GRC/IT Compliance Analyst

Socket.dev

United States

Remote

USD 108,000 - 130,000

Full time

12 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Stock options

Job summary

Cleerly is seeking a GRC and IT Compliance Analyst to support security and regulatory objectives. Reporting to the Director of Information Security, you will own GRC, IT compliance, and risk management, and contribute to audits and control assessments.

Ideal candidates bring 5–7 years in security or compliance, experience with FDA submissions and SaMD, knowledge of ISO 27001, SOC 2, HITRUST, and the ability to work in a startup environment within a largely remote team.

Qualifications

  • 5–7 years in security or compliance analysis or related field.
  • Experience with FDA regulatory submissions and SaMD is preferred.
  • Knowledge of OSS/GRC tooling and internal controls for compliance.

Responsibilities

  • Build and manage enterprise risk assessment processes for compliance.
  • Support FDA regulatory submissions and control assessments.
  • Monitor and improve internal controls aligned with ISO27001, SOC 2, HITRUST.
  • Assist in audits and regulatory documentation updates.
  • Collaborate with stakeholders across security, product, and operations.

Skills

GRC experience
Agile/Scrum
Startup experience
Excellent communication
ISO 27001 knowledge

Education

BS in MIS/CS/IT

Tools

Eramba
CISO Advisor

Job description

About Cleerly

We’re Cleerly – a healthcare company that’s revolutionizing how heart disease is diagnosed, treated, and tracked. We were founded in 2017 by one of the world’s leading cardiologists and are a growing team of world-class engineering, operations, medical affairs, marketing, and sales leaders. We raised $223M in Series C funding in 2022 which has enabled rapid growth and continued support of our mission. In December 2024 we received an additional $106M in a Series C extension funding. Most of our teams work remotely and have access to our offices in Denver, Colorado, New, York, New York, Dallas, Texas, and Lisbon, Portugal with some roles requiring you to be on-site in a location. Cleerly has created a new standard of care for heart disease through value-based, AI-driven precision diagnostic solutions with the goal of helping prevent heart attacks. Our technology goes beyond traditional measures of heart disease by enabling comprehensive quantification and characterization of atherosclerosis, or plaque buildup, in each of the heart arteries. Cleerly’s solutions are supported by more than a decade of performing some of the world’s largest clinical trials to identify important findings beyond symptoms that increase a person’s risk of heart attacks. At Cleerly, we collaborate digitally and use a wide variety of systems. Our people use Google Workspace (GMail, Drive, Docs, Sheets, Slides), Slack, Confluence/Jira, and Zoom Video, prior experience in these areas is a plus. Role or department specific technology needs may vary and will be listed as requirements in the job description. While we are mostly a remote company, travel is required for some team meetings and cross function projects typically once per month or once per quarter, for some roles like sales or external facing roles travel could be up to 90% of the time. Cleerly is committed to providing safe and effective medical software that meets customer needs and our intended use. The adherence to all applicable regulatory and statutory requirements establishes a clear framework for setting measurable quality objectives. Our commitment to continually improving our products and processes proactively manages risks, ensuring ongoing compliance throughout the entire software lifecycle. Understanding this role’s relevance and importance is critical to achieving Cleerly’s quality objectives.

About the Opportunity

Our Information Security team is growing, and we have an immediate opening for a GRC and IT Compliance Analyst to help support and execute Cleerly’s security and compliance objectives. Reporting to the Director of Information Security, this role will be a multi-faceted specialist function that focuses on GRC, IT compliance, and risk management, as well as executing on core security-related audits and control assessments. The ideal candidate is a self-motivated individual who is great at task and time management and is willing to learn and adapt to changing regulatory environments.

Responsibilities

On any given day, you will be:

  • Build and implement a new enterprise risk assessment platform to streamline compliance workflows
  • Continuously monitor and update the risk platform to reflect evolving threats and regulatory requirements
  • Participate in risk analysis and features development processes to proactively identify risks to our regulated products
  • Continuously monitor and evaluate internal controls for areas of improvement
  • Conduct user access reviews to applications and services
  • Periodically review policies and procedures for compliance with best practices and compliance frameworks
  • Assist in owning and drafting documents for FDA regulatory submissions
Requirements
  • 5-7 years of experience in security or compliance analysis, IT risk assessment, risk management, or assurance/advisory experience over IT/IS general controls
  • BS degree in Management Information Systems, Computer Science, Accounting with ITGC experience, Engineering, Cybersecurity, Bio-Medical Engineering, or a related field
  • Experience with GRC software implementation
  • Experience with FDA regulatory submissions and SaMD (Software as a Medical Device) regulations
  • Proven experience in enterprise risk management (ERM) frameworks, risk identification, and qualitative/quantitative risk assessment methodologies
  • Previous experience working within a startup environment
  • Experience with Agile/Scrum environments and integrating security/compliance into the SDLC
  • Strong understanding of internal controls necessary to meet compliance frameworks such as ISO 27001, HITRUST, and SOC 2
  • Excellent verbal and written communication skill sets for addressing security concerns from internal stakeholders within the company
  • Impress us more CISA, CISM, CISSP, CRISC, or related certifications
  • Experience in the digital healthcare industry
  • Experience with open-source GRC tooling such as CISO Advisor or Eramba is a plus
Compensation

The base salary range for this role varies by location and is aligned to market benchmarks. Candidates located in higher-cost labor markets , including California, Washington, New York, New Jersey, Connecticut, Massachusetts, and Washington, DC represent the middle to high end of the range, while candidates located in all other U.S. locations represent the low to middle end of the range. Final compensation is determined based on location, experience, skills, and internal equity. This role is eligible for a XX% target annual bonus , resulting in the following base salary and Total Target Compensation (TTC) ranges: Base Salary: $108,000 - $130,000 TTC: $118,800 - $143,000 *Total Target Compensation (TTC): Total Cash Compensation (including base pay, variable pay, commission, bonuses, etc.).

Benefits
  • stock options, paid benefits, and employee perks are part of your total rewards.
Core Values

Working at Cleerly takes HEART. Discover our Core Values: H: Humility - be a servant leader E: Excellence - deliver world-changing results A: Accountability - do what you say; expect the same from others R: Remarkable - inspire & innovate with impact T: Teamwork - together we win

Equal Opportunity Employer

OUR COMPANY IS AN EQUAL OPPORTUNITY EMPLOYER. We do not discriminate on the basis of race, color, national origin, ancestry, citizenship status, protected veteran status, religion, physical or mental disability, marital status, sex, sexual orientation, gender identity or expression, age, or any other basis protected by law, ordinance, or regulation.

For more information see our Privacy Policy ( https://cleerlyhealth.com/privacy-policy). All official emails will come from @cleerlyhealth.com email accounts.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC/IT Compliance Analyst
GRC/IT Compliance Analyst

Cleerly • Denver (CO)

Hybrid
USD 108,000 - 130,000
Bonus eligibility
Executive Assistant
Executive Assistant

Cleerly • Denver (CO)

On-site
USD 90,000 - 100,000
Stock options
Benefits package
Bonus opportunities
IT Engineer III
IT Engineer III

Cleerly • Denver (CO)

Hybrid
USD 105,000 - 125,000
Stock options
401(k) match
Medical, dental, vision plans
+2
Sr. Software Engineer (Operational Systems Team)
Sr. Software Engineer (Operational Systems Team)

Cleerly • Denver (CO)

On-site
USD 153,000 - 179,000
15% target annual bonus
Stock options
Paid benefits
Sr. Software Engineer - ML Systems
Sr. Software Engineer - ML Systems

Cleerly • Denver (CO)

On-site
USD 153,000 - 179,000
15% target annual bonus
Stock options and paid benefits
Flexible remote work options
Sr. Scientist, Computational Imaging
Sr. Scientist, Computational Imaging

Cleerly • New York (NY)

On-site
USD 186,000 - 212,000
Stock options
Paid benefits
Employee perks
Clinical Account Manager (FL)
Clinical Account Manager (FL)

Cleerly • Boca Raton (FL)

Hybrid
USD 130,000 - 140,000
Flexible work arrangements
Stock options
Comprehensive benefits package
Director, Governance, Risk, and Compliance (GRC)
Director, Governance, Risk, and Compliance (GRC)

DaParrot Ltd • Northern (KY)

Hybrid
USD 212,000 - 230,000
ESPP
Remote‑first culture
Cell phone stipend
+2
Software Engineer III
Software Engineer III

Cleerly • Denver (CO)

Hybrid
USD 129,000 - 152,000
15% target annual bonus
Stock options
Paid benefits
+1
Director, Compliance
Director, Compliance

Claritas Rx • United States

On-site
USD 180,000 - 220,000
Unlimited PTO
Stock options
Flexible work environment