Lead Security Analyst-GRC
Collective Health
At Collective Health, we’re transforming how employers and their people engage with their health benefits by seamlessly integrating cutting-edge technology, compassionate service, and world-class user experience design.As our Lead Security Analyst - GRC, you’ll lead initiatives that address the company’s—and some of our industry’s—most sophisticated and meaningful security engineering challenges. You will build relationships across all parts of the business and drive multi-functional initiatives to continuously improve our security and privacy posture. You will be responsible for building and implementing controls that can scale and optimize as we move into a context-aware security environment. What you'll do: Governance & Compliance: Evaluate and implement security controls based on frameworks such as NIST, CIS, HIPAA, SOC 2, and HITRUST.Develop and maintain policies, procedures, and documentation (controls, narratives, matrices).Lead SOC 2 and HITRUST audit engagements, from audit planning through remediation.Coordinate and monitor third-party risk assessments and compliance reviews.Own and lead BCP (Business Continuity Planning) and BIA (Business Impact Assessments) efforts.Build and maintain security risk registry Audit & Risk Management: Perform audit readiness assessments, and support internal/external audits.Partner with external auditors, control owners, and leadership to minimize business disruption.Track and drive remediation plans based on audit findings and compliance gaps.Maintain and communicate exception documentation for policy deviations.Educate and guide control/risk owners on their responsibilities. Advisory & Communication: Act as a liaison between technical and non-technical stakeholders.Respond to security questionnaires, RFIs, and client compliance inquiries.Develop and deliver security awareness and training programs.Provide executive reporting on program status, risks, and overall health. To be successful in this role, you'll need: Required: 8+ years in cybersecurity, GRC, audit, or risk/compliance roles.Experience managing SOC 2 / HITRUST audits, especially in cloud-native environments.Strong working knowledge of security frameworks and regulatory requirements.Demonstrated policy, data management, and risk mitigation capabilities.Familiarity with GRC tools and audit processes.Excellent communication and cross-functional collaboration skills. Preferred (Nice to Haves): Big 4 accounting firm background.Professional certifications: CISSP, CISA, CRISC, CISM, or similar. Pay Transparency Statement This is a hybrid position based out of one of our offices: Plano, TX, or Lehi, UT. Hybrid employees are expected to be in the office two days per week.#LI-hybrid The actual pay rate offered within the range will depend on factors including geographic location, qualifications, experience, and internal equity. In addition to the [salary/hourly rate], you will be eligible for 205,000 stock options and benefits like health insurance, 401k, and paid time off. Learn more about our benefits at Why Join Us? Mission-driven culture that values innovation, collaboration, and a commitment to excellence in healthcare Impactful projects that shape the future of our organization Opportunities for professional development through internal mobility opportunities, mentorship programs, and courses tailored to your interests Flexible work arrangements and a supportive work-life balance We are an
$123.7k - $254.67k
...philosophy and how we use AI in our recruiting process here.Pinterest’s Security team (Pinfosec) is seeking an IC14 Security Engineer - Security Governance, Risk & Compliance (GRC Senior Analyst) to support and strengthen our security governance and assurance programs...SuggestedInterim roleWork at officeLocal areaRelocationRelocation package- ...Valon is seeking a Sr. Security Analyst to join our Security team in the US. You will work closely with the Head of Security GRC to protect our systems, cloud infrastructure, products, and customer data. You will apply risk and compliance principles, build AI-supported...Suggested
$118.68k - $175.8k
...company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam.Team:The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s security organization, focused on enabling the business by proactively managing...SuggestedWork experience placementWork at officeLocal area$153k - $215k
...Work directly with Engineering to embed security and privacy controls into our products, including... ...you'll bring: ~5+ years in privacy, GRC, or security compliance, ideally with time... ..., CIPP/E, CIPP/US, CISA, CISSP, ISO 27001 Lead Implementer, or ISO 27701 Lead Implementer...SuggestedContract workWork at officeFlexible hours- ...Job Description Job Description Job43 – EITS Security Risk Analyst B (Engagement) Location: 100% Remote Max Submissions: 5 Proposed... ...internal risk reviews, assessments, and exceptions using a GRC tool . ???? Governance & Compliance Document and maintain...SuggestedImmediate startRemote workFlexible hours
$117.2k - $176.7k
...of it all.Ready to level-up your career at the company leading workforce transformation in the agentic era? You’re in... ...are the future of Salesforce.The ExperienceEnterprise Security is looking for a Senior Analyst to support our Business Information Security Officers (...Full time- ...Airwallex is seeking a Senior Product Manager for Identity & User Security to scale onboarding, verification, authentication, recovery, and notifications. You will partner with Engineering, Design, Risk, Compliance, Operations, Security and Data Science to deliver resilient...
