Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Governance, Risk, and Compliance (GRC) Analyst

CareMetx

From intake to outcomes, CareMetx is dedicated to delivering industry-leading patient access solutions and support services that help patients quickly start and stay on specialty therapy treatments. We provide scalable, efficient digital hub services for pharmaceutical companies and healthcare providers, streamlining workflows with seamless integration for patient enrollment, consent, and prior authorization. Our best-in-class patient support services enhance every step of care, connecting patients, providers, and brands to drive better outcomes and accelerate time-to-therapy.

Job Title: Governance, Risk, and Compliance (GRC) Analyst

POSITION SUMMARY:

Reporting to the Chief Information Security Officer, the Governance, Risk, and Compliance (GRC) Analyst manages the day-to-day operation of CareMetx's governance, risk, and compliance program. This role ensures that all HIPAA, SOC 2, and NIST CSF 2.0 controls in the GRC platform maintain current evidence, runs the IT Risk Management process, manages external audits and customer security reviews, and supports the policy and continuity-testing programs. The Governance, Risk, and Compliance Analyst is responsible for the unmonitored (manually collected) controls and the program and process layer of compliance, while the Senior Security Engineer is responsible for the monitored (automated, technical) controls. The role works closely with the CISO, business leaders, and the Executive Leadership Team, and is the organizing force that keeps CareMetx continuously audit-ready in a HIPAA-regulated, PHI-handling environment.

PRIMARY DUTIES AND RESPONSIBILITIES:

Control & Evidence Management (GRC Platform)
  • Ensure every HIPAA, SOC 2, and NIST CSF 2.0 control in the GRC platform has current, valid evidence, refreshed at least annually.
  • Manage all unmonitored controls - the manually collected items such as policies, procedures, standards, and records - including gathering, uploading, and renewing their evidence on schedule.
  • Maintain an evidence calendar so manual controls are refreshed before they expire.
  • Maintain a control-ownership matrix recording who is accountable for every compliance item in the GRC platform, and keep it current as people and systems change.
IT Risk Management
  • Manage the IT Risk Management process end to end.
  • Collect risks from business and functional leaders on a recurring basis and document each in a maintained risk register.
  • Work with the CISO to score and prioritize risks using a consistent methodology.
  • Track remediation and treatment activity to closure and follow up with risk owners.
  • Alert business leaders when risks are untreated, overdue, or trending the wrong way.
  • Build and deliver risk reporting and presentations for the Executive Leadership Team.
Audit & Assessment Support
  • Coordinate the annual SOC 2 audit and HIPAA assessments: assemble and organize requested evidence.
  • Serve as the primary point of contact and manage day-to-day communications with external auditors.
  • Maintain year-round audit readiness so audits are a checkpoint, not a fire drill.
Customer Security Reviews
  • Complete customer security questionnaires and audit / due-diligence requests accurately and on time.
  • Maintain a reusable answer library and keep the customer trust portal content current to reduce one-off effort.
Vendor Risk Management
  • Support the vendor management process - confirm that vendors hold SOC 2 or other certifications appropriate to their criticality.
  • Report issues, such as a vendor breach or missing certification, to the Vendor Management team.
Policy & Documentation
  • Support the CISO and IT in writing, reviewing, and maintaining policies, procedures, and standards.
  • Manage the document lifecycle - version control, review cadence, approvals, and publication - and keep policy evidence aligned in the GRC platform.
Continuity & Resilience Testing
  • Schedule and coordinate required tests and exercises, including Disaster Recovery (DR), Business Continuity (BCP), and Incident Response (IR) tabletops.
  • Track completion, capture results, and file the test evidence against the relevant controls.
Compliance Oversight & Escalation
  • Monitor overall compliance posture across the three frameworks and flag gaps early.
  • Alert the CISO and management promptly whenever the organization is out of compliance - a control failing, evidence missing or expired, or an owner unresponsive.
Scope & Authority
  • Reports to the CISO, with a dotted-line relationship to the Vice President, Compliance & Risk Management; partners with the corporate Compliance and Risk Management teams to support enterprise-wide programs.
  • Manages the unmonitored / manually collected control set and the day-to-day operation of the GRC program.
  • Authority to require evidence, status updates, and risk submissions from control and risk owners across the business.
  • Escalates non-compliance and untreated risk to the CISO and management.
  • Other duties as assigned by the CISO.
Qualifications

