Lead Security Analyst - GRC

CollectiveHealth, Inc.
San Francisco, CA, United States
5 days ago
Apply on www.themuse.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$172,500.0 - $215,625.0
Working hours
Regular working hours

Tech stack

Cloud Engineering Cyber Security Smartsuite Data Management

Job description

As our Lead Security Analyst - GRC, you’ll lead initiatives that address the company’s-and some of our industry’s-most sophisticated and meaningful security engineering challenges. You will build relationships across all parts of the business and drive multi-functional initiatives to continuously improve our security and privacy posture. You will be responsible for building and implementing controls that can scale and optimize as we move into a context-aware security environment., Evaluate and implement security controls based on frameworks such as NIST, CIS, HIPAA, SOC 2, and HITRUST.Develop and maintain policies, procedures, and documentation (controls, narratives, matrices).Lead SOC 2 and HITRUST audit engagements, from audit planning through remediation.Coordinate and monitor third-party risk assessments and compliance reviews.Own and lead BCP (Business Continuity Planning) and BIA (Business Impact Assessments) efforts.Build and maintain security risk registry

Audit & Risk Management:

Perform audit readiness assessments, and support internal/external audits.Partner with external auditors, control owners, and leadership to minimize business disruption.Track and drive remediation plans based on audit findings and compliance gaps.Maintain and communicate exception documentation for policy deviations.Educate and guide control/risk owners on their responsibilities.

Advisory & Communication:

Act as a liaison between technical and non-technical stakeholders.Respond to security questionnaires, RFIs, and client compliance inquiries.Develop and deliver security awareness and training programs.Provide executive reporting on program status, risks, and overall health.

Requirements

8+ years in cybersecurity, GRC, audit, or risk/compliance roles.Experience managing SOC 2 / HITRUST audits, especially in cloud-native environments.Strong working knowledge of security frameworks and regulatory requirements.Demonstrated policy, data management, and risk mitigation capabilities.Familiarity with GRC tools and audit processes.Excellent communication and cross-functional collaboration skills., Big 4 accounting firm background.Professional certifications: CISSP, CISA, CRISC, CISM, or similar.

Benefits & conditions

The actual pay rate offered within the range will depend on factors including geographic location, qualifications, experience, and internal equity. In addition to the [salary/hourly rate], you will be eligible for 205,000 stock options and benefits like health insurance, 401k, and paid time off. Learn more about our benefits at https://jobs.collectivehealth.com/benefits/. San Francisco, CA Pay Range $172,500-$215,625 USD Lehi, UT Pay Range $138,000-$172,500 USD Plano, TX Pay Range $151,800-$189,750 USD

Why Join Us?

  • Mission-driven culture that values innovation, collaboration, and a commitment to excellence in healthcare
  • Impactful projects that shape the future of our organization
  • Opportunities for professional development through internal mobility opportunities, mentorship programs, and courses tailored to your interests
  • Flexible work arrangements and a supportive work-life balance

About the company

At Collective Health, we’re transforming how employers and their people engage with their health benefits by seamlessly integrating cutting-edge technology, compassionate service, and world-class user experience design.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.themuse.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:43 min

Data management for stateful cloud-native workloads

Michael Cade · World Congress 2022

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

5:25 min

Shifting left and creating internal security champion programs

Vandana Verma Sehgal · LIVE

1:44 min

Career transition into cloud native and data management

Michael Cade · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all