Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior GRC Analyst, HIPAA

DoorDash USA

About the Team At DoorDash, Security is critical to earning and maintaining trust across our global marketplace. The Governance, Risk, and Compliance team partners across Security, Engineering, Product, Legal, Privacy, IT, and business teams to translate regulatory, customer, and contractual obligations into scalable controls and practical security outcomes. We are looking for a Senior GRC Analyst, HIPAA to help mature and operate HIPAA-related security and compliance programs across DoorDash. This role will support multiple ongoing HIPAA workstreams, partner closely with engineering teams, and help ensure regulated data environments are designed, operated, and monitored in a secure, compliant, and scalable way. About the Role As a Senior GRC Analyst, HIPAA, you will be a subject matter expert for HIPAA security compliance within DoorDash’s GRC function. You will be responsible for turning legal requirements into operational controls, map them to DoorDash controls, assess gaps, drive remediation, and support audit-ready evidence across technical and operational environments. This is a senior individual contributor role for someone who has implemented and managed HIPAA programs in a technology company or similarly complex regulated environment. You will work directly with Engineering, Product, Security Engineering, Legal, IT, and business stakeholders to make HIPAA compliance practical, measurable, and sustainable. You’re excited about this opportunity because you will… Lead and support HIPAA security compliance workstreams across multiple products, platforms, systems, and engineering teams. Turn legal requirements into actionable technical and operational control requirements. Perform HIPAA readiness assessments, gap analyses, risk assessments, and control design/effectiveness reviews across cloud, SaaS, data, and internal tooling environments. Build and maintain control mappings across HIPAA, HITRUST, SOC 2, ISO 27001, NIST 800-53, and DoorDash security standards. Partner with Engineering and Security Engineering to implement scalable controls across IAM, encryption, logging and monitoring, vulnerability management, secure SDLC, incident response, data retention, and access review processes. Maintain HIPAA security program documentation, including policies, standards, procedures, control narratives, evidence requirements, risk registers, exception records, and remediation plans. Support internal and external audits, partner/customer assessments, security questionnaires, and compliance evidence collection. Partner with Legal, and Security Operations on incidents involving PHI/ePHI, including compliance impact analysis, documentation, and remediation tracking. Mature GRC tooling, workflows, dashboards, and continuous control monitoring to reduce manual compliance overhead. Provide practical guidance to technical and non-technical stakeholders so HIPAA requirements are understood, adopted, and embedded into day-to-day engineering practices. Monitor regulatory, framework, and industry changes related to HIPAA, HITRUST, healthcare security, and regulated data environments. We’re excited about you because… You have 6+ years of experience in security compliance, GRC, risk management, audit, privacy/security operations, or related information security roles. You have 3+ years of hands-on experience implementing, operating, or materially maturing HIPAA programs in a technology, SaaS, health-tech, or highly regulated environment. You have strong working knowledge of HIPAA Security Rule requirements and practical experience applying HIPAA safeguards to cloud, SaaS, data, and engineering environments. You understand how PHI/ePHI flows through modern systems and can partner with engineering teams on data classification, access controls, encryption, logging, retention, and secure data handling. You have experience with adjacent frameworks and standards such as HITRUST, SOC 2, ISO 27001, NIST 800-53, PCI DSS, GDPR or CCPA. You have led or supported audits, compliance assessments, control testing, evidence collection, risk assessments, and remediation programs. You can translate complex compliance requirements into clear, actionable tasks for Engineering, Product, Security, IT, Legal, and Privacy stakeholders. You have enough technical fluency to understand cloud architecture, APIs, IAM, CI/CD, infrastructure-as-code, logging, vulnerability management, and security monitoring concepts. You communicate clearly, write high-quality documentation, manage multiple workstreams independently, and drive cross-functional progress without direct authority. You are pragmatic: you know how to reduce real risk while enabling teams to move quickly and responsibly. Preferred Qualifications Experience working directly with Engineering or Security Engineering teams in a high-growth technology company. Experience building or scaling a HIPAA program rather than only maintaining an existing checklist. Experience with HITRUST certification, SOC 2 audits, ISO 27001 audits, or multi-framework control mapping. Experience with third-party risk management, vendor security reviews, business associate/vendor security expectations, and customer security assessments. Experience supporting privacy, security incident response, or breach assessment workflows involving regulated data. Familiarity and interest towards AI, data platform, healthcare interoperability, payments, or marketplace environments. Preferably you have also built something yourself using AI. We expect this position to be filled by 8/26/26. Compensation The successful candidate’s starting pay will fall within the pay range listed below and is determined based on job-related factors including, but not limited to, skills, experience, qualifications, work location, and market conditions. Base salary is localized according to an employee’s work location. Ranges are market-dependent and may be modified in the future. In addition to base salary, the compensation for this role includes opportunities for equity grants. Talk to your recruiter for more information. DoorDash cares about you and your overall well-being. That’s why we offer a comprehensive benefits package to all regular employees, which includes a 401(k) plan with employer matching, 16 weeks of paid parental leave, wellness benefits, commuter benefits match, paid time off and paid sick leave in compliance with applicable laws (e.g. Colorado Healthy Families and Workplaces Act). DoorDash also offers medical, dental, and vision benefits, 11 paid holidays, disability and basic life insurance, family-forming assistance, and a mental health program, among others. To learn more about our benefits, visit our careers page here. See below for paid time off details: For salaried roles: flexible paid time off/vacation, plus 80 hours of paid sick time per year. For hourly roles: vacation accrued at about 1 hour for every 25.97 hours worked (e.g. about 6.7 hours/month if working 40 hours/week; about 3.4 hours/month if working 20 hours/week), and paid sick time accrued at 1 hour for every 30 hours worked (e.g. about 5.8 hours/month if working 40 hours/week; about 2.9 hours/month if working 20 hours/week). The national base pay range for this position within the United States, including Illinois and Colorado.

