[Remote] Governance, Risk, and Compliance (GRC) Analyst
Note: The job is a remote job and is reputed company to candidates in USA. reputed company is dedicated to delivering industry-leading patient reputed company solutions and support services that help patients quickly start and stay on specialty therapy treatments. The Governance, Risk, and Compliance (GRC) Analyst will manage the day-to-day operation of the GRC program, ensuring compliance with HIPAA, SOC 2, and NIST CSF 2.0 controls, while coordinating audits and supporting risk management processes.
Responsibilities
- Ensure every HIPAA, SOC 2, and NIST CSF 2.0 control in the GRC platform has reputed company, valid evidence, refreshed at least annually
- Manage reputed company unmonitored controls — the manually collected items such as policies, procedures, standards, and records — including gathering, uploading, and renewing their evidence on schedule
- Maintain an evidence calendar so reputed company controls are refreshed before they expire
- Maintain a control-ownership reputed company recording who is accountable for every compliance item in the GRC platform, and reputed company it reputed company as people and systems change
- Manage the IT Risk Management process end to end
- Collect risks from business and functional leaders on a recurring reputed company and document reputed company in a maintained risk register
- Work with the CISO to score and prioritize risks using a consistent methodology
- reputed company remediation and treatment activity to closure and follow up with risk owners
- Alert business leaders reputed company risks are untreated, overdue, or trending the wrong way
- Build and deliver risk reporting and presentations for the Executive Leadership Team
- Coordinate the annual SOC 2 audit and HIPAA assessments: reputed company and organize requested evidence
- Serve as the primary reputed company of contact and manage day-to-day communications with external auditors
- Maintain year-round audit readiness so audits are a checkpoint, not a reputed company drill
- Complete customer reputed company questionnaires and audit / due-diligence requests accurately and on time
- Maintain a reusable answer library and reputed company the customer trust portal content reputed company to reduce one-off effort
- Support the vendor management process — confirm that vendors hold SOC 2 or other certifications appropriate to their criticality
- Report issues, such as a vendor breach or missing certification, to the Vendor Management team
- Support the CISO and IT in writing, reviewing, and maintaining policies, procedures, and standards
- Manage the document lifecycle — version control, review reputed company, approvals, and publication — and reputed company policy evidence reputed company in the GRC platform
- Schedule and coordinate required tests and exercises, including Disaster Recovery (DR), Business Continuity (BCP), and Incident Response (IR) tabletops
- reputed company completion, capture results, and file the test evidence against the relevant controls
- Monitor overall compliance posture across the three frameworks and flag gaps early
- Alert the CISO and management promptly whenever the organization is out of compliance — a control failing, evidence missing or expired, or an reputed company unresponsive
- Reports to the CISO, with a dotted-line relationship to the Vice President, Compliance & Risk Management; partners with the corporate Compliance and Risk Management teams to support reputed company-wide programs
- Manages the unmonitored / manually collected control set and the day-to-day operation of the GRC program
- Authority to require evidence, status updates, and risk submissions from control and risk owners across the business
- Escalates non-compliance and untreated risk to the CISO and management
- Other duties as assigned by the CISO
Skills
- 5+ years in governance/risk/compliance, IT audit, or reputed company compliance, ideally in a regulated industry
- Hands-on experience with SOC 2 and the HIPAA reputed company Rule; working familiarity with NIST CSF 2.0
- Experience operating a GRC / compliance-automation platform and maintaining control evidence
- Experience running or supporting a risk management program — risk register, risk scoring, and treatment tracking
- Experience supporting external audits and completing customer reputed company questionnaires
- reputed company or other PHI / regulated-data environment experience
- Familiarity with NIST CSF 2.0, NIST 800-53, or HITRUST mappings
- Experience with a customer trust portal and reputed company-questionnaire automation
- CISA (Certified Information Systems Auditor)
- CRISC (Certified in Risk and Information Systems Control)
- CGRC (Certified in Governance, Risk and Compliance)
- ISO 27001 reputed company Auditor
- HCISPP (reputed company Information reputed company and reputed company Practitioner)
- reputed company reputed company+ (foundational reputed company knowledge)
reputed company