> Markdown version of [/jobs/ext/3257533-sr-grc-analyst](https://www.wearedevelopers.com/jobs/ext/3257533-sr-grc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. GRC Analyst - **Company:** Aya Healthcare - **Location:** San Diego, CA, United States - **Experience:** Expert - **Salary:** $105,000.0 - $135,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Spreadsheets, Cyber Security, Information Technology Audit, Smartsuite, Workflow Management Systems, Servicenow - **Published:** September 2, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/88227901/1 ## About the Role * 4+ years of experience in Governance, Risk, and Compliance, Information Security, IT Audit, or a related discipline. * Hands-on experience operating or configuring GRC tools such as ServiceNow GRC / IRM, Drata, Vanta, or Hyperproof to automate and manage compliance workflows. * Demonstrated experience owning GRC projects, compliance deliverables, or process-improvement initiatives from planning through completion. * Strong working knowledge of SOC 2 or ISO/IEC 27001:2022. Familiarity with HIPAA and other healthcare-related compliance requirements is preferred. * Experience with control design, evidence evaluation, risk assessments, audit support, remediation tracking, or compliance testing. * Experience improving manual compliance processes through automation, workflow design, or system-based reporting. * Strong written and verbal communication skills, with the ability to explain risk and compliance concepts to both technical and non-technical audiences. * Demonstrated ability to work independently, manage competing priorities, anticipate next steps, and escalate risks early. * Experience collaborating across Information Security, IT, Engineering, Legal, Privacy, Finance, Audit, and business teams. * Bachelor's degree in IT / CS is preferred. * CISA, CISSP (or CISSP Associate), CCSP, ISO 27001 credential, or another relevant security or compliance certification is preferred. * Experience with additional security, compliance, AI governance, and privacy frameworks or regulatory requirements, such as ISO/IEC 42001, NIST AI RMF, NIST CSF, GDPR/UK GDPR, and CCPA/CPRA, is a plus. * Experience with ServiceNow GRC / IRM implementation, administration, configuration, or integration is preferred. * Experience developing GRC metrics, dashboards, key performance indicators, or leadership reporting is preferred. * Experience supporting internal or external audits in a regulated or healthcare-related environment is preferred. Core Role Criteria: * GRC Subject-Matter Expertise: Demonstrates deep knowledge within GRC and understands how compliance activities affect related security, technology, privacy, legal, and business processes. * Project and Outcome Ownership: Owns assigned outcomes end to end, delivers high-quality work, and holds self and project participants accountable for commitments. * GRC Tool Capability: Experience with modern GRC tools such as ServiceNow, Drata, or Vanta. Experience with ServiceNow GRC / IRM beyond basic end-user activity is preferred. * Compliance Automation Mindset: Identifies opportunities to reduce manual effort and validates automation or process improvements through measurable results. * Analytical Judgment: Evaluates evidence, identifies control gaps and emerging risks, understands dependencies, and recommends practical solutions. * Cross-Functional Collaboration: Builds effective working relationships and guides stakeholders through compliance requirements using clear, business-relevant language. * Strategic Orientation: Understands emerging risks and long-term trends within GRC and connects day-to-day work to broader organizational objectives. * Informal Leadership: Leads projects from start to completion and guides teammates through collaboration, knowledge sharing, and example without requiring formal management authority. * Delivery and Initiative: Manages work independently, anticipates next steps, improves processes, and delivers projects on schedule. ## Description We are seeking a Senior Governance, Risk & Compliance (GRC) Analyst to help operate and mature Aya's enterprise GRC program, with a strong emphasis on compliance automation, scalability, and operational excellence. In this role, you will own GRC projects and deliverables across the organization while serving as a subject-matter expert in compliance operations, risk management, and ServiceNow GRC / IRM. This is a hands-on opportunity for someone energized by improving modern GRC capabilities and moving away from manual, point-in-time audit work toward automated, continuously operating compliance processes. You will work cross-functionally across Information Security, IT, Legal, Privacy, Engineering, Finance, and Audit to translate regulatory and framework requirements into practical controls, improve evidence collection and reporting, and deliver clear, actionable insights to stakeholders and leadership. You will work in the Security organization and report to the Manager, Governance, Risk & Compliance. This role is remote and will work PST business hours., * Own assigned GRC projects, compliance deliverables, and process improvements from planning through completion. * Support the day-to-day operation and continuous improvement of Aya's enterprise GRC program. * Design and improve scalable workflows that translate regulatory and framework requirements into clear control activities and operational responsibilities. * Support compliance efforts for SOC 2 and ISO/IEC 27001:2022, including readiness activities, audit preparation, evidence coordination, control testing, auditor support, and remediation tracking. * Establish and maintain clear control ownership, traceability, documentation, and evidence requirements. * Identify opportunities to replace manual or spreadsheet-driven compliance activities with automated, system-driven processes. * Improve automated evidence collection, control testing, issue and remediation tracking, dashboards, and reporting. * Conduct control reviews, risk assessments, evidence evaluations, and compliance gap analyses. * Monitor remediation activities, follow up with control owners, identify delivery risks, and escalate issues when appropriate. * Build and maintain dashboards, metrics, and reports that communicate compliance status, trends, exceptions, risks, and remediation progress. * Partner with ServiceNow platform and engineering teams to ensure GRC solutions are scalable, supportable, and aligned with enterprise processes. * Engage with customers to respond to compliance, security, privacy, and risk-related questions in RFPs, due diligence requests, contracts, and customer meetings. * Collaborate with Security, IT, Engineering, Finance, Legal, Privacy, Internal Audit, and business stakeholders to resolve control and compliance issues. * Translate risk and compliance requirements into clear, business-relevant guidance that enables teams to take action. * Lead working sessions, walkthroughs, and process discussions with control owners and subject-matter experts. * Identify emerging risks, process dependencies, and long-term improvement opportunities within the GRC domain. * Guide and support junior analysts and teammates through collaboration, knowledge sharing, and example. * Review work products for accuracy, completeness, and alignment with established quality standards. * Document process improvements, design decisions, procedures, and lessons learned. ## Related Videos - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Great DevEx and Regulatory Compliance - Possible?](https://www.wearedevelopers.com/videos/1426-great-devex-and-regulatory-compliance-possible) - [Launching a marketplace on-time: A lesson in taking shortcuts using spreadsheets!](https://www.wearedevelopers.com/videos/477-launching-a-marketplace-on-time-a-lesson-in-taking-shortcuts-using-spreadsheets) - [From Global Capability Centers to AI-Powered Command Centers](https://www.wearedevelopers.com/videos/100096-from-global-capability-centers-to-ai-powered-command-centers) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) - [Your Enterprise RAG Has No Legal Basis](https://www.wearedevelopers.com/videos/100344-your-enterprise-rag-has-no-legal-basis) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers) - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship)