
Senior Security Compliance Analyst
Posted Jun 20

Posted Jun 20
This is a fully remote position, open to applicants in United States.
• Lead and facilitate customer security audits, addressing security questionnaires and showcasing compliance with various security frameworks.
• Organize, coordinate, and oversee ISO 27001 audits, which include evidence collection, control implementation, and engagement with auditors.
• Maintain ongoing compliance with HIPAA, NIST CSF, and other regulatory standards relevant to healthcare data security.
• Create and uphold policies, procedures, and security documentation to satisfy regulatory and contractual obligations.
• Conduct gap analyses and risk assessments to pinpoint and address compliance risks.
• Oversee and enhance security governance frameworks, ensuring they align with industry best practices and business objectives.
• Execute third-party vendor risk assessments to ensure adherence to security policies and contractual commitments.
• Supervise security controls, ensuring their effectiveness and continuous enhancement in line with security frameworks.
• Assist in security awareness training initiatives, making certain that employees comprehend their compliance responsibilities.
• Keep updated on ISO 27001, HIPAA, NIST 800-53, and other pertinent standards, converting them into actionable security controls.
• Support in defining security metrics and reporting compliance status and risk posture to leadership.
• Collaborate closely with legal, security, IT, and business teams to ensure alignment of compliance requirements with security operations.
• A minimum of a Bachelor's degree in Information Security, Computer Science, Risk Management, or a related field (or equivalent experience).
• At least 8+ years of progressive experience in Governance, Risk, and Compliance (GRC), compliance, or security audit roles.
• Experience in the healthcare sector or regulated industries is highly preferred.
• Preferred certifications include: ISO 27001 Lead Auditor/Implementer, CISSP, CISM, CISA, HITRUST CCSFP, CRISC.
• Proven experience leading ISO 27001, SOC2, or HITRUST audits, which includes ISMS implementation and coordination of external audits.
• Strong understanding of NIST CSF, SOC 2, GDPR, and various other security frameworks.
• Practical experience with customer security audits, including responding to security questionnaires and managing security assessments.
• Ability to conduct risk assessments, policy reviews, and compliance gap analyses.
• Excellent written and verbal communication skills, with the capacity to convey technical concepts to non-technical audiences.
• Detail-oriented, possessing outstanding organizational and project management skills.
• Capability to work both independently and collaboratively in a remote setting.
• Familiarity with GRC tools (e.g., OneTrust, LogicGate, Archer, Vanta, Drata) is advantageous.
• Competitive salary and performance-based bonuses.
• Comprehensive health, dental, and vision insurance.
• Flexible working hours and remote work options.
• Opportunities for professional development and certification reimbursement.
• A supportive and inclusive work environment.
Proficio
Compass
CyberSheath
StarTekk
Get handpicked remote jobs straight to your inbox weekly.