
Senior Risk Management Analyst
Posted 21 hours ago

Posted 21 hours ago
This is a fully remote position, open to applicants in United States.
• Take charge of and enhance the enterprise risk register, providing an organization-wide perspective on risk that is distinct from the cyber risk register.
• Refine the enterprise risk appetite statement and implement it in business decisions throughout the organization.
• Manage and expand the ERM policy along with the enterprise risk assessment methodology; conduct assessments and ensure accountability among designated risk owners.
• Communicate the enterprise risk posture to executive leadership and the Enterprise Risk Committee.
• Generate risk assessment and governance documentation across the control framework portfolio, which includes SOC 2, HITRUST, HIPAA, and NIST CSF 2.0.
• Establish a reporting schedule for the security program portfolio and proactively identify delivery risks before deadlines are missed.
• Maintain a multi-year security risk-reduction roadmap and provide updates on progress.
• Oversee the security organization’s OKRs from definition through measurement and reporting.
• Monitor critical dependencies and drive priority initiatives to successful completion.
• Manage the security awareness program.
• Handle property and casualty renewals, claims, certificates of insurance, carrier audits, and insurance requirements outlined in customer contracts.
• Broaden second-line risk coverage into pharmacy, financial, and clinical risk in collaboration with domain owners.
• Coordinate with the third-party risk and resilience owner to ensure vendor and concentration risks are incorporated into the enterprise risk register.
• Automate routine tasks related to register maintenance, assessment intake, evidence collection, and reporting.
• Perform additional duties as assigned.
• Over 10 years of experience in information security, risk management, or Governance, Risk, and Compliance (GRC).
• Proven track record of owning a governance, risk, and compliance program or an enterprise risk program, encompassing registers, policies, and assessment methodologies.
• Experience in maintaining a multi-year risk-reduction roadmap and reporting on its progress.
• Hands-on experience with risk and control self-assessment (RCSA) or a similar enterprise risk assessment methodology that you have executed.
• Proficiency in authoring and presenting risk reports to executives and boards or similar governing bodies.
• History of holding stakeholders across different teams accountable to their commitments without direct authority.
• Program experience with SOC 2, HITRUST, HIPAA, NIST CSF, or a comparable control framework.
• Experience as the first individual dedicated full-time to a function, operating independently without a dedicated team or budget line.
• CRISC, CISA, CISSP, or equivalent certification is preferred.
• Experience in healthcare settings involving sensitive data is preferred.
• Familiarity with agentic AI systems designed to automate governance intake, evidence collection, or reporting is preferred.
• Direct involvement in SOC 2, HITRUST, or HIPAA assurance cycles is preferred.
• Development of a security awareness program from inception is preferred.
• Experience in the ownership or administration of a GRC platform is preferred.
• Medical, Dental, and Vision plans
• Flexible Spending/Health Savings Accounts
• Flexible PTO
• 401(k) + Company Match
• Life Insurance
• Pet insurance
AireSpring
Valiant Solutions
TD
Valiant Solutions
Get handpicked remote jobs straight to your inbox weekly.