EXPERIENCE AND EDUCATIONAL REQUIREMENTS:

Required Qualifications
  • 5+ years in governance/risk/compliance, IT audit, or security compliance, ideally in a regulated industry.
  • Hands-on experience with SOC 2 and the HIPAA Security Rule; working familiarity with NIST CSF 2.0.
  • Experience operating a GRC / compliance-automation platform and maintaining control evidence.
  • Experience running or supporting a risk management program - risk register, risk scoring, and treatment tracking.
  • Experience supporting external audits and completing customer security questionnaires.
Preferred Qualifications
  • Healthcare or other PHI / regulated-data environment experience.
  • Familiarity with NIST CSF 2.0, NIST 800-53, or HITRUST mappings.
  • Experience with a customer trust portal and security-questionnaire automation.
Certifications Preferred (any of the following)
  • CISA (Certified Information Systems Auditor).
  • CRISC (Certified in Risk and Information Systems Control).
  • CGRC (Certified in Governance, Risk and Compliance).
  • ISO 27001 Lead Auditor.
  • HCISPP (HealthCare Information Security and Privacy Practitioner).
  • CompTIA Security+ (foundational security knowledge).
MINIMUM SKILLS, KNOWLEDGE AND ABILITY REQUIREMENTS:
  • Strong writing skills for policies and procedures, and clear executive-level reporting and presentation skills.
  • Excellent organization, follow-through, and cross-functional communication; able to chase evidence and hold owners accountable diplomatically.
Physical Demands:

The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
  • While performing the duties of this job, the employee is regularly required to sit.
  • The employee must occasionally lift and/or move up to 10 pounds.
Work Environment:

The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions. The noise level in the work environment is usually moderate.

Schedule:
  • Must be flexible on schedule and hours.
  • Some Travel may be required.

CareMetx considers equivalent combinations of experience and education for most jobs. All candidates who believe they possess equivalent experience and education are encouraged to apply.

At CareMetx we work hard, we believe in what we do, and we want to be a company that does right by our employees. Our niche industry is an integral player in getting specialty products and devices to the patients who need them by managing reimbursements for those products, identifying alternative funding when insurers do not pay, and providing clinical services.

CareMetx is an equal employment opportunity employer. All qualified applicants will receive consideration for employment and will not be discriminated against based on race, color, sex, sexual orientation, gender identity, religion, disability, age, genetic information, veteran status, ancestry, or national or ethnic origin.
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Governance, Risk, and Compliance (GRC) Analyst in United States vacancy
  • $138k - $173k

    THE POSITIONOur roster has an opening with your name on itFanDuel is seeking a Senior Technology Governance, Risk & Compliance (GRC) Analyst to join its Technology GRC team as a strategic specialist supporting our first line of defense (1LOD) function. This role offers... 
    Suggested
    Temporary work
    Work at office
    Local area
    Worldwide
    Shift work

    FanDuel

    Atlanta, GA
    3 days ago
  •  ...GRC Analyst Join our team as a GRC Analyst and play a key role in regulatory compliance, IT risk management, security. You'll assess risks, support audits, and develop policies...  ...team. • Assist in the maintenance, governance, and execution of Threat and Vulnerability... 
    Suggested
    Casual work
    Work at office
    Work from home
    Home office
    Night shift
    Weekend work

    Delta Dental of Missouri

    Saint Louis, MO
    3 days ago
  •  ...Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We're partnering with the world's leading AI research labs to build smarter, safer AI - and we need practitioners who know how GRC actually works in the real world. If you've spent time... 
    Suggested
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    10 hours per week
    Flexible hours

    Alignerr

    Denver, CO
    1 day ago
  •  ...Ivo is seeking a detail-oriented and proactive GRC Analyst to support the company's compliance, risk management, and security assurance initiatives. This...  ...policies, standards, and procedures. Support AI governance and responsible AI compliance initiatives. What... 
    Suggested
    Contract work
    Work at office
    Remote work
    Visa sponsorship
    Relocation package
    Flexible hours

    IVO Inc

    San Francisco, CA
    5 days ago
  •  ...& Deeter continues to expand its technology capabilities and strengthen its security posture. We are seeking a Governance, Risk & Compliance (GRC) Analyst to support critical governance, risk management, compliance, and audit readiness initiatives. This role is ideal... 
    Suggested

    Frazier & Deeter

    Atlanta, GA
    1 day ago
  •  ...Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We're partnering with the world's leading AI research labs to build smarter, more trustworthy AI - and we need practitioners who know how GRC actually works in the real world. Your expertise... 
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours

    Alignerr

    Dallas, TX
    1 day ago
  •  ...Job Title: Governance, Risk, and Compliance (GRC) Analyst Key Responsibilities: Governance Develop, maintain, and enforce IT security policies, standards, and procedures. Support internal governance frameworks and ensure alignment with industry best... 

