GRC/IT Compliance Analyst
$108k - $130kCleerly
About Cleerly
We’re Cleerly – a healthcare company that’s revolutionizing how heart disease is diagnosed, treated, and tracked. We were founded in 2017 by one of the world’s leading cardiologists and are a growing team of world-class engineering, operations, medical affairs, marketing, and sales leaders. We raised $223M in Series C funding in 2022 which has enabled rapid growth and continued support of our mission. In December 2024 we received an additional $106M in a Series C extension funding. Most of our teams work remotely and have access to our offices in Denver, Colorado, New, York, New York, Dallas, Texas, and Lisbon, Portugal with some roles requiring you to be on-site in a location.
Cleerly has created a new standard of care for heart disease through value-based, AI-driven precision diagnostic solutions with the goal of helping prevent heart attacks. Our technology goes beyond traditional measures of heart disease by enabling comprehensive quantification and characterization of atherosclerosis, or plaque buildup, in each of the heart arteries. Cleerly’s solutions are supported by more than a decade of performing some of the world’s largest clinical trials to identify important findings beyond symptoms that increase a person’s risk of heart attacks.
At Cleerly, we collaborate digitally and use a wide variety of systems. Our people use Google Workspace (GMail, Drive, Docs, Sheets, Slides), Slack, Confluence/Jira, and Zoom Video, prior experience in these areas is a plus. Role or department specific technology needs may vary and will be listed as requirements in the job description.
While we are mostly a remote company, travel is required for some team meetings and cross function projects typically once per month or once per quarter, for some roles like sales or external facing roles travel could be up to 90% of the time.
Cleerly is committed to providing safe and effective medical software that meets customer needs and our intended use. The adherence to all applicable regulatory and statutory requirements establishes a clear framework for setting measurable quality objectives. Our commitment to continually improving our products and processes proactively manages risks, ensuring ongoing compliance throughout the entire software lifecycle. Understanding this role's relevance and importance is critical to achieving Cleerly's quality objectives.
About the Opportunity
Our Information Security team is growing, and we have an immediate opening for a GRC and IT Compliance Analyst to help support and execute Cleerly’s security and compliance objectives. Reporting to the Director of Information Security, this role will be a multi-faceted specialist function that focuses on GRC, IT compliance, and risk management, as well as executing on core security-related audits and control assessments. The ideal candidate is a self-motivated individual who is great at task and time management and is willing to learn and adapt to changing regulatory environments.
Responsibilities
You will work closely with our Information Security leadership and cross-functional teams to drive GRC initiatives and ensure the continuous monitoring of security controls. On any given day, you will be:
- Build and implement a new enterprise risk assessment platform to streamline compliance workflows;
- Continuously monitor and update the risk platform to reflect evolving threats and regulatory requirements;
- Participate in risk analysis and features development processes to proactively identify risks to our regulated products;
- Continuously monitor and evaluate internal controls for areas of improvement;
- Conduct user access reviews to applications and services;
- Periodically review policies and procedures for compliance with best practices and compliance frameworks;
- Assist in owning and drafting documents for FDA regulatory submissions.
Requirements
- 5-7 years of experience in security or compliance analysis, IT risk assessment, risk management, or assurance/advisory experience over IT/IS general controls;
- BS degree in Management Information Systems, Computer Science, Accounting with ITGC experience, Engineering, Cybersecurity, Bio-Medical Engineering, or a related field;
- Experience with GRC software implementation;
- Experience with FDA regulatory submissions and SaMD (Software as a Medical Device) regulations;
- Proven experience in enterprise risk management (ERM) frameworks, risk identification, and qualitative/quantitative risk assessment methodologies;
- Previous experience working within a startup environment;
- Experience with Agile/Scrum environments and integrating security/compliance into the SDLC;
- Strong understanding of internal controls necessary to meet compliance frameworks such as ISO 27001, HITRUST, and SOC 2;
- Excellent verbal and written communication skill sets for addressing security concerns from internal stakeholders within the company.
Impress us more
- CISA, CISM, CISSP, CRISC, or related certifications;
- Experience in the digital healthcare industry;
- Experience with open-source GRC tooling such as CISO Advisor or Eramba is a plus.
Compensation
The base salary range for this role varies by location and is aligned to market benchmarks.
- Candidates located in higher-cost labor markets , including California, Washington, New York, New Jersey, Connecticut, Massachusetts, and Washington, DC represent the middle to high end of the range, while candidates located in all other U.S. locations represent the low to middle end of the range.
- Final compensation is determined based on location, experience, skills, and internal equity.
This role is eligible for a XX% target annual bonus , resulting in the following base salary and Total Target Compensation (TTC) ranges:
- Base Salary: $108,000 - $130,000
- TTC: $118,800 - $143,000
*Total Target Compensation (TTC): Total Cash Compensation (including base pay, variable pay, commission, bonuses, etc.) Additionally, stock options, paid benefits, and employee perks are part of your total rewards.
