IT GRC Analyst

Eightelevengroup

Town of Texas, Northern (WI, KY)

Hybrid

USD 76,000 - 110,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Medasource is seeking an IT GRC Analyst to join the IT Security and Governance team on a 6-month contract-to-hire basis, remote within the USA. The role focuses on governance, risk, and compliance across HIPAA, SOC 2, and NIST, collaborating with IT, Security, Privacy, Compliance, Legal, and business stakeholders.

The ideal candidate has 3-5 years in information security, risk, or GRC, healthcare industry experience, and strong audit documentation skills. Travel up to 10% may be required.

Qualifications

  • 3-5 years of information security, risk management, compliance, audit, or GRC functions.
  • Healthcare industry experience is required.
  • Knowledge of HIPAA, NIST CSF, SOC 2, CIS.
  • Ability to prepare audit-ready documentation and maintain evidence repositories.
  • Excellent written and verbal communication, including executive reporting.

Responsibilities

  • Perform information security risk assessments and document findings.
  • Administer and maintain the organization's GRC program.
  • Develop and evaluate security policies, standards, and guidelines.
  • Coordinate evidence collection and remediation tracking for audits.
  • Map controls to HIPAA, SOC 2, NIST, CMS, URAC.
  • Support security awareness and training initiatives.
  • Assist with AI governance and regulatory requirements.

Skills

Analytical thinking
Organizational skills
Attention to detail
Executive reporting
Problem solving

Education

Bachelor's degree in Information Security/IT/Cybersecurity or related field

Tools

Microsoft Office
Governance tools
Compliance platforms

Job description

IT GRC Analyst

Remote, USA

Compensation: $55 - $80 per hour

Contract Length: 6-month Contract to Hire

Hours: Standard full-time schedule, 8 hours/day, 5 days/week; potential for extended hours under heavy audit or incident response activity.

Start Date: ASAP

ABOUT THE ROLE

Our client is a healthcare organization providing primary and post-acute care services to seniors across assisted living, life plan communities, independent living, skilled nursing, and long-term care settings nationwide. The organization is value-driven, offering competitive pay, comprehensive benefits, and flexible scheduling, with a mission to improve the health, happiness, and dignity of the seniors it serves.

We are seeking an IT GRC Analyst to join the IT Security and Governance team on a 6-month contract-to-hire basis, working remotely within the USA. The IT GRC Analyst will play a key role in supporting the organization's IT Governance, Risk, and Compliance (GRC) program, focusing on security governance, regulatory compliance, risk management, audit readiness, policy administration, and control monitoring. This position collaborates with IT, Security, Privacy, Compliance, Legal, and business stakeholders to enhance the organization's security posture and ensure compliance with healthcare regulations such as HIPAA, SOC 2, and NIST. The role also contributes to business continuity, disaster recovery, and AI governance initiatives. Up to 10% travel may be required.

WHAT YOU'LL DO
  • Perform information security risk assessments and document identified risks, control gaps, and remediation recommendations
  • Support administration and maintenance of the organization's IT Governance, Risk, and Compliance (GRC) program
  • Assist with development, review, maintenance, and periodic evaluation of security policies, standards, procedures, and guidelines
  • Coordinate evidence collection, control validation, documentation activities, and remediation tracking for internal and external audits and assessments
  • Maintain and map security controls against applicable regulatory, contractual, and industry frameworks (e.g., HIPAA, SOC 2, NIST, CMS, URAC)
  • Assist with security exception review processes and document risk acceptance decisions
  • Maintain compliance metrics, risk registers, issue logs, corrective action plans, and other governance documentation
  • Collaborate with technology teams to identify and remediate security vulnerabilities, control deficiencies, and compliance gaps
  • Analyze emerging cybersecurity, privacy, and regulatory requirements and provide recommendations for program improvements
  • Support security awareness, compliance training, and organizational education initiatives
  • Support security governance forums, risk committees, and related working groups through agenda preparation, risk presentation, meeting facilitation, and documentation of decisions and action items
  • Facilitate risk intake, scoring, prioritization, escalation, and ongoing monitoring activities in accordance with organizational risk management procedures
  • Support administration, data quality, workflow management, reporting, and continuous improvement of GRC tooling and platforms
  • Participate in security and compliance reviews for new technologies, systems, projects, AI initiatives, and significant change requests to identify regulatory and security requirements early in the lifecycle
  • Support business continuity, disaster recovery, resilience planning, testing, and associated governance activities
  • Support AI governance, risk assessments, control validation, and compliance reviews for approved AI technologies and use cases
  • Develop and maintain key risk indicators (KRIs), key performance indicators (KPIs), and executive reporting packages supporting leadership and governance oversight
  • Perform other related duties as assigned to support departmental and organizational objectives
WHAT YOU BRING
  • 3-5 years of experience in information security, risk management, compliance, audit, or GRC functions
  • Healthcare industry experience required
  • Strong understanding of information security governance, risk management, compliance, and control frameworks
  • Knowledge of healthcare regulatory requirements, including HIPAA Privacy and Security Rules
  • Familiarity with industry frameworks and standards such as NIST CSF, SOC 2, HIPAA, and CIS
  • Experience conducting risk assessments, compliance reviews, and control evaluations
  • Understanding of third-party risk management and vendor security review processes
  • Ability to interpret laws, regulations, contractual requirements, and industry standards
  • Strong analytical, organizational, and problem-solving skills with exceptional attention to detail and critical thinking
  • Experience preparing audit-ready documentation and maintaining evidence repositories
  • Excellent written and verbal communication skills, including executive-level reporting and presentations
  • Ability to prioritize multiple assignments and manage deadlines in a dynamic healthcare environment
  • Proficiency with Microsoft Office applications, governance tools, and compliance management platforms
  • Bachelor's degree in Information Security, Information Technology, Cybersecurity, Computer Science, Healthcare Informatics, or a related field (or equivalent experience)

