GRC Analyst

Visa Hunt

United States

On-site

USD 81,000 - 138,000

Full time

6 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

US Anesthesia Partners, Inc. is seeking a GRC Analyst to strengthen security by designing and managing control and risk workflows, performing third-party risk assessments, and ensuring compliance with HIPAA, HITRUST, PCI, SOC 2, and NIST frameworks.

The role involves developing control libraries, maintaining risk registers, driving automation, and supporting audits with evidence management. A bachelor’s degree and 5+ years in governance, risk, and compliance are preferred; AuditBoard experience

Qualifications

  • Bachelor’s degree or equivalent experience in information security, compliance, or GRC.
  • Minimum of 5 years in governance, risk, and compliance functions within IT or security.
  • Experience with HIPAA, NIST CSF, SOC 2, HITRUST, and related frameworks.
  • Strong written and verbal communication for cross-functional stakeholders.
  • Familiarity with audits, risk assessments, and control testing.

Responsibilities

  • Leads design, configuration, and governance of control frameworks and risk workflows.
  • Maintains control libraries, narratives, ownership, and evidence requirements.
  • Oversees risk registers, scoring, and remediation within the GRC platform.
  • Drives automation for control testing, evidence collection, and attestations.
  • Supports audits with evidence gathering, responses, and remediation tracking.
  • Develops and presents reports on control effectiveness, risk status, and compliance gaps.

Skills

Excellent written and verbal comms
Ability to manage multiple priorities
Familiarity with compliance frameworks
Strong collaboration across teams
Security policy communication

Education

Bachelor’s degree in information security, cybersecurity, or related field

Tools

AuditBoard/Optro
SOC 2 / HITRUST / HIPAA frameworks
CISA / CRISC / CISM certifications

Job description

Overview

The GRC Analyst will play a critical role in strengthening the security posture of our growing organization by designing, implementing, and managing control and risk workflows, as well as performing third-party risk assessments. This position is pivotal in ensuring compliance with industry standards and regulations, identifying and mitigating risks, and supporting USAP’s overall security governance framework.

At this time, US Anesthesia Partners does not hire candidates residing in California, Hawaii, or Alaska.

The base pay estimate for this role is $80,900 - $137,600 annually. The final offer will depend on the skills, experience, and qualifications of the selected candidate. This range is for base pay only and does not include bonuses or other compensation. This position is eligible for an annual bonus. Bonuses are not guaranteed and are awarded based on company and individual performance.

Job Highlights

ESSENTIAL DUTIES AND RESPONSIBILITIES: (The ideal candidate must be able to complete all physical requirements of the job with or without a reasonable accommodation)

