Governance, Risk & Compliance Analyst (Third-Party Risk Analyst)

recruit22

Chicago (IL)

On-site

USD 65,000 - 90,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

A leading recruitment firm is seeking a Governance, Risk & Compliance (GRC) Analyst in Chicago to enhance risk management strategies within the healthcare sector. The successful candidate will coordinate vendor assessments, manage audits, and maintain compliance with regulatory standards. Responsibilities also include developing GRC platforms and security policies. Ideal candidates have 2+ years in IT Security and familiarity with cybersecurity frameworks such as HIPAA and PCI DSS. Relevant certifications are preferable.

Qualifications

  • 2+ years of experience in Information Security, IT Security, or IT Risk Management.
  • Familiarity with GRC platforms and cybersecurity frameworks such as HIPAA, PCI DSS, and NIST 800.
  • Ability to manage multiple tasks independently in a fast-paced environment.

Responsibilities

  • Support enterprise risk strategy by identifying and managing key risks.
  • Coordinate third-party vendor risk assessments and maintain associated controls.
  • Assist with audit processes including SOC 2, HIPAA, and HITRUST.
  • Develop and implement security policies, procedures, and reporting mechanisms.
  • Design, deploy, and maintain the GRC platform to support risk and compliance initiatives.
  • Lead third-party risk management efforts and contribute to BC/DR planning.
  • Respond to security-related inquiries and draft technical reports.

Skills

Information Security
Project Management
Strong Communication
Organizational Skills

Education

University degree in Information Security or related field
University degree in related field

Tools

GRC platforms
Cybersecurity frameworks

Job description

recruit22 is looking for a Governance, Risk & Compliance (GRC) Analyst to join one of our clients in the healthcare sector. The Governance, Risk & Compliance (GRC) Analyst plays a key role in supporting the organization's risk management strategy, with a focus on third-party risk. This role involves coordinating vendor assessments, supporting audit activities, and maintaining compliance with industry standards and regulatory frameworks. The analyst will also contribute to the development and maintenance of GRC platforms and security policies.

Responsibilities
  • Support enterprise risk strategy by identifying, reporting, and managing remediation activities for key risks.
  • Coordinate third-party vendor risk assessments, conduct gap analyses, and maintain associated controls and metrics.
  • Assist with internal and external audit processes, including SOC 2, HIPAA, and HITRUST.
  • Develop and implement security policies, procedures, and reporting mechanisms.
  • Design, deploy, and maintain the GRC platform to support risk and compliance initiatives.
  • Lead third-party risk management efforts and contribute to incident response and business continuity/disaster recovery (BC/DR) planning.
  • Respond to security-related inquiries, draft technical reports, and stay informed on evolving security regulations and best practices.
Required Qualifications
  • University degree in Information Security, Computer Science, Information Technology, or equivalent experience.
  • 2 or more years of experience in Information Security, IT Security, or IT Risk Management.
  • Familiarity with GRC platforms and cybersecurity frameworks such as HIPAA, PCI DSS, and NIST 800.
  • Strong communication, organizational, and project management skills.
  • Ability to manage multiple tasks independently in a fast-paced environment.
Preferred Qualifications
  • Bachelor's degree in a relevant field.
  • 5 or more years of experience in risk management or cybersecurity.
  • Experience working in healthcare environments and with frameworks such as ISO/IEC 27001/27002.
  • Relevant certifications such as CISM, CISA, CRISC, or CGEIT.

No 3rd party vendor and no sponsorship offered at this time

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Governance, Risk and Compliance Analyst Senior
Governance, Risk and Compliance Analyst Senior

Cone Health • Greensboro (NC)

On-site
USD 90,000 - 130,000
GRC Analyst
GRC Analyst

The Emery Company, LLC • Houston (TX)

On-site
USD 85,000 - 110,000
IT GRC - Risk Analyst
IT GRC - Risk Analyst

Core Specialty • Cincinnati (OH)

Hybrid
USD 85,000 - 115,000
Medical insurance
Dental & Vision
401(k) match
+2
GRC Security Analyst
GRC Security Analyst

Ladders • United States

Remote
USD 130,000 - 150,000
Collaborative culture
Growth opportunities
Hands-on security experience
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta-Denta • St. Louis (MO)

On-site
USD 75,000 - 110,000
IT GRC Lead Analyst
IT GRC Lead Analyst

Westfield Insurance • Westfield Center (OH)

On-site
USD 90,000 - 120,000
GRC Analyst
GRC Analyst

Apex B2Bi Solutions • Illinois

On-site
USD 90,000 - 130,000
IT GRC Analyst
IT GRC Analyst

Medasource • Town of Texas (WI), Northern (KY)

On-site
USD 76,000 - 110,000
GOVERNANCE, RISK, AND COMPLIANCE ANALYST
GOVERNANCE, RISK, AND COMPLIANCE ANALYST

Access Data Consulting Corporation • Phoenix (AZ)

On-site
USD 80,000 - 100,000
Governance, Risk, & Compliance (GRC) Analyst
Governance, Risk, & Compliance (GRC) Analyst

Districttechgroup • Washington

On-site
USD 80,000 - 100,000
Fully remote work environment
Competitive salary and performance bonuses
Health, dental, and vision insurance
+2