FREE ACCESS
5,000–10,000 jobs/day
See all jobs on JobTailor
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

GRC Analyst
US Anesthesia PartnersGRC Analyst strengthening USAP’s healthcare security governance and compliance program. Managing controls, risk assessments, audits, policies, and third-party vendor risk.
Posted 8/4/2026full-timeRemote • Alaska, California, Hawaii • 🇺🇸 United StatesMid-LevelSenior💰 $80,900 - $137,600 per yearWebsite
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in governance, risk, and compliance (GRC) frameworks, including HIPAA, NIST, and SOC 2, while effectively managing risk assessments and control procedures. Proficient in automating workflows and collaborating with cross-functional teams to enhance compliance and security measures.
Highest-signal resume keywords
Governance, Risk, And Compliance (GRC)Risk Assessment And ManagementControl Frameworks And ProceduresCertified Information Systems Auditor (CISA)Certified Risk And Information Systems Control (CRISC)
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Control Framework DesignRisk Workflow AutomationControl Testing And Evidence CollectionRisk Register MonitoringPolicy Review And ApprovalVendor Risk AssessmentKey Risk Indicators DevelopmentCompliance Framework FamiliarityControl Effectiveness TestingAudit Evidence Gathering
Soft Skills
Excellent Written And Verbal CommunicationCollaboration Across Cross-Functional TeamsAbility To Manage Multiple PrioritiesIndependent Work Capability
Tools & Technologies
GRC PlatformRisk Management SoftwareAudit Management Tools
Certifications & Qualifications
Certified Information Systems Auditor (CISA)Certified Risk And Information Systems Control (CRISC)Certified Information Security Manager (CISM)CompTIA Security+ISO 27001 Lead Auditor
Industry Keywords
HIPAANISTSOC 2HITRUSTCompliance FrameworksInformation SecurityIT Governance
Tech Stack
Tools & technologiesCyber Security
About the role
Key responsibilities & impact- Design, configure, and govern control frameworks and risk workflows within the GRC platform
- Establish and maintain control procedures aligned with internal policy, HIPAA, HITRUST, PCI, SOC 2, NIST, and other applicable frameworks
- Develop and maintain control libraries, including narratives, ownership assignments, testing frequency, and evidence requirements
- Monitor and update risk registers, including risk tracking, scoring, and prioritization
- Automate control testing, evidence collection, attestations, and remediation workflows
- Track policy review cycles and maintain current documentation
- Lead information security risk assessments across IT, operational, and third-party domains
- Perform control walkthroughs and operating effectiveness testing; document results and control gaps
- Collaborate with internal teams and external auditors on audits and assessments
- Prepare reports, dashboards, and metrics on control effectiveness, risk status, and compliance gaps
- Map controls to regulatory and framework requirements
- Gather audit evidence, coordinate stakeholder responses, and track remediation through closure
- Manage audit findings, corrective action plans, and remediation timelines
- Guide risk assessments, document findings, and support evidence management
- Develop and report key risk indicators and key performance indicators
- Maintain risk scoring methodologies and escalate significant risks and control deficiencies
- Lead information security policy, procedure, standard, and guideline lifecycle management
- Direct policy review and approval workflows
- Evaluate third-party vendors for security and compliance risks
- Track vendor risk assessments, reassessment cycles, and risk ratings
- Develop and monitor vendor remediation action plans
- Support vendor onboarding and offboarding risk reviews
- Enhance GRC processes and workflows, champion automation and integration, and support maturity benchmarking
- Perform other duties and responsibilities as assigned
Requirements
What you’ll need- Bachelor’s degree in information security, cybersecurity, computer science, information technology, business administration, or a closely related field required
- Equivalent experience may be considered in lieu of a degree, such as 4+ years of relevant information security, compliance, or GRC experience
- Minimum of 5 years relevant experience in governance, risk, and compliance functions within IT or information security
- Certified Information Systems Auditor (CISA) preferred
- Certified Risk and Information Systems Control (CRISC) preferred
- Certified Information Security Manager (CISM) preferred
- Other relevant certifications, such as CompTIA Security+ or ISO 27001 Lead Auditor, preferred
- Prior experience implementing, managing, or auditing security policies and procedures
- Familiarity with HIPAA, NIST CSF, SOC 2, HITRUST, and related compliance frameworks
- Prior experience conducting risk assessments and supporting risk management activities
- Excellent written and verbal communication skills, including communicating technical concepts and compliance requirements to technical and non-technical stakeholders
- Ability to manage multiple priorities, work independently, and collaborate across cross-functional teams
- Must reside in an eligible U.S. location; USAP does not hire candidates residing in California, Hawaii, or Alaska
- Ability to complete the physical requirements of the job with or without reasonable accommodation
- Ability to use office equipment and communicate verbally and in writing
Benefits
Comp & perks- Base pay estimate of $80,900 - $137,600 annually
- Eligible for an annual bonus
- Equal employment opportunities regardless of protected characteristics