GRC Analyst, Federal Programs

🕒 il y a 1 mois

🇺🇸 États-Unis – Télétravail

💵 $101 500 - $159 500 / an

⏰ Temps Plein

🟡 Intermédiaire

🟠 Senior

🚔 Conformité

🗣️🇺🇸🇬🇧 Anglais requis

Postuler Maintenant
Trouver des Emplois à Distance Similaires

📊 Vérifiez votre score de CV pour ce poste

Améliorez vos chances d'obtenir un entretien en vérifiant votre score de CV avant de postuler.

Logo of Sword Health

Sword Health

201 - 500 employés

Fondée en 2015

⚕️ Assurance santé

🤖 Intelligence artificielle

🧘 Bien-être

Healthcare Insurance • Artificial Intelligence • Wellness

Sword Health est une entreprise de santé numérique qui combine l'intelligence artificielle et l'expertise clinique pour fournir des soins de classe mondiale pour les affections musculo-squelettiques, articulaires et pelviennes. En proposant de la physiothérapie numérique et des soins pilotés par l'IA, Sword aide les individus à se remettre de leurs maladies physiques depuis le confort de leur domicile, évitant ainsi les chirurgies et réduisant le besoin de médicaments. L'entreprise fournit aux employeurs, aux régimes de santé, et aux particuliers des plans de traitement personnalisés qui sont rentables et ont prouvé leur efficacité en matière de réduction de la douleur et d'amélioration de la productivité. Sword Health s'engage à élargir l'accès à des soins de haute qualité et à assurer l'équité en matière de santé dans les communautés mondiales.

Description

• Serve as a member of Sword's GRC team, contributing to security compliance across all products and services, with primary ownership of federal programs; • Define and maintain the CMMC assessment boundary, working across infrastructure, engineering, and business teams to ensure the scope is accurate and defensible; • Map NIST SP 800-171 practices to Sword's current environment and produce a clear, evidence-based gap analysis; • Translate identified gaps into prioritized remediation tasks with clear ownership, for audiences ranging from DevOps engineers to clinical operations managers; • Build and maintain the System Security Plan (SSP), Plan of Action and Milestones (POA&M), and all artifacts required for assessment; • Serve as Sword's primary interface with the C3PAO and assessment team during formal CMMC assessments; • Drive FedRAMP readiness in parallel, including control documentation, evidence collection, and continuous monitoring; • Contribute to audits and compliance activities across other active frameworks, including SOC 2 and HITRUST, as part of Sword's broader GRC program.

🎯 Exigences

• 5+ years of hands-on experience in GRC, compliance, or security, with at least 3 of those years focused on federal compliance frameworks such as CMMC or FedRAMP; • Demonstrated experience owning deliverables and driving remediation through a CMMC, FedRAMP, or equivalent federal compliance effort; • Strong working knowledge of CMMC Level 2 practices, scoping methodology, and CUI handling requirements; • Ability to produce compliance documentation — SSPs, POA&Ms, gap analyses, control narratives — without heavy supervision; • Proven ability to communicate technical compliance requirements to non-technical stakeholders across engineering, operations, and business teams; • Experience engaging directly with external auditors and assessors, including evidence packaging and real-time response during assessments; • US citizenship required; • Ability to obtain a federal Public Trust designation if required by a sponsoring agency. • **What we would love to see** • CMMC Certified Professional (CCP) credential, or active pursuit of it; • CMMC Certified Assessor (CCA) credential; • Hands-on experience with FedRAMP authorization packages, continuous monitoring, and agency ATO processes; • Background in defense contracting or regulated health tech environments; • Experience working across multiple compliance frameworks simultaneously (HITRUST, SOC 2, ISO 27001); • Familiarity with GRC platforms such as Hyperproof, Drata, or Vanta.

🏖️ Avantages

• Comprehensive health, dental and vision insurance* • Life and AD&D Insurance* • Financial advisory services* • Supplemental Insurance Benefits (Accident, Hospital and Critical Illness)* • Health Savings Account* • Equity shares* • Discretionary PTO plan* • Parental leave* • 401(k) • Flexible working hours • Remote-first company • Paid company holidays • Free digital therapist for you and your family

Postuler Maintenant

Emplois Similaires

🕒 il y a 1 mois

Arclin

501 - 1000

🌾 Agriculture

Global Steward responsible for product stewardship and regulatory compliance in the Kevlar® business. Leading safety and sustainability efforts while collaborating with cross-functional teams.

🇺🇸 États-Unis – Télétravail

⏰ Temps Plein

🟡 Intermédiaire

🟠 Senior

🚔 Conformité

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 1 mois

Syner-G BioPharma Group

201 - 500

🧬 Biotechnologie

💊 Pharmaceutique

⚕️ Assurance santé

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 1 mois

Subsplash

201 - 500

☁️ SaaS

🤝 À but non lucratif

Senior GRC Analyst at Subsplash advancing security and risk operations. Leading AI-first compliance function and identifying security gaps to mature control environment.

🇺🇸 États-Unis – Télétravail

💵 $95 000 - $105 000 / an

⏰ Temps Plein

🟠 Senior

🚔 Conformité

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 1 mois

Vantage Data Centers

1001 - 5000

🏢 Entreprise

Manager leading interconnection strategy and regulatory analysis for U.S. power markets at Vantage Data Centers. Collaborating across internal teams to support market entry and growth strategy.

🇺🇸 États-Unis – Télétravail

💵 $130 000 - $140 000 / an

⏰ Temps Plein

🟡 Intermédiaire

🟠 Senior

🚔 Conformité

🦅 Parrain de Visa H1B

info

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 1 mois

Danaher Corporation

10 000+ employés

🧬 Biotechnologie

🔬 Science

🤝 B2B

Global Trade Compliance - Export Controls Lead responsible for managing export compliance at Pall Corporation. Focus on ITAR compliance globally with collaboration across site leaders and departments.

🇺🇸 États-Unis – Télétravail

💵 $120 000 - $160 000 / an

⏰ Temps Plein

🟠 Senior

🚔 Conformité

🦅 Parrain de Visa H1B

info

🗣️🇺🇸🇬🇧 Anglais requis