GRC Analyst

🔥 0 minutes ago

🇺🇸 United States – Remote

💵 $80.9k - $137.6k / year

⏰ Full Time

🟡 Mid-level

🟠 Senior

🎲 Risk

👻 Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of US Anesthesia Partners

US Anesthesia Partners

5001 - 10000 employees

Founded 2012

💼 Consulting

🏥 Healthcare

⚕️ Healthcare Insurance

Consulting • Healthcare • Healthcare Insurance

US Anesthesia Partners is a leading provider of comprehensive anesthesia services, dedicated to delivering exceptional patient care and operational excellence. Founded by a team of forward-thinking anesthesiologists, USAP specializes in various anesthesiology areas including cardiovascular care, obstetrics, and pediatrics. With a network of thousands of clinicians and hundreds of facility partners across the nation, they serve over two million patients annually, aiming to redefine the standards of quality in anesthesia services.

📋 Description

• Design, configure, and govern control frameworks and risk workflows within the GRC platform • Establish and maintain control procedures aligned with internal policy, HIPAA, HITRUST, PCI, SOC 2, NIST, and other applicable frameworks • Develop and maintain control libraries, including narratives, ownership assignments, testing frequency, and evidence requirements • Monitor and update risk registers, including risk tracking, scoring, and prioritization • Drive automation for control testing, evidence collection, attestations, and remediation • Track policy review cycles and maintain current documentation • Lead information security risk assessments across IT, operational, and third-party domains • Perform control walkthroughs and operating effectiveness testing; document results and control gaps • Collaborate with internal teams and external auditors on audits and assessments • Maintain control mappings and compliance documentation • Prepare reports, dashboards, and metrics on control effectiveness, risk status, and compliance gaps • Support internal and external audits by gathering evidence, coordinating responses, and tracking remediation • Manage audit findings, corrective action plans, and remediation timelines • Guide risk assessments and document vulnerabilities, threats, findings, and supporting evidence • Partner with stakeholders on risk mitigation strategies and track progress and ownership • Develop, monitor, and report KRIs and KPIs • Apply risk scoring methodologies, including likelihood, impact, and residual risk calculations • Escalate significant risks and control deficiencies to management and governance committees • Lead the development and lifecycle management of information security policies, procedures, standards, and guidelines • Direct policy review and approval workflows • Evaluate third-party vendors for security and compliance risks, including SOC reports, security questionnaires, and contracts • Track vendor risk assessments, reassessment cycles, and risk ratings • Develop and monitor vendor remediation action plans • Support vendor onboarding and offboarding risk reviews • Enhance GRC processes and workflows • Monitor industry trends, emerging threats, and GRC best practices • Champion automation and integration initiatives • Guide program assessments and maturity benchmarking • Perform other assigned duties

🎯 Requirements

• Bachelor’s degree in information security, cybersecurity, computer science, information technology, business administration, or a closely related field required; equivalent experience may be considered in lieu of a degree • Minimum of 5 years relevant experience in governance, risk, and compliance functions within IT or information security • Experience with AuditBoard (now named Optro) highly preferred • CISA preferred • CRISC preferred • CISM preferred • Other relevant certifications such as CompTIA Security+ or ISO 27001 Lead Auditor preferred • Prior experience implementing, managing, or auditing security policies and procedures • Familiarity with HIPAA, NIST CSF, SOC 2, HITRUST, and other compliance frameworks • Prior experience conducting risk assessments and supporting risk management activities • Excellent written and verbal communication skills, including communicating technical concepts and compliance requirements to technical and non-technical stakeholders • Ability to manage multiple priorities, work independently, and collaborate across cross-functional teams • Must reside in the United States; US Anesthesia Partners does not hire candidates residing in California, Hawaii, or Alaska

🏖️ Benefits

• Annual bonus eligibility (not guaranteed; based on company and individual performance) • Reasonable accommodations for individuals with disabilities

Apply Now

Similar Jobs

🔥 3 hours ago

dv01

51 - 200

🛡️ Insurance

📦 Logistics

💸 Finance

Data Governance Lead building ownership, quality, and compliance frameworks for dv01’s structured-finance analytics platform. Enabling trustworthy AI products across millions of financial loans.

🔥 9 hours ago

Finalis

51 - 200

💼 Consulting

📦 Logistics

📣 Marketing

Quality & Risk Manager overseeing audits, risk, vendors, and cybersecurity for Finalis’s compliant investment banking platform. Leading the quality and risk team under the Chief Compliance Officer.

🔥 10 hours ago

PETA

201 - 500

🍽️ Food & Beverage

💼 Consulting

⚖️ Legal

Shareholder strategy officer coordinating PETA’s corporate governance campaigns. Engaging investors, researching SEC procedures, and presenting resolutions to reduce animal suffering in supply chains.

🔥 22 hours ago

Banner Health

10,000+ employees

🏥 Healthcare

⚕️ Healthcare Insurance

Risk adjustment coding reviewer validating ICD-10 documentation for Banner Health’s Arizona healthcare network. Educating providers and improving coding accuracy and compliance.

🔥 23 hours ago

Zigabyte

51 - 200

💼 Consulting

🏥 Healthcare

📦 Logistics

IGA Engineer designing SailPoint and Entra identity governance solutions. Automating access lifecycle, certifications, provisioning, and compliance reporting across enterprise systems.