A complete application in a minute — tailored resume and cover letter, ready to send.
Cone Health is seeking a Senior GRC Analyst to collaborate with process owners, internal and external auditors, and stakeholders to review, monitor, and resolve cybersecurity risk. You will support HITRUST, HIPAA and NIST CSF audits and attestations, respond to assessments, and ensure compliance with SOC2, ISO 27001, PCI-DSS, SOX, and other GRC activities.
The role involves implementing internal and external assessments, managing the lifecycle of audits, and contributing to the IT compliance
The Governance, Risk & Compliance (GRC) Analyst - Senior will collaborate with process owners, internal auditors, external auditors, and other stakeholders in order to assist in reviewing, monitoring, and resolving cybersecurity risk. This includes helping the organization manage HITRUST, HIPAA and NIST Common Security Framework (CSF) audits and attestations. By supporting the implementation of internal and external assessments, responding to and managing the full lifecycle of compliance audits, and ensuring compliance with existing and emerging regulations and standards including SOC2, ISO 27001, PCI-DSS, SOX, and other GRC activities, the Principal GRC Analyst will also contribute to managing the organization's IT compliance program.