JOB POSTS
Governance, Risk, and Compliance (GRC) Analyst
CAREMETX, LLC
United States (Remote)
Reporting to the Chief Information Security Officer (CISO), the Governance, Risk, and Compliance (GRC) Analyst manages the day-to-day operation of CareMetx's governance, risk, and compliance program. The role ensures HIPAA, SOC 2, and NIST CSF 2.0 controls in the GRC platform maintain current evidence, runs the IT risk management process, manages external audits and customer security reviews, and supports policy and continuity-testing programs.
KEY RESPONSIBILITIES
Control and Evidence Management: Ensure all HIPAA, SOC 2, and NIST CSF 2.0 controls in the GRC platform have current, valid evidence refreshed at least annually. Manage unmonitored controls (policies, procedures, standards, records), maintain an evidence calendar, and keep a control-ownership matrix current.
IT Risk Management: Manage the IT risk management process end to end and maintain the risk register. Collect risks from business and functional leaders, work with the CISO to score and prioritize risks, track remediation to closure, and prepare risk reporting for the Executive Leadership Team.
Audit and Assessment Support: Coordinate the annual SOC 2 audit and HIPAA assessments, serve as primary point of contact for external auditors, and maintain year-round audit readiness.
Customer Security Reviews: Complete customer security questionnaires and due diligence requests, maintain a reusable answer library, and keep customer trust-portal content current.
Vendor Risk Management: Support vendor management by confirming critical vendors hold SOC 2 or other appropriate certifications; report vendor breaches or missing certifications.
Policy and Documentation: Support the CISO and IT in writing, reviewing, and maintaining policies, procedures, and standards; manage document lifecycle and version control.
Continuity and Resilience Testing: Schedule and coordinate DR, BCP, and incident-response tabletop exercises; track completion and file test evidence.
Compliance Oversight: Monitor overall compliance posture across HIPAA, SOC 2, and NIST CSF 2.0 and escalate gaps to the CISO and management.
QUALIFICATIONS
Required: 5+ years in governance, risk, and compliance, IT audit, or security compliance, ideally in a regulated industry. Hands-on experience with SOC 2 and the HIPAA Security Rule; familiarity with NIST CSF 2.0. Experience operating a GRC/compliance-automation platform, running a risk management program, supporting external audits, and completing customer security questionnaires. Strong policy writing and executive-level reporting skills.
Preferred: Experience in healthcare or other PHI/regulated-data environments. Familiarity with NIST 800-53 or HITRUST mappings. Experience with customer trust portals and security-questionnaire automation tools.
Preferred Certifications: CISA, CRISC, CGRC, ISO 27001 Lead Auditor, HCISPP, or CompTIA Security+.
Employment type: Full-time, fully remote, with a flexible schedule. Some travel may be required.
CareMetx is an equal employment opportunity employer and considers all qualified applicants without regard to race, color, sex, sexual orientation, gender identity, religion, disability, age, genetic information, veteran status, ancestry, or national or ethnic origin.
HOW TO APPLY
Apply online via CareMetx's Paylocity job posting: https://recruiting.paylocity.com/Recruiting/Jobs/Details/4350839
Get jobs like this directly to your email!
Get the latest job postings sent directly to your email. Choose between a variety of filters to create a job alert matching your needs, and be the first one to be notified about new job posts.