This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We are seeking an Information Security GRC Analyst - a disciplined professional who understands that rigorous compliance is the bedrock of our ability to serve our members safely. The Information Security GRC Analyst is a pivotal member of the Information Security team, responsible for the integrity of our security frameworks and the maturity of our compliance programs. Your primary focuses will be ensuring our policies and procedures align with SOC2 and HITRUST, administering and maturing the risk management program, and serving as a key stakeholder in the Vendor Risk Management process.
Job Responsibility:
Manage the alignment of internal policies, procedures, and controls with the HITRUST CSF and SOC2
Contribute to the design and implementation of robust security controls across the organization
Collaborate with stakeholders to draft and update information security policies and standards
Act as a primary participant in SOC2 and HITRUST assessments and audits, managing evidence gathering, documentation, and technical interaction with external auditors
Work closely with IT and Security teams to verify that controls are designed correctly and operating effectively
Assist in identifying vulnerabilities and participate in risk assessments for proposed business changes
Facilitate the Vendor Management Program by performing third party risk reviews for a broad range of technology vendors and reporting risk findings to technology stakeholders
Requirements:
Verifiable experience leading or playing a high-level role in a successful Information Security GRC program that encompasses vendor lifecycle management, alignment with compliance frameworks, and risk management
2+ years in Information Security, IT Audit, or a Security GRC role
A strong understanding of networking, operating systems, cloud security, and encryption
An in-depth knowledge of HITRUST CSF and SOC2 and a working knowledge of NIST and ISO 27001
Exceptional written communication skills with the ability to create clear, accurate documentation that stands up to auditor scrutiny
Experience with Jira, Google Workspace, and GRC platforms such as Vanta, Drata, or similar products
What we offer:
Medical, dental and vision insurance
$4,400 annual HSA contribution
Paytient Health Payment Account (HPA)
Monthly lifestyle spending stipend
Five weeks of annual PTO
Week-long fully paid 'summer break' for all employees