Working at Cleerly takes HEART. Discover our Core Values:
- H: Humility - be a servant leader
- E: Excellence - deliver world-changing results
- A: Accountability - do what you say; expect the same from others
- R: Remarkable - inspire & innovate with impact
- T: Teamwork - together we win
Don’t meet 100 percent of the qualifications? Apply anyway and help us diversify our candidate pool and workforce. We value experience, whether gained formally or informally on the job or through other experiences. Job duties, activities and responsibilities are subject to change by our company.
OUR COMPANY IS AN EQUAL OPPORTUNITY EMPLOYER. We do not discriminate on the basis of race, color, national origin, ancestry, citizenship status, protected veteran status, religion, physical or mental disability, marital status, sex, sexual orientation, gender identity or expression, age, or any other basis protected by law, ordinance, or regulation.
For more information see our Privacy Policy ( All official emails will come from @cleerlyhealth.com email accounts.
#Cleerly
- Overview The IT GRC Analyst operates within the enterprise Cybersecurity Operations function and supports the Information Technology, Information... ...Officer. This role executes governance, risk, and compliance activities aligned with regulatory frameworks and internal policies...SuggestedWork at officeRemote work
- ...supporting enterprise governance, policy, compliance, and audit readiness across a complex organization... ...Security, Risk, Compliance, Legal, Audit, IT, application owners, and business... ...improvement, and effective use of ServiceNow GRC/IRM and ITSM capabilities. What's In...SuggestedContract workRemote work
$80.05k - $165k
About the Role:Responsible for leading Cybersecurity and IT governance, risk, and compliance efforts, including the establishment and maintenance of IT... ..., assignment, remediation tracking, and closure of GRC-related issues in ServiceNow, ensuring timely resolution,...SuggestedFull timeWork at office- ...The GRC Cybersecurity Analyst III is a senior level contributor responsible for leading ICCU’s Governance, Risk, and Compliance (GRC) initiatives within the scope of the IT domain. This role provides strategic oversight of cyber and IT operational risk assessments, regulatory...SuggestedFull timeWork experience placementWork at office
$55 - $80 per hour
...IT GRC Analyst Remote, USA Compensation: $55 - $80 per hour Contract Length: 6-month Contract to Hire Hours: Standard full-time schedule... ...role in supporting the organization's IT Governance, Risk, and Compliance (GRC) program, focusing on security governance, regulatory...SuggestedHourly payFull timeContract workWork at officeLocal areaImmediate startRemote workFlexible hours$99k - $225k
Enterprise Cybersecurity GRC Governance AnalystThe Opportunity: The Enterprise Cybersecurity (ECS) Governance, Risk, and Compliance (GRC) team is seeking an experienced Information System Security Officer (ISSO) to bridge the gap between high-level policy and technical...Full timeContract workPart timeWork at officeLocal areaRemote work- ...RoleAs a member of the Information Security team, the IS GRC Senior Analyst - Risk & Compliance will be responsible for understanding the firm’s security... ...audit activities. This role will consult and interface with IT leadership, IT staff, and non-IT departments to conduct...Full timeContract workWork experience placementH1bRemote workVisa sponsorshipRelocation packageMonday to Friday
- Medasource is seeking an IT GRC Analyst to join our IT Security and Governance team on a 6-month contract-to-hire basis, working remotely... ...the USA. The role focuses on security governance, regulatory compliance, risk management, audit readiness, policy administration, and...Remote jobContract work
- Medasource is seeking an IT GRC Analyst to join the IT Security and Governance team on a 6-month contract-to-hire basis, remote within the USA. The role focuses on governance, risk, and compliance across HIPAA, SOC 2, and NIST, collaborating with IT, Security, Privacy,...Remote jobContract work
- Trustmark in Ridgeland, MS is seeking an IT GRC Analyst to oversee governance, risk, and compliance activities. The role includes coordinating compliance efforts, executing IT assessments, and developing policies. The ideal candidate will hold a Bachelor's in information...Remote job
$51 per hour
...Cybersecurity GRC Analyst (Remote) Location: 100% Remote Rate: $51/hour (No PTO) Overview... ...risk management, governance, and compliance initiatives. This role is responsible for... ...governance, risk management, compliance, IT audit, and security controls, along with...Temporary workWork at officeLocal areaRemote work- ...Cybersecurity Governance, Risk & Compliance (GRC) Analyst We're looking for a Cybersecurity Governance, Risk & Compliance (GRC) analyst who will... ...in Cybersecurity Governance, Risk & Compliance (GRC), IT Audit, Risk Management, Data Protection or a similar cybersecurity...Remote work
$66.3k - $114.29k
...Cybersecurity GRC Analyst Western National is seeking a Cybersecurity GRC Analyst to join our team! The individual in this role will... ...'s information security program by supporting regulatory compliance, managing third-party security risk, advancing security framework...Full timeWork at officeLocal areaRemote workWork visaFlexible hours- ...Opportunity Ivo is seeking a detail-oriented and proactive GRC Analyst to support the company's compliance, risk management, and security assurance initiatives.... ..., and partnering cross-functionally with engineering, IT, legal, HR, and business stakeholders. This is a...Contract workWork at officeRemote workVisa sponsorshipRelocation packageFlexible hours