$132,600—$195,000 USD

About DoorDash At DoorDash, our mission to empower local economies shapes how our team members move quickly, learn, and reiterate in order to make impactful decisions that display empathy for our range of users—from Dashers to merchant partners to consumers. We are a technology and logistics company that started by enabling door-to-door delivery, and we are looking for team members who can help us go from a company that is known as the place you order food to a company that people turn to for any and all goods. DoorDash is growing rapidly and changing constantly, which gives our team members the opportunity to share their unique perspectives, solve new challenges, and own their careers. We're committed to supporting employees’ happiness, healthiness, and overall well-being by providing comprehensive benefits and perks including premium healthcare, wellness expense reimbursement, paid parental leave and more. Our Commitment to Diversity and Inclusion We’re committed to growing and empowering a more inclusive community within our company, industry, and cities. That’s why we hire and cultivate diverse teams of people from all backgrounds, experiences, and perspectives. We believe that true innovation happens when everyone has room at the table and the tools, resources, and opportunity to excel. Statement of Non-Discrimination: In keeping with our beliefs and goals, no employee or applicant will face discrimination or harassment based on: race, color, ancestry, national origin, religion, age, gender, marital/domestic partner status, sexual orientation, gender identity or expression, disability status, or veteran status. Above and beyond discrimination and harassment based on “protected categories,” we also strive to prevent other subtler forms of inappropriate behavior (i.e., stereotyping) from ever gaining a foothold in our office. Whether blatant or hidden, barriers to success have no place at DoorDash. We value a diverse workforce – people who identify as women, non-binary or gender non-conforming, LGBTQIA+, American Indian or Native Alaskan, Black or African American, Hispanic or Latinx, Native Hawaiian or Other Pacific Islander, differently-abled, caretakers and parents, and veterans are strongly encouraged to apply. Thank you to the Level Playing Field Institute for this statement of non-discrimination. Pursuant to the San Francisco Fair Chance Ordinance, Los Angeles Fair Chance Initiative for Hiring Ordinance, and any other state or local hiring regulations, we will consider for employment any qualified applicant, including those with arrest and conviction records, in a manner consistent with the applicable regulation. If you need any accommodations, please inform your recruiting contact upon initial connection. Notice to Applicants for Jobs Located in NYC or Remote Jobs Associated With Office in NYC Only We used Covey as part of our hiring and/or promotional process for jobs in NYC and certain features may qualify it as an AEDT in NYC. As part of the hiring and/or promotion process, we provided Covey with job requirements and candidate submitted applications. We began using Covey Scout for Inbound from August 21, 2023, through December 21, 2023. We resumed using Covey Scout for Inbound again on June 29, 2024, and ceased using Covey Scout for Inbound on April 30, 2026. The Covey tool has been reviewed by an independent auditor. Results of the audit may be viewed here:

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Senior GRC Analyst, HIPAA in United States vacancy
  • $95k - $105k

     ...Job Description Job Description Sr. GRC Analyst About Subsplash Subsplash is an exciting award-winning team of 280+ mission-driven...  ...dues and subscription spend under budget. About the Role The Senior GRC Analyst acts as a strategic lead to advance security and... 
    Senior
    Temporary work
    Currently hiring
    Remote work
    Relocation

    Subsplash

    Albuquerque, NM
    15 days ago
  •  ...Hotman Group is a boutique cybersecurity and GRC consulting firm doing meaningful work...  ...You Will Do   As an Experienced or Senior GRC Analyst at Hotman Group you will work directly with...  ...including SOC 2, ISO 27001, NIST CSF, HIPAA, HITRUST, CMMC, and others  Prepare... 
    Senior
    Remote job
    Permanent employment
    Full time
    Contract work

    Hotman Group

    Remote
    28 days ago
  • $130k - $150k

     ...About This Role We’re seeking a GRC Analyst to support the day-to-day execution of our...  ...preparing audit evidence for SOC 2, ISO 27001, HIPAA, and other frameworks Partnering with...  ...diligence requests with guidance from senior team members Maintaining and updating... 
    Senior
    Temporary work

    Crusoe

    San Francisco, CA
    14 days ago
  •  ...frameworks including NIST, HITRUST, PCI, HIPAA, SOC, MAR, CMS, JCAHO, etc. The incumbent...  ...Accountant (CPA) Certified Information Systems Analyst (CISA) Certified Information Privacy...  ...skills for diverse audiences (senior management, board, peer, and team). Strong... 
    Senior
    Contract work
    For contractors
    Work at office
    Local area

    Highmark Health

    Pittsburgh, PA
    4 days ago
  •  ...three (3) years of experience working in clinical research, as an analyst or in an operational role. Prefer research experience in a...  ...research, including human subjects protection, drugs, devices, HIPAA regulations, Good Clinical Practices, coverage analysis, research... 
    Senior
    Work at office

    Parkland Health and Hospital System

    Dallas, TX
    1 day ago
  • $130k - $160k

     ...Senior Cybersecurity Risk Analyst At Danaher, our work saves lives. And each of us plays a part. Fueled...  ...privacy regulatory landscape (GDPR, HIPAA, PCI DSS, SOX) ~ Demonstrated experience...  ...origin scrutiny. Familiarity with GRC platforms (e.g., OneTrust, ServiceNow... 
    Senior
    Remote job
    Work from home
    Flexible hours

    Danaher

    Las Vegas, NV
    1 day ago
  • $77.2k - $96.5k

     ...Behind WWT's Resilient Future Step into a dynamic role as an Information Security (InfoSec) Governance, Risk, and Compliance (GRC) Analyst within Audit and Compliance, where you will be at the forefront of driving operational excellence within the Audit and... 
    Permanent employment
    Full time
    H1b
    Visa sponsorship
    Shift work

    World Wide Technology

    Edwardsville, IL
    2 days ago
  •  ...Privacy Senior Regulatory Compliance Analyst The Privacy Senior Regulatory Compliance Analyst is responsible for leading and driving complex regulatory...  ...and state privacy laws and regulations, including HIPAA, HITECH, CCPA, and other applicable healthcare data protection... 
    Senior
    Work experience placement
    Work at office

    E-Solutions

    Oakland, CA
    13 hours ago
  •  ...all employees and contractors (including HIPAA training). Establishes and maintains effective...  .... Participates in meetings with senior staff and management to identify and address...  ...of Governance, Risk, and Compliance (GRC) solutions and common control frameworks for... 
    Senior
    For contractors
    Local area

    Seminole Electric

    Tampa, FL
    3 days ago
  •  ...federally mandated disclosures. Partner with internal and external stakeholders to monitor benefit program compliance with ERISA, HIPAA, ACA, COBRA, and related laws. Support internal and external audits by preparing reports, gathering documentation, and responding... 
    Senior
    Full time
    H1b
    Immediate start

    Commure

    Mountain View, CA
    4 days ago
  •  ...Senior Risk Compliance Officer Location: On site in Memphis, TN, Knoxville, TN, Orlando, FL, Miami Lakes, FL, Longwood, FL; Little Rock, AR; Asheboro, NC; Johnson City, TN Summary The position is responsible for performing complex confidential research and investigations... 
    Senior

    First Horizon

    Longwood, FL
    1 day ago
  •  ...Senior Healthcare Business Analyst Location: Hartford, CT - Hybrid - 3 Days a Week Position Summary: We are seeking a detail oriented and analytical...  ...workflows, and reporting needs, ensuring compliance with HIPAA and other regulatory standards. Conduct gap analysis... 
    Senior
    3 days per week

    Yantran LLC

    Hartford, CT
    22 hours ago
  •  ...Arm Limited in Austin, Texas, is seeking a Senior Principal SoC Architect to drive the exploration of system-level technologies for the Infrastructure market. Candidates should have extensive experience in system architecture, power management techniques, and effective... 
    Senior

    Jobleads-US

    Austin, TX
    1 day ago
  •  ...Senior Benefits Analyst (Remote) Join a working team that is dedicated to the mission of the work we do! Teaching Strategies is an innovative...  ...Ensures compliance with all applicable regulations (ERISA, ACA, HIPAA, COBRA, etc.) Supports audits, filings (e.g., Form 5500),... 
    Senior
    Remote job
    Temporary work

    Teaching Strategies, LLC

    Denton, TX
    2 days ago
  •  ...Red Hat, Inc. is seeking a Senior Principal Software Engineer to lead initiatives in the Azure Red Hat OpenShift team. This high-impact role involves defining infrastructure patterns for ARO and guiding projects from concept to delivery, ensuring operational excellence... 
    Senior

    Jobleads-US

    Raleigh, NC
    1 day ago
  •  ...Senior Credit Risk Associate Location: McLean, VA | Dallas, TX | Tampa, FL | Jersey City, NJ Experience level: Mid-senior Experience required: 5 Years Education level: Bachelor's degree Job function: Finance Industry: Financial Services Total position... 
    Senior
    Relocation package

    Beyond SOF

    Tampa, FL
    22 hours ago
  •  ...Senior Director, Regulatory Affairs About the Company International labelling organization based in Los Angeles Industry Retail Type Privately Held About the Role The Senior Director, Regulatory Affairs will be responsible for developing and managing... 
    Senior
    Worldwide

    Confidential

    New York, NY
    2 days ago
  • $260k - $275k

    Saviynt, located in San Francisco, is hiring a Senior Principal Software Engineer to lead the development of our AI security products. You will design and implement secure and scalable workflows, work across various cloud platforms, and contribute to product direction... 
    Senior

    Jobleads-US

    San Francisco, CA
    4 days ago
  •  ...technical, analytical, and administrative support to the department and senior executives for the purpose of promoting informed strategy...  ...the Health Insurance Portability Accountability Act of 1996 (HIPAA) as described in the Notice of Privacy Practices and Privacy Policies... 
    Senior
    For contractors
    Local area
    Weekend work

    Highmark Health

    Pittsburgh, PA
    4 days ago
  •  ...Senior Risk Consultant DataVisor is the world's leading AI-powered Fraud and Risk Platform that delivers the best overall detection coverage in the industry. With an open SaaS platform that supports easy consolidation and enrichment of any data, DataVisor's fraud and... 
    Senior

    DataVisor

    Mountain View, CA
    1 day ago
  • $150.8k - $251.3k

     ...Management Framework, applicable policies, regulatory expectations, and industry standards. The role reports to an Operational Risk Senior Manager and supports providing independent and objective insights to guide and influence business risk management in the... 
    Senior
    Work experience placement
    Work at office

    M&T Bank

    Baltimore, MD
    1 day ago
  • $210k - $256.67k

    Infosys Limited is looking for a Senior Principal in SAP EWM who will manage full life cycle implementations of SAP S/4HANA, lead complex projects, and provide expert consulting services. Candidates must have at least 15 years of relevant experience, including 3-5 full... 
    Senior
    Remote job

    Jobleads-US

    Atlanta, GA
    4 days ago
  •  ...Compliance Risk Management Senior Associate Bring your expertise to JPMorgan Chase. As part of Risk Management and Compliance, you are at the center of keeping JPMorgan Chase strong and resilient. You help the firm grow its business in a responsible way by anticipating... 
    Senior

    Chase

    Tampa, FL
    2 days ago
  •  ...Compliance And Operations Risk Test Senior Specialist Join JPMorganChase to drive excellence in compliance and risk management. Leverage your analytical skills and collaborate with cross-functional teams to make a significant impact. At JPMorganChase, you'll be part... 
    Senior

    Chase

    Plano, TX
    1 day ago
  •  ...Senior Risk Analyst Enterprise Risk Management (ERM) operates as an independent second line of defense, responsible for maintaining and enforcing Talcott's risk management framework across all subsidiaries. One of our key accountabilities is to monitor key exposures... 
    Senior
    Work at office

    Talcott Financial Group

    Hartford, CT
    2 days ago
  •  ...healthcare industry. About the Role We're on the hunt for driven Senior Engineers to join our team at an exciting stage of our startup's...  ...You will develop scalable software solutions that comply with HIPAA and other security standards. What We're Looking For ~4–8+... 
    Senior
    Work at office

    Assort Health Inc.

    San Francisco, CA
    4 days ago
  • $260k - $275k

    Medium is seeking a Senior Principal Software Engineer in San Francisco to lead the design and implementation of AI security solutions. This role requires over 15 years in software engineering, with expert skills in Java, Spring, and cloud platforms such as AWS and Azure... 
    Senior

    Jobleads-US

    San Francisco, CA
    1 day ago
  • Location: Moody Outpatient Center 5th Floor Primary Purpose Responsible for analytical and operational support in the areas of compensation and compensation systems. Serves as a subject matter expert (SME) related to compensation for the maintenance, administration...
    Senior
    Contract work
    Interim role

    Parkland Health and Hospital System

    Dallas, TX
    1 day ago
  •  ...backend systems. Candidates should have a Bachelor's degree in Computer Science or Software Engineering and a strong communication record presenting to senior leadership. The position offers competitive compensation and relocation is provided. #J-18808-Ljbffr Jobleads-US
    Senior
    Relocation

    Jobleads-US

    Seattle, WA
    2 days ago
  • $167k - $260k

     ...Senior Credit Risk & Approval Specialist Wells Fargo is seeking a Senior Credit Risk & Approval Specialist to join the CIB Credit...  ...skills, including strong excel and PowerPoint skills (banking analyst or consulting background is a plus, but not required) Experience... 
    Senior
    Work experience placement
    Relocation package

    Wells Fargo

    Charlotte, NC
    22 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior GRC Analyst, HIPAA. Be the first to apply!