This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Security Analyst, Compliance based in the United States.
This role will play a central part in strengthening and operating an information security governance, risk, and compliance program within a healthcare environment. You will help protect sensitive health information while ensuring security policies, controls, and processes meet regulatory and industry expectations. The position combines risk management, audit leadership, compliance assessments, third-party risk, and security program development. You will work closely with IT, Privacy, Compliance, business stakeholders, external auditors, and partners to maintain a strong control environment. A key focus will be advancing HITRUST and SOC 2 readiness while maintaining an effective risk register and remediation process. This is an opportunity to help mature an evolving GRC function and establish scalable processes across the organization.
Accountabilities:
- Lead and mature the information security risk management program, including risk identification, assessment, tracking, remediation, and performance measurement.
- Develop and report security risk and compliance metrics that provide clear visibility into program performance and organizational risk.
- Advance the existing security assessment and reporting program while coordinating audits and assessments such as SOC 2, HITRUST, and client security requests.
- Lead the use of the HITRUST Common Security Framework to assess, measure, and maintain the maturity of the information security program.
- Manage the information security risk register and coordinate the remediation of identified risks with relevant stakeholders.
- Perform information security and information technology risk assessments and apply appropriate risk-scoring methodologies to establish baseline risk levels against defined risk appetite.
- Respond to client security questionnaires and ad hoc assessment requests while maintaining accurate tracking and follow-through.
- Collaborate with IT, Privacy, Compliance, and other business teams to develop and maintain security and document-control content aligned with applicable frameworks.
- Support compliance with the HITRUST security framework and other relevant regulatory and industry requirements.
- Contribute to third-party risk management activities and evaluate security risks associated with external partners and business relationships.
- Build and improve repeatable GRC processes that strengthen the organization’s overall security governance and operational efficiency.
- Work with external auditors and internal stakeholders to facilitate evidence collection, assessment activities, remediation, and reporting.
- Perform additional information security, governance, risk, and compliance duties as required by the business.
- Bachelor’s degree in cybersecurity or a related discipline, combined with relevant professional experience.
- 5+ years of professional experience in information security.
- 3+ years of experience managing information security audit activities, either as an assessor, assessed organization, or both.
- Hands-on experience as an information security professional, ideally within a healthcare environment.
- Direct experience with healthcare security and HITRUST requirements.
- Proven ability to create and implement structured processes for ongoing security and compliance programs.
- Experience developing and managing risk-scoring methodologies and establishing baseline risk against organizational risk appetite.
- Strong experience conducting information security and IT risk assessments.
- Knowledge of regulatory controls and recognized security frameworks and standards, including HIPAA, ISO 27001/27002, PCI, NIST, and related industry practices.
- Experience working with GRC platforms such as Archer.
- Demonstrated expertise in security governance, risk, and compliance.
- Experience with contract reviews is preferred.
- HITRUST certification is preferred.
- CISSP, CISM, GIAC, or other relevant information security certifications are preferred.
- Experience in third-party risk management and security assessment activities.
- Strong critical-thinking and critical-assessment capabilities, with the ability to evaluate complex security and compliance issues.
- Ability to remain calm and confident under pressure while managing sensitive or time-critical matters.
- Strong collaboration and conflict-management skills.
- Ability to prioritize effectively and manage multiple workstreams simultaneously in a high-pressure environment.
- Comfortable working independently while also contributing effectively within cross-functional teams.
- Excellent written and verbal communication skills.
- Strong customer service and stakeholder-management skills.
- Remote position based in the United States.
- Limited travel, scheduled according to business needs.
- Opportunity to help shape and mature an information security GRC program.
- Exposure to HITRUST, SOC 2, healthcare security, risk management, and regulatory compliance initiatives.
- Cross-functional collaboration with IT, Privacy, Compliance, business stakeholders, and external auditors.
- Opportunity to establish scalable security governance and compliance processes within a healthcare environment.
Requirements:
Benefits:

