> Markdown version of [/jobs/ext/3376344-grc-analyst](https://www.wearedevelopers.com/jobs/ext/3376344-grc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # GRC Analyst - **Company:** Ambience Healthcare - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software as a Service, Data Streaming - **Published:** September 30, 2026 - **Apply:** https://startup.jobs/grc-analyst-ambience-healthcare-10232913 ## About the Role * Hands-on SOC 2 ownership: Senior-level GRC or compliance experience in a SaaS environment, including owning a SOC 2 (or equivalent) audit from evidence collection through auditor sign-off, ideally using a GRC automation platform like Vanta or Drata. * Technical curiosity: Comfortable using an AI coding tool like Claude Code to answer compliance questions directly from source code (you won't need to write code yourself), and able to threat-model a new vendor: what data it touches, where that data flows, and what controls it needs. * Clear writing and communication: You write policies and standards that hold up to audit and that engineers can actually use, and you work directly and confidently with engineering, legal, and customers. * Startup ownership mindset: You thrive in ambiguity, take a partially built function and make it accountable without waiting for structure to be handed to you, and happily work outside a narrow swim lane. Nice-to-Have * Broader framework experience: ISO 27001 experience, and exposure to ISO 42001 or other AI governance frameworks. * Regulated-industry background: Experience in healthcare, fintech, or another highly regulated industry. ## Description Health systems trust Ambience with some of the most sensitive data there is, and proving that we deserve that trust is essential to every partnership we build. We are looking for a Senior GRC Analyst to own our governance, risk, and compliance program end to end, from SOC 2 and PHI governance to vendor and AI-model risk to the security evidence our customers rely on., * Own the compliance program: Run SOC 2 end to end, including the auditor relationship, evidence collection and interpretation in Vanta, and continuous audit readiness as our infrastructure evolves. Help lay the groundwork for AI governance frameworks like ISO 42001. * Bring rigor to PHI governance: Build and maintain an authoritative inventory of where PHI lives and which systems and models touch it, and surface and close HIPAA and governance gaps. * Investigate controls first-hand: Use AI coding assistants analytically to verify whether a control (for example, encryption at rest) is actually implemented, producing clear, evidenced answers without engineering hand-holding. * Stand up vendor and AI-model risk reviews: Build and run the security review process for new vendors and AI model providers, partnering with legal and finance to bring every vendor into the fold with a documented risk assessment. * Drive risk to closure: Partner with engineering to enumerate, prioritize, and remediate security risks on a predictable, auditable cadence, and author the security and compliance policies that engineering, legal, and GTM teams can actually follow. * Be the front door for customer trust: Serve as first point of contact for RFPs and security questionnaires, and maintain a trust portal with current, customer-facing evidence. ## Related Videos - [Python-Based Data Streaming Pipelines Within Minutes](https://www.wearedevelopers.com/videos/1233-python-based-data-streaming-pipelines-within-minutes) - [Outsmarting the System: What Game Cheaters Can Teach Us About Cyber Security](https://www.wearedevelopers.com/videos/1396-outsmarting-the-system-what-game-cheaters-can-teach-us-about-cyber-security) - [Edit Your Future: Queerverse Radical AI](https://www.wearedevelopers.com/videos/909-edit-your-future-queerverse-radical-ai) - [How to govern Vibe Coding for the Enterprise](https://www.wearedevelopers.com/videos/100290-how-to-govern-vibe-coding-for-the-enterprise) - [Why and when should we consider Stream Processing frameworks in our solutions](https://www.wearedevelopers.com/videos/1085-why-and-when-should-we-consider-stream-processing-frameworks-in-our-solutions) - [How to Stop Your Agents From Going Rogue - Arnav Gupta](https://www.wearedevelopers.com/videos/2152-how-to-stop-your-agents-from-going-rogue-arnav-gupta) ## Related Articles - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [13 AI Tools You Have to Try](https://www.wearedevelopers.com/magazine/219-13-ai-tools-you-have-to-try)