineering teams to develop scalable and maintainable GRC solutions

• Address customer inquiries regarding compliance, security, privacy, and risk in RFPs, due diligence requests, contracts, and meetings

• Work together with Security, IT, Engineering, Finance, Legal, Privacy, Internal Audit, and business stakeholders

• Convert risk and compliance requirements into actionable business guidance

• Lead working sessions, walkthroughs, and discussions with control owners and subject-matter experts

• Identify emerging risks, process dependencies, and long-term improvements in GRC

• Mentor junior analysts and team members through collaboration, knowledge sharing, and examples

• Review work outputs for accuracy, completeness, and adherence to quality standards

• Document process enhancements, design choices, procedures, and lessons learned


⛳️ Requirements

• Minimum of 4 years of experience in Governance, Risk, and Compliance, Information Security, IT Audit, or a related field

• Practical experience in operating or configuring GRC tools such as ServiceNow GRC / IRM, Drata, Vanta, or Hyperproof

• Proven track record of managing GRC projects, compliance deliverables, or process improvement initiatives from planning through execution

• Strong familiarity with SOC 2 or ISO/IEC 27001:2022 standards

• Experience with control design, evidence evaluation, risk assessments, audit support, remediation tracking, or compliance testing

• Background in enhancing manual compliance processes through automation, workflow design, or system-based reporting

• Excellent written and verbal communication skills, with the ability to convey risk and compliance concepts to both technical and non-technical audiences

• Capability to work independently, manage competing priorities, anticipate next steps, and escalate risks proactively

• Experience collaborating across Information Security, IT, Engineering, Legal, Privacy, Finance, Audit, and business teams

• Bachelor’s degree in IT / CS is preferred

• CISA, CISSP (or CISSP Associate), CCSP, ISO 27001 certification, or another relevant security or compliance credential is preferred

• Familiarity with additional security, compliance, AI governance, and privacy frameworks or regulatory requirements, including ISO/IEC 42001, NIST AI RMF, NIST CSF, GDPR/UK GDPR, and CCPA/CPRA, is a plus

• Experience in ServiceNow GRC / IRM implementation, administration, configuration, or integration is preferred

• Proven experience in developing GRC metrics, dashboards, KPIs, or leadership reporting is preferred

• Experience in supporting internal or external audits within a regulated or healthcare-related environment is preferred

• Availability during PST business hours


🏝️ Benefits

• Comprehensive premium medical, dental, life, and vision insurance

• Generous 401(k) matching contributions

• Reimbursement programs

• Discretionary bonuses

• Paid sick leave in compliance with applicable state, federal, and local legislation

• Celebrations and rewards for achieving objectives

• Company-sponsored virtual events, happy hours, and team-building activities

• Birthday treats

• Unlimited DTO (time off)

• Daily virtual yoga, meditation, or boot camp classes

People also viewed

XBOX16 hours ago

Senior Purchase to Pay (P2P) Engagement & Governance Specialist

US flagCalifornia OnlyFull-timeRisk$65.8k – $121.7k/year
ApplyView job
Monarch Money18 hours ago

Senior Security GRC Analyst

US flagUnited States OnlyFull-timeRisk$180k – $215k/year
ApplyView job
XBOX20 hours ago

Senior Purchase to Pay (P2P) Engagement – Governance Specialist

US flagCalifornia OnlyFull-timeRisk$79.4k – $146.8k/year
ApplyView job
Ramboll22 hours ago

Consultant, Climate Risk

US flagVirginia OnlyFull-timeRisk$69.2k – $100.2k/year
ApplyView job
SGS22 hours ago

Fire Risk Assessor

PL flagPoland OnlyFull-timeRisk£42k/year
ApplyView job
Syneos Health1 day ago

Central Risk Manager – Risk Based Central Monitoring

IN flagIndia OnlyFull-timeRisk
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers