Senior GRC Analyst

Job not on LinkedIn

🔥 16 hours ago

🇺🇸 United States – Remote

💵 $105k - $135k / year

⏰ Full Time

🟠 Senior

🎲 Risk

🦅 H1B Visa Sponsor

infoinfo

👻 Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Aya Healthcare

Aya Healthcare

5001 - 10000 employees

Founded 2001

🏥 Healthcare

💼 Consulting

📦 Logistics

Healthcare • Consulting • Logistics

Aya Healthcare is a prominent provider of healthcare staffing services, connecting healthcare professionals such as nurses and allied health workers with healthcare facilities across the United States. They offer travel nursing, per diem, and permanent placement services, ensuring that hospitals and healthcare systems have the necessary staff to provide high-quality patient care. Aya Healthcare focuses on improving the staffing industry through innovative technology and exceptional customer service.

📋 Description

• Own assigned GRC projects, compliance deliverables, and process improvements from planning through completion • Support the day-to-day operation and continuous improvement of Aya’s enterprise GRC program • Design and improve scalable workflows translating regulatory and framework requirements into control activities and operational responsibilities • Support SOC 2 and ISO/IEC 27001:2022 compliance, including readiness, audit preparation, evidence coordination, control testing, auditor support, and remediation tracking • Establish control ownership, traceability, documentation, and evidence requirements • Replace manual or spreadsheet-driven compliance activities with automated, system-driven processes • Improve automated evidence collection, control testing, issue and remediation tracking, dashboards, and reporting • Conduct control reviews, risk assessments, evidence evaluations, and compliance gap analyses • Monitor remediation, follow up with control owners, identify delivery risks, and escalate issues • Build and maintain dashboards, metrics, and reports communicating compliance status, trends, exceptions, risks, and remediation progress • Partner with ServiceNow platform and engineering teams on scalable, supportable GRC solutions • Respond to customer compliance, security, privacy, and risk questions in RFPs, due diligence requests, contracts, and meetings • Collaborate with Security, IT, Engineering, Finance, Legal, Privacy, Internal Audit, and business stakeholders • Translate risk and compliance requirements into actionable business guidance • Lead working sessions, walkthroughs, and process discussions with control owners and subject-matter experts • Identify emerging risks, process dependencies, and long-term GRC improvements • Guide junior analysts and teammates through collaboration, knowledge sharing, and example • Review work products for accuracy, completeness, and quality standards • Document process improvements, design decisions, procedures, and lessons learned

🎯 Requirements

• 4+ years of experience in Governance, Risk, and Compliance, Information Security, IT Audit, or a related discipline • Hands-on experience operating or configuring GRC tools such as ServiceNow GRC / IRM, Drata, Vanta, or Hyperproof • Experience owning GRC projects, compliance deliverables, or process-improvement initiatives from planning through completion • Strong working knowledge of SOC 2 or ISO/IEC 27001:2022 • Experience with control design, evidence evaluation, risk assessments, audit support, remediation tracking, or compliance testing • Experience improving manual compliance processes through automation, workflow design, or system-based reporting • Strong written and verbal communication skills, with ability to explain risk and compliance concepts to technical and non-technical audiences • Ability to work independently, manage competing priorities, anticipate next steps, and escalate risks early • Experience collaborating across Information Security, IT, Engineering, Legal, Privacy, Finance, Audit, and business teams • Bachelor’s degree in IT / CS is preferred • CISA, CISSP (or CISSP Associate), CCSP, ISO 27001 credential, or another relevant security or compliance certification is preferred • Experience with additional security, compliance, AI governance, and privacy frameworks or regulatory requirements, including ISO/IEC 42001, NIST AI RMF, NIST CSF, GDPR/UK GDPR, and CCPA/CPRA, is a plus • Experience with ServiceNow GRC / IRM implementation, administration, configuration, or integration is preferred • Experience developing GRC metrics, dashboards, KPIs, or leadership reporting is preferred • Experience supporting internal or external audits in a regulated or healthcare-related environment is preferred • PST business-hours availability

🏖️ Benefits

• Free premium medical, dental, life and vision insurance • Generous 401(k) match • Reimbursements • Discretionary bonuses • Paid sick leave in accordance with applicable state, federal, and local laws • Celebrations and rewards for achieving goals • Company-sponsored virtual events, happy hours, and team-building activities • Birthday treat • Unlimited DTO (time off) • Daily virtual yoga, meditation, or boot camp classes

Apply Now

Similar Jobs

🕒 Yesterday

YipitData

201 - 500

💸 Finance

🏢 Enterprise

GRC Analyst testing controls, managing audits, and assessing risk for YipitData’s alternative-data analytics business. Supporting SOC 2, vendor reviews, customer questionnaires, and AI governance.

🕒 Yesterday

EHS Support

201 - 500

💼 Consulting

🏥 Healthcare

🍽️ Food & Beverage

Project Scientist leading human health risk assessments for EHS Support’s environmental consulting clients. Managing projects, regulators, staff mentorship, and remedial strategy development.

🕒 Yesterday

US Anesthesia Partners

5001 - 10000

💼 Consulting

🏥 Healthcare

⚕️ Healthcare Insurance

GRC Analyst strengthening USAP’s healthcare security posture through control frameworks, risk workflows, audits, and vendor assessments. Managing compliance across HIPAA, HITRUST, PCI, SOC 2, and NIST.

🕒 Yesterday

US Anesthesia Partners

5001 - 10000

💼 Consulting

🏥 Healthcare

⚕️ Healthcare Insurance

GRC Analyst strengthening security governance for a growing anesthesia healthcare organization. Managing controls, risk assessments, audits, vendors, and compliance workflows.

🕒 Yesterday

dv01

51 - 200

🛡️ Insurance

📦 Logistics

💸 Finance

Data Governance Lead building ownership, quality, and compliance frameworks for dv01’s structured-finance analytics platform. Enabling trustworthy AI products across millions of financial loans.