    PROLIM Corporation

    Austin, TX
    2 days ago
  •  ...Governance, Risk, and Compliance (GRC) Analyst We operate at the intersection of technology and law, in an industry that demands agility and innovation. Our team is dedicated to developing advanced solutions for legal professionals. Our daily work involves tackling... 
    Full time
    Flexible hours

    Fulcrum Global Technologies

    Phoenix, AZ
    2 days ago
  • Overview The IT GRC Analyst operates within the enterprise Cybersecurity Operations function and supports the Information Technology...  ...under the Chief Information Officer. This role executes governance, risk, and compliance activities aligned with regulatory frameworks and... 
    Work at office
    Remote work

    Trustmark

    Ridgeland, MS
    1 day ago
  • $80k - $100k

     ...Cybersecurity Compliance Analyst – Orlando, FL Salary: $80,000–$100,000 base + 25% bonus...  ...Cybersecurity Compliance Analyst to support governance, risk, compliance, and audit readiness...  ...years of experience in cybersecurity, GRC, IT compliance, cyber risk, audit, or... 
    Relocation package
    Shift work
    Orlando, FL
    16 days ago
  • $135k - $165k

     ...foundational to our platform and customer relationships. As we continue to scale, we are looking for a highly motivated Governance, Risk & Compliance (GRC) Analyst to support and mature Ivo's security compliance and risk management programs. Why Ivo Every civilization runs on... 
    Contract work
    Flexible hours

    Ivo

    San Francisco, CA
    5 days ago
  • ASSYST is seeking an Information Security Governance, Risk & Compliance (GRC) Analyst to support our client in administering and maintaining an established enterprise Information Security Governance, Risk, and Compliance (GRC) program. This role will focus on managing Information... 
    Work at office
    Local area

    Assyst

    Rockville, MD
    4 days ago
  • Governance, Risk & Compliance (GRC) Analyst (AI Training) About The Role We partner with the world's leading AI research teams and labs to build and train cutting-edge AI models. Right now, we're looking for experienced GRC professionals to help us shape how AI reasons... 
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours

    Alignerr

    New York, NY
    2 days ago
  • ISA Consulting is seeking a Compliance Analyst to support Security, Privacy, AI Governance, and Service Delivery within its GRC program. The role centers on maintaining compliance with...  .... The ideal candidate has 2+ years in risk, compliance, or audit, strong English writing... 

    ISA Consulting Group

    Tampa, FL
    18 hours ago
  • $60k - $70k

    Governance Risk and Compliance (GRC) Analyst US - Remote (Preference: Central/East Coast) Company Description TurnCare™ is revolutionizing patient care by leveraging advanced, data-driven technology to promote enhanced mobility, improved perfusion, and better healthcare... 
    Remote job
    For contractors
    Work experience placement
    Internship
    Local area

    TurnCare, Inc.

    Brooklyn, NY
    2 days ago
  • Governance, Risk, & Compliance (GRC) Analyst Washington, DC Remote Full-Time About This Role As a GRC Analyst, you will help organizations navigate the complex landscape of cybersecurity compliance and risk management. You will work directly with clients to assess their... 
    Full time
    Remote work

    Districttechgroup

    Washington DC
    3 days ago
  • Senior Governance, Risk, Compliance (GRC) Analyst job at Oura. New York, NY. At Oura, our mission is to empower every person to own their inner potential. With our award-winning Oura Ring and app, we help over 2.5 million people turn insights about sleep, activity, and... 
    Work at office
    Local area
    Remote work
    Flexible hours

    Itlearn360

    New York, NY
    2 days ago
  • Yamaha Motor Corporation, USA is seeking a Governance and Risk Compliance Analyst in Marietta, GA to partner with privacy and website teams. You will support...  ...consent controls, GPC activities, and broader Cyber GRC initiatives while contributing to information security... 

    Yamaha Motor U.S.A.

