GRC Security Analyst

Curana Health, Inc.

United States

Remote

USD 117,000 - 143,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Health insurance
401(k) retirement plan
Paid time off
Paid holidays

Job summary

Curana Health, Inc. is seeking an IT Governance, Risk, and Compliance Analyst to strengthen our IT Security and Governance program across risk management, policy, and controls.

You will collaborate with IT, Security, Compliance, Legal, and business teams to identify risks and drive audit-ready processes. You bring 2–5 years in GRC or information security, with hands-on experience in risk assessments, control testing, and regulatory compliance.

Qualifications

  • Bachelor's degree in Information Security, Cybersecurity, Information Technology, Computer Science, Healthcare Informatics, or related field (equivalent experience considered).
  • 2–5 years of experience in GRC, information security, risk management, audit, compliance, cybersecurity, or related function.
  • Experience supporting risk assessments, compliance reviews, audits, control testing, or governance activities.
  • Experience in regulated industries or compliance-driven environments.
  • Knowledge of HIPAA Security Rule and governance concepts.
  • Strong analytical and communication skills; ability to manage multiple priorities in a fast-paced environment.

Responsibilities

  • Conduct security risk assessments and document risks, control gaps, and recommended steps.
  • Support ongoing improvements to Curana Health's GRC program.
  • Maintain security policies, standards, procedures, and guidelines.
  • Coordinate audit and assessment activities, including evidence collection and remediation tracking.
  • Map security controls to HIPAA, SOC 2, NIST, CIS, CMS, URAC, and related frameworks.
  • Support regulatory readiness initiatives and governance metrics.
  • Maintain risk registers, issue logs, and corrective action plans.
  • Collaborate with technology teams to address vulnerabilities and compliance gaps.
  • Participate in risk intake, assessment, prioritization, and monitoring.
  • Support third-party risk management and vendor security reviews.

Skills

GRC
Information Security
Risk Management
Audit
Compliance
Regulated Industry

Education

Bachelor's degree in Information Security/Cybersecurity/IT/CS/Healthcare Informatics

Tools

ServiceNow GRC
Archer
OneTrust
AuditBoard
LogicGate

Job description

At Curana Health, we're on a mission to radically improve the health, happiness, and dignity of older adults - and we're looking for passionate people to help us do it.

As a national leader in value-based care, we offer senior living communities and skilled nursing facilities a wide range of solutions (including on-site primary care services, Accountable Care Organizations, and Medicare Advantage Special Needs Plans) proven to enhance health outcomes, streamline operations, and create new financial opportunities.

Founded in 2021, we've grown quickly - now serving 200,000+ seniors in 1,500+ communities across 32 states. Our team includes more than 1,000 clinicians alongside care coordinators, analysts, operators, and professionals from all backgrounds, all working together to deliver high-quality, proactive solutions for senior living operators and those they care for.

Ranked #147 on the Inc. 5000 list of America's fastest-growing private companies, we're just getting started. If you're looking to make a meaningful impact on the senior healthcare landscape, you're in the right place - and we look forward to working with you.

For more information about our company, visit CuranaHealth.com.

Summary

Curana Health is seeking an IT Governance, Risk, and Compliance Analyst to join our IT Security and Governance team. In this role, you will help strengthen our security and compliance programs by supporting risk management, audit readiness, policy administration, control monitoring, and regulatory compliance activities. You will work closely with IT, Security, Privacy, Compliance, Legal, and business teams to identify risks, support practical solutions, and help ensure Curana Health continues to meet security and regulatory expectations as we grow.

Who You Are:

You are an IT Governance, Risk, and Compliance professional who enjoys connecting the dots between security requirements, business needs, and practical solutions. With approximately 2-5 years of experience in information security, compliance, risk management, audit, cybersecurity governance, or a related area, you bring a strong interest in identifying risks, improving processes, and helping teams stay audit-ready.You are analytical, detail-oriented, and collaborative, with the ability to communicate clearly with both technical and non-technical stakeholders. You have hands-on experience with activities such as evidence collection, remediation tracking, risk registers, control validation, and compliance documentation. Healthcare experience is highly valued, though candidates from other regulated industries such as financial services, banking, similar highly regulated environments are encouraged to apply.You will thrive in this role if you enjoy working in a fast-moving, growing environment where thoughtful problem-solving, responsible innovation, and continuous improvement are valued.

