Senior Lead Information Security Governance, Risk, and Compliance (GRC) Analyst

🕒 2 days ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of US Anesthesia Partners

US Anesthesia Partners

5001 - 10000 employees

Founded 2012

💼 Consulting

🏥 Healthcare

⚕️ Healthcare Insurance

Consulting • Healthcare • Healthcare Insurance

US Anesthesia Partners is a leading provider of comprehensive anesthesia services, dedicated to delivering exceptional patient care and operational excellence. Founded by a team of forward-thinking anesthesiologists, USAP specializes in various anesthesiology areas including cardiovascular care, obstetrics, and pediatrics. With a network of thousands of clinicians and hundreds of facility partners across the nation, they serve over two million patients annually, aiming to redefine the standards of quality in anesthesia services.

📋 Description

• Lead the design, configuration, and governance of control frameworks and risk workflows within the GRC platform, ensuring alignment with organizational objectives and compliance requirements. • Establish and maintain enterprise control procedures, ensuring alignment with relevant frameworks (Internal Policy, HIPAA, HITRUST, PCI, SOC 2, NIST, and other applicable frameworks). • Oversee the development and maintenance of control libraries, including control narratives, ownership assignments, testing frequency, and evidence requirements. • Monitor and update risk registers, ensuring accurate tracking, scoring, and prioritization of risks within the platform. • Drive automation workflows to streamline control testing, evidence collection, attestations, and remediation processes. • Track policy review cycles and ensure documentation remains current with regulatory and business changes. • Lead and maintain information security risk assessments across IT, operational, and third-party domains. • Perform control walkthroughs and operating effectiveness testing; documents results and identifies control gaps. • Collaborate with internal teams and external auditors to facilitate audits and assessments using the GRC platform for evidence management, issue tracking, and reporting. • Ensure ongoing compliance with regulatory requirements and industry standards by maintaining up-to-date documentation and control mappings. • Prepares and presents reports, dashboards, and metrics on control effectiveness, risk status, and compliance gaps. • Maps controls to applicable regulatory and framework requirements, identifying overlaps to reduce duplicative testing. • Supports internal and external audits by gathering evidence, coordinating stakeholder responses, and tracking remediation through closure. • Tracks and manages audit findings, corrective action plans (CAPs), and remediation timelines within the GRC platform. • Guides risk assessments to identify potential vulnerabilities and threats, documenting findings and supporting evidence in the GRC platform. • Partners with stakeholders to develop and implement risk mitigation strategies, tracking progress and ownership within the platform. • Develops, monitors, and reports on key risk indicators (KRIs) and key performance indicators (KPIs) to proactively identify and address emerging risks. • Maintains and applies consistent risk scoring methodologies, including likelihood, impact, and residual risk calculations. • Escalates significant risks and control deficiencies to management and governance committees, providing recommendations for mitigation and improvement, in a timely manner. • Leads the development, maintenance, and lifecycle management of information security policies, procedures, standards, and guidelines. • Directs policy review and approval workflows with policy owners and stakeholders. • Ensures policies remain aligned with evolving regulatory requirements and organizational changes. • Leads evaluations of third-party vendors for security and compliance risks, including review of SOC reports, security questionnaires, and contractual requirements. • Tracks vendor risk assessments, reassessment cycles, and risk ratings within the GRC platform. • Works with business owners to develop and monitor vendor remediation action plans. • Supports vendor onboarding and offboarding risk reviews, ensuring appropriate due diligence is documented. • Identifies opportunities to enhance GRC processes and workflows to improve efficiency, accuracy, and effectiveness. • Stays current on industry trends, emerging threats, and best practices in GRC, recommending improvements to the security and compliance program. • Champions automation and integration initiatives to reduce manual effort. • Guides periodic program assessments and maturity benchmarking to guide roadmap priorities. • Performs other duties and responsibilities as assigned.

🎯 Requirements

• Bachelor’s degree in information security, cybersecurity, computer science, information technology, business administration, or a closely related field required. • Equivalent experience may be considered in lieu of a degree (e.g., 4+ years of relevant experience in information security, compliance, or GRC roles). • Minimum of 8 years’ relevant experience in governance, risk, and compliance functions within IT or information security. • Certified Information Systems Auditor (CISA) preferred. • Certified Risk and Information Systems Control (CRISC) preferred. • Certified Information Security Manager (CISM) preferred. • Other relevant certifications (e.g., CompTIA Security+, ISO 27001 Lead Auditor) preferred. • Prior experience implementing, managing, or auditing security policies and procedures. • Familiarity with compliance frameworks (HIPAA, NIST CSF, SOC 2, HITRUST, etc.). • Prior experience conducting risk assessments and supporting risk management activities. • Excellent written and verbal communication skills, including the ability to communicate technical concepts and compliance requirements to both technical and non-technical stakeholders. • Ability to manage multiple priorities, work independently, and collaborate effectively across cross-functional teams.

🏖️ Benefits

• This position is eligible for an annual bonus. Bonuses are not guaranteed and are awarded based on company and individual performance.

Apply Now

Similar Jobs

🕒 5 days ago

Nightingale Education Group

11 - 50

🏥 Healthcare

💼 Consulting

📚 Education

Senior Analyst, Cybersecurity responsible for monitoring events and vendor risk management for Nightingale College. Supporting the improvement of security processes and compliance controls in cybersecurity operations.

🕒 5 days ago

Alvaria Inc

1001 - 5000

🤝 B2B

📡 Telecommunications

🏥 Healthcare

Cybersecurity Analyst responsible for day-to-day internal security operations and SaaS posture management at Aspect. Overseeing incident coordination and security governance in a remote setting.

🕒 5 days ago

Guidehouse

10,000+ employees

🏥 Healthcare

🎖️ Defense

📦 Logistics

IT Audit & Compliance Analyst ensuring compliance with federal cybersecurity frameworks at large federal agency. Coordinating audits and preparing assessor-ready documentation for IT systems.

🕒 5 days ago

Sysco

10,000+ employees

📦 Logistics

🏥 Healthcare

🏨 Hospitality

Senior Analyst managing Workday Functional Security processes at Sysco. Ensure compliance and risk management while supporting HR operational objectives.

🕒 5 days ago

NVIDIA

10,000+ employees

🏥 Healthcare

🏭 Manufacturing

🤖 Artificial Intelligence

Cyber Security Analyst with expertise in incident response and cloud security at NVIDIA. Leading investigations and strengthening security posture against sophisticated cyber threats.