Senior Security Compliance Analyst

Jobtailor

Deutschland

Vor Ort

EUR 109.543 - 153.361

Vollzeit

14 Tage+

Erhalte mehr Antworten von Arbeitgebern

Versende in nur wenigen Minuten einen passgenauen Lebenslauf.

Zusammenfassung

OneStudyTeam is looking for a Senior Security Compliance Analyst to enhance security and compliance programs within the healthcare sector. The ideal candidate will lead security audits, manage ISO 27001 certification, and ensure compliance with HIPAA and other regulations.

Applicants should have over 8 years of relevant experience and a degree in Information Security or related fields. The position offers a salary range of $125,000 - $175,000 USD per year.

Qualifikationen

  • 8+ years of experience in GRC, compliance, or security audit roles are required.
  • Certifications such as ISO 27001 Lead Auditor, CISSP, CISM, CISA preferred.
  • Strong written and verbal communication skills with technical explanations for non-technical stakeholders.

Aufgaben

  • Lead and support security audits and compliance programs.
  • Prepare and manage ISO 27001 and HIPAA compliance.
  • Conduct third-party vendor risk assessments.

Kenntnisse

Governance, Risk, and Compliance (GRC)
ISO 27001
Healthcare industry experience
Risk assessments
Security frameworks familiarity

Ausbildung

Bachelor’s degree in Information Security, Computer Science, Risk Management, or related field

Tools

GRC tools (e.g., OneTrust, LogicGate, Archer, Vanta, Drata)

Jobbeschreibung

At OneStudyTeam (a Reify Health company), we specialize in speeding up clinical trials and improving patient outcomes through a cloud‑based platform used in over 6,000 research sites and 100+ countries.

We are seeking a Senior Security Compliance Analyst with expertise in Governance, Risk, and Compliance (GRC) to support and enhance our security and compliance programs in the healthcare industry.

What You’ll Be Working On:
  • Lead and support customer security audits, responding to security questionnaires and demonstrating compliance with security frameworks.
  • Prepare, coordinate, and manage ISO 27001 audits, including evidence collection, control implementation, and auditor engagement.
  • Ensure ongoing compliance with HIPAA, NIST CSF, and other regulatory requirements applicable to healthcare data security.
  • Develop and maintain policies, procedures, and security documentation to meet regulatory and contractual obligations.
  • Perform gap analyses and risk assessments to identify and remediate compliance risks.
  • Manage and improve security governance frameworks, ensuring alignment with industry best practices and business objectives.
  • Conduct third‑party vendor risk assessments, ensuring compliance with security policies and contractual obligations.
  • Monitor security controls, ensuring effectiveness and continuous improvement in alignment with security frameworks.
  • Support security awareness training initiatives, ensuring employees understand compliance responsibilities.
  • Stay current on ISO 27001, HIPAA, NIST 800-53, and other relevant standards, translating them into actionable security controls.
  • Assist in defining security metrics and reporting on compliance status and risk posture to leadership.
  • Work closely with legal, security, IT, and business teams to align compliance requirements with security operations.
What You’ll Bring to OneStudyTeam:
  • Bachelor’s degree in Information Security, Computer Science, Risk Management, or related field (or equivalent experience).
  • 8+ years of progressive experience in GRC, compliance, or security audit roles.
  • Experience in healthcare or regulated industries strongly preferred.
  • Certifications strongly preferred: ISO 27001 Lead Auditor/Implementer, CISSP, CISM, CISA, HITRUST CCSFP, CRISC.
  • Experience leading ISO 27001, SOC2, or HITRUST audits, including ISMS implementation and external audit coordination.
  • Strong understanding of NIST CSF, SOC 2, GDPR, and other security frameworks.
  • Hands‑on experience with customer security audits, including responding to security questionnaires and managing security assessments.
  • Ability to perform risk assessments, policy reviews, and compliance gap analyses.
  • Strong written and verbal communication skills, with the ability to explain technical concepts to non‑technical stakeholders.
  • Detail‑oriented with excellent organizational and project management skills.
  • Ability to work independently and collaboratively in a remote environment.
  • Familiarity with GRC tools (e.g., OneTrust, LogicGate, Archer, Vanta, Drata) is a plus.