    Marietta, GA
    3 days ago
  •  ...security environment supporting enterprise governance, policy, compliance, and audit readiness across a complex...  ...closely with Information Security, Risk, Compliance, Legal, Audit, IT,...  ...improvement, and effective use of ServiceNow GRC/IRM and ITSM capabilities. What's In... 
    Contract work
    Remote work

    Axiom-Path

    Richmond, VA
    3 days ago
  • $150k - $200k

     ...the global economy. Join us! Overview We're hiring a GRC Senior Analyst to help build the compliance foundation powering the future of global crypto...  ...recovery runbooks. Conduct vendor and third-party risk assessments as we expand our global network of partners... 
    Remote job
    Full time
    Work at office
    2 days per week

    Mesh

    Remote
    1 day ago
  •  ...We are seeking a highly skilled and motivated Senior GRC Analyst to join our Security and Privacy team. In this role, you will own and grow RainFocus's governance, risk, and compliance program — maintaining our control framework, leading risk assessments, supporting... 
    Full time

    Rainfocus

    Remote
    1 day ago
  •  ...in strengthening enterprise security, governance, and risk management capabilities.Partner directly...  ...environment where you'll help build foundational GRC processes rather than simply...  ...across Information Security, IT, Legal, Compliance, Privacy, and business leaders to establish... 
    Contract work
    Flexible hours

    AccruePartners

    Charlotte, NC
    1 day ago
  • $130k - $170k

     ...to unlock human performance and extend healthspan. The Governance, Risk, and Compliance (GRC) team helps ensure technology and cybersecurity risks are...  ...execution-oriented Senior Governance, Risk, and Compliance Analyst to lead the day-to-day execution and support the ongoing... 
    Full time
    Work at office
    Relocation

    WHOOP

    Boston, MA
    3 days ago
  • The TeamThe Analyst Governance, Risk, and Compliance, a member of the Information Security - Governance, Risk and Compliance (GRC) team, focuses on implementing and maintaining governance frameworks, managing risk remediation activities, and ensuring adherence to regulatory... 
    Work experience placement
    Work at office
    Local area

    American Tower

    Boston, MA
    2 days ago
  •  ...RoleAs a member of the Information Security team, the IS GRC Senior Analyst - Risk & Compliance will be responsible for understanding the firm’s...  ...analysis and monitor controls.The Information Security Governance, Risk & Compliance Senior Analyst (Risk & Compliance) is... 
    Full time
    Contract work
    Work experience placement
    H1b
    Remote work
    Visa sponsorship
    Relocation package
    Monday to Friday

    AlixPartners

    Detroit, MI
    1 day ago
  • Job Summary:The IT Governance, Risk, and Compliance (GRC) Lead Analyst serves as a subject matter expert responsible for leading the design, implementation, maturity, and continuous improvement of the organization’s IT governance, risk management, and compliance programs... 
    Full time
    Work at office
    3 days per week

    Westfield Insurance

    Westfield Center, OH
    1 day ago
  •  ...Ruleset Security is offering an exciting internship opportunity for a Governance, Risk, and Compliance (GRC) Analyst. This role is perfect for students or recent graduates looking to gain hands-on experience in cybersecurity, compliance, and risk management. The internship... 
    Full time
    Internship

    Ruleset Security

    Arlington, VA
    3 days ago
  •  ...Insight Global is seeking a Technology Risk Governance Analyst to support a Fortune 100 fintech...  ...ideal candidate has experience within GRC, technology risk, or information security...  ...Technology Risk, IT Audit, Governance, Risk & Compliance (GRC), or a related field. -... 
    Remote work

    Insight Global

    United States
    1 day ago
  •  ...Job Description An R&D technology client is seeking a Senior Governance, Risk & Compliance Analyst for a contract role supporting the implementation and operationalization of an enterprise GRC platform. This role will focus on helping configure the GRC solution, establish... 
    Contract work

    Insight Global

    Conshohocken, PA
    5 days ago
  •  ...facilities in Tennessee, Arizona, and Rhode Island as well as Canada, Spain, France, Australia, and China. Governance, Risk, and Compliance (GRC) Analyst - SOX & Data Security Focus Location: Clemmons, NC Job Type: Full-time Department: Information... 
    Full time

    Hayward Industries Inc

    Clemmons, NC
    5 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Governance, Risk, and Compliance (GRC) Analyst. Be the first to apply!