GRC Analyst

🔥 1 hour ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of US Anesthesia Partners

US Anesthesia Partners

5001 - 10000 employees

Founded 2012

💼 Consulting

🏥 Healthcare

⚕️ Healthcare Insurance

Consulting • Healthcare • Healthcare Insurance

US Anesthesia Partners is a leading provider of comprehensive anesthesia services, dedicated to delivering exceptional patient care and operational excellence. Founded by a team of forward-thinking anesthesiologists, USAP specializes in various anesthesiology areas including cardiovascular care, obstetrics, and pediatrics. With a network of thousands of clinicians and hundreds of facility partners across the nation, they serve over two million patients annually, aiming to redefine the standards of quality in anesthesia services.

📋 Description

• Design, configure, and govern control frameworks and risk workflows within the GRC platform • Establish and maintain control procedures aligned with internal policy, HIPAA, HITRUST, PCI, SOC 2, NIST, and other applicable frameworks • Develop and maintain control libraries, including narratives, ownership assignments, testing frequency, and evidence requirements • Monitor and update risk registers, including risk tracking, scoring, and prioritization • Automate control testing, evidence collection, attestations, and remediation workflows • Track policy review cycles and maintain current documentation • Lead information security risk assessments across IT, operational, and third-party domains • Perform control walkthroughs and operating effectiveness testing; document results and control gaps • Collaborate with internal teams and external auditors on audits and assessments • Prepare reports, dashboards, and metrics on control effectiveness, risk status, and compliance gaps • Map controls to regulatory and framework requirements • Gather audit evidence, coordinate stakeholder responses, and track remediation through closure • Manage audit findings, corrective action plans, and remediation timelines • Guide risk assessments, document findings, and support evidence management • Develop and report key risk indicators and key performance indicators • Maintain risk scoring methodologies and escalate significant risks and control deficiencies • Lead information security policy, procedure, standard, and guideline lifecycle management • Direct policy review and approval workflows • Evaluate third-party vendors for security and compliance risks • Track vendor risk assessments, reassessment cycles, and risk ratings • Develop and monitor vendor remediation action plans • Support vendor onboarding and offboarding risk reviews • Enhance GRC processes and workflows, champion automation and integration, and support maturity benchmarking • Perform other duties and responsibilities as assigned

🎯 Requirements

• Bachelor’s degree in information security, cybersecurity, computer science, information technology, business administration, or a closely related field required • Equivalent experience may be considered in lieu of a degree, such as 4+ years of relevant information security, compliance, or GRC experience • Minimum of 5 years relevant experience in governance, risk, and compliance functions within IT or information security • Certified Information Systems Auditor (CISA) preferred • Certified Risk and Information Systems Control (CRISC) preferred • Certified Information Security Manager (CISM) preferred • Other relevant certifications, such as CompTIA Security+ or ISO 27001 Lead Auditor, preferred • Prior experience implementing, managing, or auditing security policies and procedures • Familiarity with HIPAA, NIST CSF, SOC 2, HITRUST, and related compliance frameworks • Prior experience conducting risk assessments and supporting risk management activities • Excellent written and verbal communication skills, including communicating technical concepts and compliance requirements to technical and non-technical stakeholders • Ability to manage multiple priorities, work independently, and collaborate across cross-functional teams • Must reside in an eligible U.S. location; USAP does not hire candidates residing in California, Hawaii, or Alaska • Ability to complete the physical requirements of the job with or without reasonable accommodation • Ability to use office equipment and communicate verbally and in writing

🏖️ Benefits

• Base pay estimate of $80,900 - $137,600 annually • Eligible for an annual bonus • Equal employment opportunities regardless of protected characteristics

Apply Now

Similar Jobs

🔥 1 hour ago

Sunrun

10,000+ employees

💼 Consulting

🏭 Manufacturing

⚡ Energy

Compliance Engineer leading regulatory certification for SnapNrack solar mounting products at Sunrun. Managing UL, Intertek, ICC, testing, documentation, and product approval activities across the lifecycle.

🔥 1 hour ago

Ascensus

5001 - 10000

💼 Consulting

🛡️ Insurance

💸 Finance

Compliance Servicing Specialist supporting Ascensus’s retirement, education, and healthcare savings accounts. Handling client calls, account compliance issues, and death-claim processing for financial institutions.

🔥 1 hour ago

Prime Therapeutics

1001 - 5000

🏥 Healthcare

💼 Consulting

🛡️ Insurance

Senior Regulatory Analyst leading regulatory reviews, audits, and compliance implementation for Prime Therapeutics, a pharmacy benefit manager. Monitoring healthcare regulations across Commercial, Medicare, Medicaid, and Marketplace programs.

🔥 1 hour ago

Asset Living

1001 - 5000

🏠 Real Estate

Affordable housing compliance manager overseeing regulatory compliance, audits, reporting, and risk mitigation for Asset Living’s nationwide property portfolio. Advising clients, operations, and compliance teams while mentoring managers.

🔥 1 hour ago

Stryker

10,000+ employees

🏥 Healthcare

💼 Consulting

📦 Logistics

Stryker pharmaceutical regulatory specialist leading global submissions, QMS oversight, audits, and CAPA compliance. Supporting clinical investigations, product registrations, and lifecycle quality requirements remotely across the United States.