- ...Doist is seeking a Safeguards Enforcement Analyst on the account abuse team to build and execute enforcement workflows that keep our products safe, focusing on detecting and mitigating potential harm. You will drive enforcement areas including access controls and identity...
- ...Security ContractorRequired Skills & ExperienceMust-haves5+ years in IT security, identity, or security-minded IT ops at a tech company.Production Okta (or Entra) and an MDM (Kandji (Iru), Jamf, or Intune). Apple fleet experience.You have done access reviews and offboarding...For contractors
- ...Job Description Security Analyst - Endpoint Security & Infrastructure Location: Daly City, California, USA Work Mode: Onsite Employment Type: Full-Time Eligibility: Authorized to work in the US without sponsorship Experience: 5+ Years We...Full timeImmediate startShift work
$90k - $100k
...Americans on food assistance. Backed by leading fintech investors, Forage is a fast-... ...are looking for: We’re looking for a Security Analyst to help keep Forage’s security and compliance... ...: ~1-4 years of experience in GRC, security compliance, IT audit or security...Work at office- ...Information Security Analyst Location: San Francisco, CA; Los Angeles, CA; Salt Lake City, Utah Duration: 12+ Months, 5 days onsite Must Have: SPL that Splunk uses Actual incident tickets – resolve actual security incident tickets Qualifications: Bachelor's degree in...Contract workWork at office
$151.05k - $166.95k
...Digital Finance is expanding its Information Security function, and this is the team's first... ...impact. As Senior Security Operations Analyst (Detection & Response), you will be the second... ..., partnering directly with the security lead to detect, investigate, and contain...Temporary workWork experience placementImmediate startRemote workHome officeFlexible hours2 days per week3 days per week1 day per week$180k - $258k
...AI-driven transformation of healthcare payments and eliminate administrative friction for good.Role OverviewWe are seeking a Security GRC Lead to build our first in-house GRC program from the ground up. In this role, you won't just write policies or collect manual screenshots...- ...on LinkedIn, Facebook , Instagram , X and YouTube. Job Description Working in the Border Security operations space, the Associate Border Security Analyst performs the day-to-day operations on Firewalls, IPS and IDS platforms and Zscaler....Full timeTemporary workLocal areaWeekend work
- ...Position: IAM Remediation & Identity Security Analyst Location: Remote (working PST hours) Contract: 6+Months Overview We are seeking an experienced Identity & Access Management (IAM) professional to support remediation efforts following a recent...Contract workRemote work
$111k - $135k
...welcome the challenge. What you’ll do As a Risk & Compliance Lead at Brex, you will play a critical role in ensuring compliance... .... Work closely with various departments (Legal, People, GRC) to implement or enhance compliance program initiatives, such as...Full timeFixed term contractWork at officeRemote workWork from home$117k - $175k
...working at least three days a week in the office. As a Senior Lead Health Actuarial Consultant , you will manage client projects... ...primary financial contact for clients while providing direction to analysts and associates. We will count on you to: ~ Lead routine...Minimum wageFull timeWork at officeLocal areaRemote workFlexible hours3 days per week1 day per week$150k - $225.5k
...at least three days a week in the office. As a Sr. Principal Lead Health Actuary Consultant , you'll manage client projects... ...negotiations. You’ll create deliverables, provide direction to analysts and associates, and serve as one of the primary financial client...Minimum wageFull timeWork at officeLocal areaRemote workFlexible hours3 days per week1 day per week- ...angel operators in the valley. The Opportunity We’re hiring a Security Lead to build and own the security function at Petual. You’ll... ...securing enterprise SaaS handling sensitive data, ideally in fintech, GRC, or another regulated space Experience with AWS, Kubernetes,...