Nice to Haves:

  • Experience supporting HIPAA, SOC 2, CIS, NIST Cybersecurity Framework, or similar regulatory and security frameworks
  • Experience participating in audits, risk assessments, control testing, or compliance monitoring activities
WHAT'S IN IT FOR YOU
  • Competitive pay and comprehensive benefits
  • Flexible scheduling and remote work
  • Opportunity to contribute to a mission-driven organization improving the lives of seniors
  • Professional growth in a dynamic healthcare environment
  • Potential for contract-to-hire conversion

#LI-CM1

Medasource is an equal opportunity employer that does not discriminate on the basis of actual or perceived race, color, creed, religion, national origin, ancestry, citizenship status, age, sex or gender (including pregnancy, childbirth, lactation and related medical conditions), gender identity or gender expression, sexual orientation, marital status, military service and veteran status, physical or mental disability, protected medical condition as defined by applicable state or local law, genetic information, or any other characteristic protected by applicable federal, state, or local laws and ordinances.

Benefits & Perks:

Medasource offers competitive medical, dental, vision, Health Savings Account, Dependent Care FSA, and supplemental coverage with plans that can fit each employee’s needs. We offer a 401k plan that includes a company match and is fully vested after you become eligible, paid time off, sick time, and paid company holidays. We also offer an Employee Assistance Program (EAP) that provides services like virtual counseling, financial services, legal services, life coaching, etc.

Pay Disclaimer:

The pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT GRC Analyst
IT GRC Analyst

Medasource • Town of Texas (WI), Northern (KY)

Hybrid
USD 76,000 - 110,000
Remote IT GRC Analyst - Healthcare Compliance & Risk
Remote IT GRC Analyst - Healthcare Compliance & Risk

Medasource • Town of Texas (WI), Northern (KY)

Hybrid
USD 76,000 - 110,000
Remote IT GRC Analyst — Healthcare Compliance
Remote IT GRC Analyst — Healthcare Compliance

Eightelevengroup • Town of Texas (WI), Northern (KY)

Hybrid
USD 76,000 - 110,000
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta Dental of Missouri • Missouri

Hybrid
USD 80,000 - 100,000
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta-Denta • St. Louis (MO)

Hybrid
USD 75,000 - 110,000
Governance, Risk, & Compliance (GRC) Analyst
Governance, Risk, & Compliance (GRC) Analyst

Districttechgroup • Washington

Hybrid
USD 80,000 - 100,000
Fully remote work environment
Competitive salary and performance bonuses
Health, dental, and vision insurance
+2
Global Security Governance, Risk & Compliance Manager (Remote)
Global Security Governance, Risk & Compliance Manager (Remote)

Barnes Aerospace • United States

Remote
USD 140,000 - 190,000
Senior Governance, Risk & Compliance (GRC) Analyst
Senior Governance, Risk & Compliance (GRC) Analyst

Cianbro • North Stonington (CT)

On-site
USD 90,000 - 110,000
Employee-owned company
Security GRC Lead
Security GRC Lead

candidhealth • San Francisco (CA)

On-site
USD 180,000 - 258,000
Information Security GRC Analyst III - CISSP preferred
Information Security GRC Analyst III - CISSP preferred

CareSource • United States

On-site
USD 94,000 - 165,000
Bonus potential
Total rewards package