Essential Duties & Responsibilities
  • Conduct security risk assessments and help document risks, control gaps, and recommended next steps.
  • Support ongoing improvements to Curana Health's Governance, Risk, and Compliance program.
  • Help maintain security policies, standards, procedures, and guidelines.
  • Coordinate audit and assessment activities, including evidence collection, control validation, documentation, and remediation tracking.
  • Map security controls to frameworks including HIPAA, SOC 2, NIST, CIS, CMS, and URAC.
  • Support compliance monitoring activities and assist with regulatory readiness initiatives.
  • Maintain risk registers, issue logs, corrective action plans, compliance metrics, and governance documentation.
  • Partner with technology teams to address security vulnerabilities, control deficiencies, and compliance gaps.
  • Participate in risk intake, assessment, prioritization, escalation, and ongoing monitoring activities.
  • Support third-party risk management and vendor security review processes.
Qualifications

Required Qualifications

  • Bachelor's degree in Information Security, Cybersecurity, Information Technology, Computer Science, Healthcare Informatics, or a related field; equivalent experience will also be considered.
  • 2-5 years of experience in GRC, information security, risk management, audit, compliance, cybersecurity, or a related function.
  • Experience supporting risk assessments, compliance reviews, audits, control testing, or governance activities.
  • Experience working in a regulated industry or compliance-driven environment.
  • Knowledge of the HIPAA Security Rule.
  • Understanding of information security governance, risk management, and compliance concepts.
  • Strong analytical, organizational, and problem-solving skills.
  • Excellent written and verbal communication skills.
  • Ability to manage multiple priorities and deadlines in a fast-paced environment.

Preferred Qualifications

  • Healthcare industry experience.
  • Knowledge of the HIPAA Privacy Rule.
  • Experience with frameworks such as HIPAA, SOC 2, NIST Cybersecurity Framework, CIS Controls, CMS, URAC, HITRUST, or ISO 27001.
  • Experience with third-party risk management programs.
  • Experience with GRC platforms such as ServiceNow GRC, Archer, OneTrust, AuditBoard, LogicGate, or similar solutions.
  • Experience supporting AI governance, emerging technology risk reviews, or security governance initiatives.

Compensation & Benefits:

This role offers a base salary starting at $130,000. Actual compensation will be determined based on relevant experience, qualifications, skills, education, certifications, internal equity, market considerations, and business needs.

Curana Health offers a competitive benefits package to eligible employees, which may include health insurance, paid time off, paid holidays, a 401(k) retirement savings plan, and additional wellness and support programs.

Curana Health is an Inc. 5000 company ranked #147 among America's fastest-growing private companies - and we're just getting started. Join us as we redefine what senior care looks like across the country.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

IT GRC Analyst
IT GRC Analyst

Medasource • Town of Texas (WI), Northern (KY)

On-site
USD 76,000 - 110,000
Healthcare GRC & Security Compliance Analyst
Healthcare GRC & Security Compliance Analyst

Curana Health, Inc. • United States

Remote
USD 117,000 - 143,000
Health insurance
401(k) retirement plan
Paid time off
+1
IT GRC Analyst
IT GRC Analyst

Eightelevengroup • Town of Texas (WI), Northern (KY)

On-site
USD 76,000 - 110,000
Security GRC Lead
Security GRC Lead

candidhealth • San Francisco (CA)

On-site
USD 180,000 - 258,000
Security GRC Lead
Security GRC Lead

Candid Health • San Francisco (CA)

On-site
USD 180,000 - 258,000
Security Engineer, GRC
Security Engineer, GRC

Candid Health • Denver (CO)

On-site
USD 180,000 - 258,000
Security GRC Lead
Security GRC Lead

Candid Health • New York (NY), Northern (KY)

On-site
USD 180,000 - 258,000
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta Dental of Missouri • Missouri

On-site
USD 80,000 - 100,000
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta-Denta • St. Louis (MO)

On-site
USD 75,000 - 110,000
Security Engineer, GRC
Security Engineer, GRC

Candid Health • New York (NY)

On-site
USD 180,000 - 258,000