- ...GRC Analyst Join our team as a GRC Analyst and play a key role in regulatory compliance, IT risk management, security. You'll assess risks, support audits, and develop policies that align with industry standards. If you have a solid IT security background, experience...Casual workWork at officeWork from homeHome officeNight shiftWeekend work
- ...Governance, Risk & Compliance (GrC) Analyst We're partnering with the world's leading AI research labs to build smarter, more trustworthy AI — and we need practitioners who know how GRC actually works in the real world. Your expertise in security policies, compliance...Hourly payOngoing contractContract workFreelanceRemote workFlexible hours
$57k - $113k
...Dallas, TX Detroit, MI Chicago, IL Charlotte, NC Summary The Sr GRC Programmer/Analyst modifies existing software/application programs, which are... ...on customer service, and the ability to work well with other IT, vendor, and business groups. Microsoft Office experience. Exempt...Full timeH1bWork at officeRemote workWork from homeFlexible hours$115k - $120k
Follett Content Solutions is hiring a Cybersecurity GRC Analyst in McHenry, IL or remote for the right person. This full-time... .... The analyst will strengthen governance, risk, and compliance postures by formalizing IT policies, operationalizing Microsoft Purview, and ensuring...Remote jobFull timeWork at office- Follett Content Solutions is hiring a Cybersecurity GRC Analyst to strengthen governance, risk, and compliance by formalizing IT policies, operationalizing Microsoft Purview, and ensuring audit readiness. This exempt, full-time role is based in McHenry, IL or remote for...Remote jobFull timeWork at office
- ...Impact:Atlas Energy is seeking a Senior SOX Compliance Analyst to support and mature our Sarbanes-Oxley... ...This role is responsible for assessing IT controls, performing testing,... ..., ISO 27001, or SOC 1/2.Experience with GRC platforms (e.g., AuditBoard, Archer), IAM...Local areaImmediate startRemote work
$15k - $120k
...every student. We are currently hiring for Cybersecurity GRC Analyst. This position is an exempt full-time position located... ...strengthening the organization’s governance, risk, and compliance posture by formalizing IT policies, operationalizing Microsoft Purview, and...Full timeWork experience placementCurrently hiringWork at officeRemote workWorldwide$60k - $70k
Governance Risk and Compliance (GRC) Analyst US - Remote (Preference: Central/East Coast) Company Description TurnCare™ is revolutionizing patient... ..., or speci al inter est . Bonus if degree in cybersecurity, IT/Information Systems, Computer Science, or related field of...Remote jobFor contractorsWork experience placementInternshipLocal area- Governance, Risk, & Compliance (GRC) Analyst Washington, DC Remote Full-Time About This Role As a GRC Analyst, you will help organizations navigate the complex landscape of cybersecurity compliance and risk management. You will work directly with clients to assess their...Full timeRemote work
- Senior Governance, Risk, Compliance (GRC) Analyst job at Oura. New York, NY. At Oura, our mission is to empower every person to own their inner... ...on our team if you have: Experience: 6+ years leading GRC, IT compliance, security, risk management projects. Compliance...Work at officeLocal areaRemote workFlexible hours
- ...Opportunity Ivo is seeking a detail-oriented and proactive GRC Analyst to support the company's compliance, risk management, and security assurance initiatives.... ..., and partnering cross-functionally with engineering, IT, legal, HR, and business stakeholders. This is a...Contract workWork at officeRemote workVisa sponsorshipRelocation packageFlexible hours
- ...Job Title: IT Compliance Analyst Location: Tempe, AZ Division: Operations Department: IT Operations About Us Quantum Computing... ...Analyst ● In-depth knowledge and hands on experience with GRC tools ● Experience working with multiple security frameworks...Remote work
$105k - $130k
...IT Compliance Analyst Billerica, MA (Hybrid) Quanterix is a global leader in ultra-sensitive biomarker detection, enabling breakthroughs... ...such as CISA, CRISC, CISSP, or similar Experience with GRC tools and compliance tracking systems Strong documentation...Work at officeWork from home$150k - $200k
GFT is seeking a Principal Cybersecurity Compliance Analyst to join our Security and Safety team in... ...improvement of governance, risk, and compliance (GRC) programs aligned with FERC (D2SI SPHP... ....Collaborate with cybersecurity, IT, OT, engineering, legal, and enterprise...Full timeWork at officeRemote work- ...community. Description JOB DESCRIPTION: The Senior IT GRC (Governance, Risk, and Compliance) Analyst oversees technical design, implementation, maintenance,... ..., risk remediation, continuous monitoring, and IT compliance documentation and reporting efforts. Coordinates...Work experience placementRemote workWork from homeFlexible hours
- Follett Content Solutions is seeking a Cybersecurity GRC Analyst in McHenry, IL or remote for the right candidate. The role requires 7-10 years in IT or governance, risk and compliance, with a focus on SOC 2, NIST CSF, and PCI DSS alignment. The position offers a hybrid...Work at officeRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to GRC/IT Compliance Analyst. Be the first to apply!