The expected salary range for this role is $125,000 - $175,000 USD per year for full‑time team members.

We value diversity and believe the unique contributions each of us brings drives our success. We do not discriminate on the basis of race, sex, religion, color, national origin, gender identity, age, marital status, veteran status, or disability status.

This organization participates in E‑Verify (E‑Verify’s Right to Work guidance can be found here).

Mandatory Employer Disclosures:
Notice to Illinois applicants: Applicants are not obligated to disclose expunged juvenile records or adjudication, arrest, or conviction.
Notice to Connecticut applicants: OneStudyTeam may require applicants to submit to a urinalysis drug test in connection with an application for employment.
Notice to Arizona, Georgia, Indiana, and North Dakota applicants: OneStudyTeam complies with applicable laws prohibiting smoking in and around places of employment.
Notice to Massachusetts applicants: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Notice to Rhode Island applicants: OneStudyTeam complies with Rhode Island law prohibiting smoking in enclosed areas within places of employment. OneStudyTeam is also subject to is subject to Chapters 29–38 of Title 28 of the Rhode Island General Laws.
Notice to Maryland applicants: UNDER MARYLAND LAW, AN EMPLOYER MAY NOT REQUIRE OR DEMAND, AS A CONDITION OF EMPLOYMENT, PROSPECTIVE EMPLOYMENT, OR CONTINUED EMPLOYMENT, THAT AN INDIVIDUAL SUBMIT TO OR TAKE A LIE DETECTOR OR SIMILAR TEST. AN EMPLOYER WHO VIOLATES THIS LAW IS GUILTY OF A MISDEMEANOR AND SUBJECT TO A FINE NOT EXCEEDING $100.

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Senior Solutions Engineer
Senior Solutions Engineer

OneTrust • München

Vor Ort
EUR 90.000 - 120.000
Healthcare coverage
Flexible PTO
Equity RSUs
+4
Senior Solution Engineer
Senior Solution Engineer

Onetrust • München

Vor Ort
EUR 90.000 - 120.000
Healthcare coverage
Flexible PTO
Equity RSUs
+5
Senior Solution Engineer
Senior Solution Engineer

United States Digital Space LLC • München

Hybrid
EUR 70.000 - 110.000
Account Executive - Strategic Accounts
Account Executive - Strategic Accounts

United States Digital Space LLC • München

Hybrid
EUR 70.000 - 120.000
Senior Consultant – GRC (Governance, Risk & Compliance)
Senior Consultant – GRC (Governance, Risk & Compliance)

HCLTech Germany • Düsseldorf

Vor Ort
EUR 90.000 - 130.000
Director, Biostatistician (Evergreen)
Director, Biostatistician (Evergreen)

Embedded Shishya • Deutschland

Remote
EUR 161.000 - 214.000
Comprehensive benefits package
Annual bonus plan
Employee Stock Purchase Plan
Commercial Advisory Director
Commercial Advisory Director

OneTrust • München

Vor Ort
EUR 120.000 - 190.000
Comprehensive healthcare coverage
Flexible PTO
Equity RSUs
+5
Director, Regulatory & Compliance
Director, Regulatory & Compliance

Embedded Shishya • Deutschland

Remote
EUR 210.000 - 237.000
Flex PTO
Medical/Dental/Vision plan options
401(k)
+1
Commercial Advisory Director
Commercial Advisory Director

Jackalope Digital LLC • München

Hybrid
EUR 150.000 - 220.000
Healthcare coverage
Flexible PTO
Equity RSUs
+3
SOC 2 Senior Auditor - Bilingual German
SOC 2 Senior Auditor - Bilingual German

Insight Assurance • Düsseldorf

Remote
EUR 60.000 - 80.000
Flexible Paid Time Off
Performance Bonuses
100% Remote