$120k
...FinanceIndustry:Technology OverviewHoulihan Lokey, Inc. (NYSE:HLI) is a leading global investment bank recognized for delivering independent... ...on number of transactions. Job DescriptionAs an Experienced Analyst, you will:At least 1 full year of investment banking experience...Full time$110k
...Sandler is currently seeking a Class of 2027 Investment Banking Analyst for our Technology team in our San Francisco, CA office.... ...will be graduating in May/June 2027 are encouraged to apply. As a leading investment bank, we enable growth and success for our clients through...Full timeWork at officeWork visa$100k - $110k
...Oppenheimer & Co. Inc. (Oppenheimer) is a leading middle-market investment bank and full-... ...services industry, including retail securities brokerage, institutional sales and trading... ...is actively looking for an experienced Analyst (2nd / 3rd year) to join our team in San...Immediate startMonday to Friday$110k - $135k
Application Deadline:Address:180 Montgomery St.Job Family Group:Capital Mrkts Sales & ServiceThe salary range for this role is $110,000 up to $135,000 USD (subject to the candidate meeting the specific skills, experience, education, and qualification requirements)Provides...Full timeContract workPart timeLocal area$125k
...diligence activities at the direction of the Investment Banking team lead. Work closely with client staff to advance projects, gathering... ...training and mentorship to summer interns and less experienced Analysts.Responsibilities include but may not be limited to:Perform...Temporary workSummer internship$182.75k - $215k
...unlock the opportunities of tomorrow. As a Lead Product Marketing Manager focused on our... ...focus on governance, risk, and compliance (GRC) to product positioning, while serving as... ...@carta-external.com domain. Report any contact from unapproved domains to security@carta.com.Full time- ...University of California, San Francisco seeks an OCI Administrator to lead and optimize UCSF's Oracle Cloud Infrastructure environment.... ..., and compute resources while enforcing IAM policies and security controls. You will partner with security, database, and application...
- ...Description Security Supervisor Have a passion for service? Ready to build a career, not just find another job? M1 Global has the opportunity you've been looking for! About Us: At M1 Global, we are reshaping the security industry with a dynamic, service-...Weekly payLocal areaFlexible hours
$40.79k - $55.12k
...to work. Job Overview As an Asset Protection Officer, you are a visible and welcoming presence who helps create a safe, secure, and service-focused shopping environment. Stationed at key entrances and high-shortage areas, you help deter theft, identify potential...Full timePart timeWork at officeAll shiftsFlexible hoursAfternoon shift$70.98k
...calls to assist both guests and associates with respect to safety, security and hotel operations. Initiate and follow up with all... ...emergency situations by knowing all hotel safety procedures and leading/directing guests and associates to safety. Record, report,...Temporary workFlexible hoursShift workNight shiftWeekend workDay shiftAfternoon shift
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Lead Security Analyst-GRC. Be the first to apply!
- security analyst San Francisco, CA
- work from home security analyst San Francisco, CA
- information security compliance analyst San Francisco, CA
- junior security analyst San Francisco, CA
- cloud security analyst San Francisco, CA
- security operations analyst San Francisco, CA
- rate analyst San Francisco, CA
- information security analyst San Francisco, CA
- bond analyst San Francisco, CA
- entry level information security analyst San Francisco, CA