  • Leads the design, configuration, and governance of control frameworks and risk workflows within the GRC platform, ensuring alignment with organizational objectives and compliance requirements.
  • Establishes and maintains control procedures, ensuring alignment with relevant frameworks (internal policy, HIPAA, HITRUST, PCI, SOC 2, NIST, and other applicable frameworks).
  • Oversees the development and maintenance of control libraries, including control narratives, ownership assignments, testing frequency, and evidence requirements.
  • Monitors and updates risk registers, ensuring accurate tracking, scoring, and prioritization of risks within the platform.
  • Drives automation workflows to streamline control testing, evidence collection, attestations, and remediation processes.
  • Tracks policy review cycles and ensures documentation remains current with regulatory and business changes.
  • Leads and maintains information security risk assessments across IT, operational, and third-party domains.
  • Performs control walkthroughs and operating effectiveness testing; documents results and identifies control gaps.
  • Collaborates with internal teams and external auditors to facilitate audits and assessments using the GRC platform for evidence management, issue tracking, and reporting.
  • Ensures ongoing compliance with regulatory requirements and industry standards by maintaining up-to-date documentation and control mappings.
  • Prepares and presents reports, dashboards, and metrics on control effectiveness, risk status, and compliance gaps.
  • Maps controls to applicable regulatory and framework requirements, identifying overlaps to reduce duplicative testing.
  • Supports internal and external audits by gathering evidence, coordinating stakeholder responses, and tracking remediation through closure.
  • Tracks and manages audit findings, corrective action plans (CAPs), and remediation timelines within the GRC platform.
  • Guides risk assessments to identify potential vulnerabilities and threats, documenting findings and supporting evidence in the GRC platform.
  • Partners with stakeholders to develop and implement risk mitigation strategies, tracking progress and ownership within the platform.
  • Develops, monitors, and reports on key risk indicators (KRIs) and key performance indicators (KPIs) to proactively identify and address emerging risks.
  • Maintains and applies consistent risk scoring methodologies, including likelihood, impact, and residual risk calculations.
  • Escalates significant risks and control deficiencies to management and governance committees, providing recommendations for mitigation and improvement, in a timely manner.
  • Leads the development, maintenance, and lifecycle management of information security policies, procedures, standards, and guidelines.
  • Directs policy review and approval workflows with policy owners and stakeholders.
  • Ensures policies remain aligned with evolving regulatory requirements and organizational changes.
  • Leads evaluations of third-party vendors for security and compliance risks, including review of SOC reports, security questionnaires, and contractual requirements.
  • Tracks vendor risk assessments, reassessment cycles, and risk ratings within the GRC platform.
  • Works with business owners to develop and monitor vendor remediation action plans.
  • Supports vendor onboarding and offboarding risk reviews, ensuring appropriate due diligence is documented.
  • Identifies opportunities to enhance GRC processes and workflows to improve efficiency, accuracy, and effectiveness.
  • Stays current on industry trends, emerging threats, and best practices in GRC, recommending improvements to the security and compliance program.
  • Champions automation and integration initiatives to reduce manual effort.
  • Guides periodic program assessments and maturity benchmarking to guide roadmap priorities.
  • Performs other duties and responsibilities as assigned.
Qualifications
KNOWLEDGE/SKILLS/ABILITIES (KSAs):
  • Bachelor’s degree in information security, cybersecurity, computer science, information technology, business administration, or a closely related field required. Equivalent experience may be considered in lieu of a degree (e.g., 4+ years of relevant experience in information security, compliance, or GRC roles).
  • Minimum of 5 years relevant experience in governance, risk, and compliance functions within IT or information security.
  • Experience with AuditBoard (now named Optro) is highly preferred.
  • Certified Information Systems Auditor (CISA) preferred.
  • Certified Risk and Information Systems Control (CRISC) preferred.
  • Certified Information Security Manager (CISM) preferred.
  • Other relevant certifications (e.g., CompTIA Security+, ISO 27001 Lead Auditor) preferred.
  • Prior experience implementing, managing, or auditing security policies and procedures.
  • Familiarity with compliance frameworks (HIPAA, NIST CSF, SOC 2, HITRUST, etc.).
  • Prior experience conducting risk assessments and supporting risk management activities.
  • Excellent written and verbal communication skills, including the ability to communicate technical concepts and compliance requirements to both technical and non-technical stakeholders.
  • Ability to manage multiple priorities, work independently, and collaborate effectively across cross-functional teams.
*The physical demands described here are representative of those that may need to be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions
  • Occasional Standing
  • Occasional Walking
  • Frequent Sitting
  • Frequent hand, finger movement
  • Use office equipment (in office or remote)
  • Communicate verbally and in writing

US Anesthesia Partners, Inc. provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, gender identity, sexual orientation, pregnancy, status as a parent, national origin, age, disability (physical or mental), family medical history or genetic information, political affiliation, military service, or other non-merit based factors.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta Dental of Missouri • Missouri

Hybrid
USD 80,000 - 100,000
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta-Denta • St. Louis (MO)

Hybrid
USD 75,000 - 110,000
IT GRC Analyst
IT GRC Analyst

Medasource • Town of Texas (WI), Northern (KY)

Hybrid
USD 76,000 - 110,000
GRC Analyst: Elevate Security, Compliance & Risk
GRC Analyst: Elevate Security, Compliance & Risk

Visa Hunt • United States

On-site
USD 81,000 - 138,000
Sr. Staff Risk Management Analyst
Sr. Staff Risk Management Analyst

Jobgether • United States

On-site
USD 140,000 - 190,000
Medical, dental, and vision
401(k) retirement plan with company  匹
Flexible PTO
+5
IT GRC Analyst
IT GRC Analyst

Eightelevengroup • Town of Texas (WI), Northern (KY)

Hybrid
USD 76,000 - 110,000
Job Posting Title Senior Manager - Automation - Remote
Job Posting Title Senior Manager - Automation - Remote

U.S. Anesthesia Partners • Northern (KY)

Hybrid
USD 89,000 - 151,000
Job Posting Title Payer Compliance Specialist I - Remote
Job Posting Title Payer Compliance Specialist I - Remote

U.S. Anesthesia Partners • Northern (KY)

Hybrid
USD 22,000 - 36,000
Quarterly bonus
Senior Manager - Automation - Remote
Senior Manager - Automation - Remote

US Anesthesia Partners • United States

On-site
USD 89,000 - 151,000
Lead GRC Analyst (IT/Security)
Lead GRC Analyst (IT/Security)

Ultra Clean Technology • Manor (TX)

On-site
USD 90,000 - 120,000