Senior Security and Compliance Analyst

Job not on LinkedIn

September 9

Apply Now
Logo of CertifyOS

CertifyOS

Healthcare Insurance • SaaS • Compliance

CertifyOS is a company that provides advanced provider data technology solutions to transform healthcare management. Their platform aims to modernize the end-to-end provider data infrastructure by offering services such as real-time provider data verification, credentialing, monitoring, and compliance management. By eliminating manual workflows, CertifyOS increases the speed, efficiency, and accuracy of data processes, ultimately reducing operating expenses for their clients, which include health plans, health systems, and digital health companies. CertifyOS emphasizes transparency and real-time insights, offering an easy-to-use experience backed by strong customer support.

51 - 200 employees

⚕️ Healthcare Insurance

☁️ SaaS

📋 Compliance

💰 $14.5M Series A on 2022-09

📋 Description

• Perform risk assessments, vendor due diligence, and control gap analysis • Develop and enforce security policies, standards, and procedures • Collaborate with engineering, IT, and business teams to remediate security risks • Support internal and external audits (SOC 2, ISO 27001, HIPAA, HITRUST, GDPR, CCPA) • Maintain evidence repositories and ensure timely submission for audits using tools like Drata • Track and close compliance gaps and audit findings • Monitor and report on compliance posture to management • Conduct security awareness training for employees • Drive third‑party risk management activities • Work with IT and Cloud teams to implement and validate security controls across AWS, Azure, and GCP • Monitor IAM, DLP, and SIEM systems • Review security configurations and provide recommendations for improvement • Manage workflows and remediation tasks via tools like Jira

🎯 Requirements

• Bachelor’s degree in Information Security, Computer Science, or related field (or equivalent experience) • 5–8 years of experience in information security, risk management, or compliance • Strong background in security governance, risk, and compliance (GRC) and hands-on experience implementing security controls across cloud and enterprise environments • Strong knowledge of security frameworks: NIST CSF, ISO 27001, CIS Controls, SOC 2 • Experience with regulatory compliance requirements: HIPAA, GDPR, CCPA, HITRUST • Hands-on experience with security tools (SIEM, DLP, IAM, CASB) • Experience with cloud platforms and security centers: AWS, Microsoft Azure, Google Cloud Platform (e.g., Google Cloud Security Command Center) • Experience performing risk assessments, vendor due diligence, and control gap analysis • Experience supporting internal and external audits and maintaining evidence repositories (e.g., using Drata) • Experience managing workflows and remediation tasks via tools like Jira • Excellent communication and documentation skills • Relevant certifications preferred: CISSP, CISA, ISO 27001 LA/LI, CCSK

Apply Now

Similar Jobs

August 22

Cloud Network Security Engineer at Revvity; secures AWS cloud networks and endpoints, collaborates across IT teams.

Ansible

AWS

Cloud

Firewalls

Switching

Terraform

July 30

SOC Analysts at AHEAD are responsible for incident detection and reporting in customer environments. They utilize strong technical skills to resolve security-related issues.

Cloud

Linux

TCP/IP

July 28

Provide guidance on Hybrid Cloud security operations and oversee security incident response as a Cloud Security Engineer.

AWS

Azure

Cloud

Cyber Security

Google Cloud Platform

ITSM

June 29

Lead software security architecture initiatives at Hyland Software to safeguard products and services.

AWS

Cloud

Java

Python

Ruby

Switching

Built by Lior Neu-ner. I'd love to hear your feedback — Get in touch via DM or support@remoterocketship.com