Lead Security Analyst-GRC

Tech Jobs for Good

United States

Hybrid

USD 150,000 - 215,000

Full time

5 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Stock options
Health insurance
401k
Paid time off

Job summary

Collective Health is seeking a Lead Security Analyst - GRC to drive governance, risk and compliance initiatives across the business. You will partner with teams to implement controls aligned with NIST, CIS, HIPAA, SOC 2 and HITRUST, building scalable security programs.

You will own audit readiness, coordinate third-party assessments, and deliver executive reporting on program health and risk. The role requires strong communication and cross-functional collaboration in a hybrid, US-based

Qualifications

  • 8+ years in cybersecurity, GRC, audit or risk/compliance roles.
  • Experience managing SOC 2 / HITRUST audits in cloud-native environments.
  • Strong knowledge of security frameworks and regulatory requirements.

Responsibilities

  • Evaluate and implement security controls based on NIST, CIS, HIPAA, SOC 2, and HITRUST.
  • Lead SOC 2 and HITRUST audit engagements from planning through remediation.
  • Coordinate third-party risk assessments and compliance reviews.
  • Educate control/risk owners and provide executive status reporting.

Skills

Cybersecurity
GRC
Audit
Risk management
Policy development
Regulatory knowledge
Cross-functional collaboration
Communication

Education

Certifications: CISSP, CISA, CRISC, CISM

Tools

GRC tools

Job description

At Collective Health, we’re transforming how employers and their people engage with their health benefits by seamlessly integrating cutting-edge technology, compassionate service, and world-class user experience design.

As our Lead Security Analyst - GRC, you’ll lead initiatives that address the company’s—and some of our industry’s—most sophisticated and meaningful security engineering challenges. You will build relationships across all parts of the business and drive multi-functional initiatives to continuously improve our security and privacy posture. You will be responsible for building and implementing controls that can scale and optimize as we move into a context-aware security environment.

What you'll do:
Governance & Compliance:

Evaluate and implement security controls based on frameworks such as NIST, CIS, HIPAA, SOC 2, and HITRUST. Develop and maintain policies, procedures, and documentation (controls, narratives, matrices). Lead SOC 2 and HITRUST audit engagements, from audit planning through remediation. Coordinate and monitor third-party risk assessments and compliance reviews. Own and lead BCP (Business Continuity Planning) and BIA (Business Impact Assessments) efforts. Build and maintain security risk registry

Audit & Risk Management:

Perform audit readiness assessments, and support internal/external audits. Partner with external auditors, control owners, and leadership to minimize business disruption. Track and drive remediation plans based on audit findings and compliance gaps. Maintain and communicate exception documentation for policy deviations. Educate and guide control/risk owners on their responsibilities.

Advisory & Communication:

Act as a liaison between technical and non-technical stakeholders. Respond to security questionnaires, RFIs, and client compliance inquiries. Develop and deliver security awareness and training programs. Provide executive reporting on program status, risks, and overall health.

To be successful in this role, you'll need:
Required:

8+ years in cybersecurity, GRC, audit, or risk/compliance roles. Experience managing SOC 2 / HITRUST audits, especially in cloud-native environments. Strong working knowledge of security frameworks and regulatory requirements. Demonstrated policy, data management, and risk mitigation capabilities. Familiarity with GRC tools and audit processes. Excellent communication and cross-functional collaboration skills.

Preferred (Nice to Haves):

Big 4 accounting firm background. Professional certifications: CISSP, CISA, CRISC, CISM, or similar.

Pay Transparency Statement

This is a hybrid position based out of one of our offices: Plano, TX, or Lehi, UT. Hybrid employees are expected to be in the office two days per week. #LI-hybrid

The actual pay rate offered within the range will depend on factors including geographic location, qualifications, experience, and internal equity. In addition to the [salary/hourly rate], you will be eligible for 205,000 stock options and benefits like health insurance, 401k, and paid time off. Learn more about our benefits at https://jobs.collectivehealth.com/benefits/.

San Francisco, CA Pay Range

$172,500 - $215,625 USD

Lehi, UT Pay Range

$138,000 - $172,500 USD

Plano, TX Pay Range

$151,800 - $189,750 USD

Why Join Us?
  • Mission-driven culture that values innovation, collaboration, and a commitment to excellence in healthcare
  • Impactful projects that shape the future of our organization
  • Opportunities for professional development through internal mobility opportunities, mentorship programs, and courses tailored to your interests
  • Flexible work arrangements and a supportive work-life balance

We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. Collective Health is committed to providing support to candidates who require reasonable accommodation during the interview process. If you need assistance, please contact recruiting-accommodations@collectivehealth.com.

Privacy Notice

For more information about why we need your data and how we use it, please see our privacy policy: https://collectivehealth.com/privacy-policy/.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security GRC Lead
Security GRC Lead

candidhealth • San Francisco (CA)

On-site
USD 180,000 - 258,000
GRC Security Analyst
GRC Security Analyst

Curana Health • United States

Remote
USD 117,000 - 143,000
Health insurance
401(k) retirement savings plan
Paid time off
GRC Security Analyst
GRC Security Analyst

Curana Health, Inc. • United States

Remote
USD 117,000 - 143,000
Health insurance
401(k) retirement plan
Paid time off
+1
Security GRC Lead
Security GRC Lead

Candid Health • San Francisco (CA)

On-site
USD 180,000 - 258,000
GRC Security Analyst
GRC Security Analyst

Ladders • United States

Remote
USD 130,000 - 150,000
Collaborative culture
Growth opportunities
Hands-on security experience
Security GRC Lead
Security GRC Lead

Candid Health • New York (NY), Northern (KY)

On-site
USD 180,000 - 258,000
Security Engineer, GRC
Security Engineer, GRC

Candid Health • Denver (CO)

On-site
USD 180,000 - 258,000
Security Engineer, GRC
Security Engineer, GRC

Candid Health • New York (NY)

On-site
USD 180,000 - 258,000
Chief Information Security Officer (CISO)
Chief Information Security Officer (CISO)

Spring Health • New York (NY), San Francisco (CA)

On-site
USD 299,000 - 344,000
Health benefits
401(k) match
Professional development reimbursement
+1
IT GRC Analyst
IT GRC Analyst

Medasource • Town of Texas (WI), Northern (KY)

On-site
USD 76,000 - 110,000