Enable job alerts via email!

Senior Security Governance Risk & Compliance (GRC) Analyst

Alma

United States

Remote

USD 145,000 - 174,000

Full time

30+ days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking a mission-driven Senior Security Governance Risk and Compliance Analyst to enhance their security culture. This pivotal role involves conducting risk assessments, developing security policies, and preparing for audits to ensure compliance with industry standards. The ideal candidate will have extensive experience in Information Security, particularly in GRC analysis within regulated sectors. You will collaborate with various stakeholders to implement security measures and educate staff, ultimately contributing to a safer environment for both providers and clients. Join a forward-thinking organization dedicated to improving mental health care access while fostering a culture of security and trust.

Qualifications

  • 5+ years in Information Security, especially in GRC analysis.
  • Experience leading SOC 2 audits with minimal findings.

Responsibilities

  • Perform risk assessments and maintain security policies.
  • Prepare for annual audits and facilitate certifications.

Skills

Information Security
GRC Analysis
Risk Assessments
Security Policies
Security Awareness Programs
Communication Skills

Tools

Drata
KnowBe4
AWS

Job description

Senior Security Governance Risk & Compliance (GRC) Analyst

Remote, Contiguous US

Alma is on a mission to simplify access to high-quality, affordable mental health care. We do this by making it easy and financially rewarding for therapists to accept insurance and offer in-network care. When a provider joins Alma, they gain access to a suite of tools that not only help them better run their business, but also grow it sustainably and develop as a provider. Alma is available in all 50 states, with over 20,000 therapists in our growing network. Alma was also named one of Inc’s Best Workplaces in 2022 and 2023.

Senior Security Governance Risk & Compliance (GRC) Analyst

Alma is seeking a mission-driven Senior Security Governance Risk and Compliance (GRC) Analyst to join our team. We are dedicated to building secure and compliant tools and services that help providers more easily manage and grow their practice.

Acting as a principal aide to the VP of Security and IT, this role will play a critical role in enabling a culture of security at Alma, making security a product differentiator that builds confidence and trust with our providers, and preparing Alma for annual audits and certifications (such as SOC 2 and HITRUST). In this role you will perform risk assessments, create and maintain our security policies, educate our staff by developing a security awareness program, respond to security assessments, and review our vendor’s security.

What you’ll do:

  • Perform risk assessments and reports on Alma’s risk management program
  • Collaborate with stakeholders to identify and facilitate the implementation of mitigating controls
  • Streamline and maintain Alma’s security policies and standards
  • Prepare the organization and facilitate annual audits and certifications (SOC 2, PCI)
  • Educate Alma’s staff by creating and managing an effective security awareness program
  • Develop our vendor risk program, ensuring our vendors meet Alma security standards
  • Develop Alma’s Trust program, preparing materials and responses to security assessments, and making security a product differentiator that builds confidence and instills trust in our providers
  • Develop and measure key metrics, and coordinate activities in support of cybersecurity priorities

Who you are:

  • You have 5+ years of work experience in Information Security, especially in a GRC analysis role
  • You have experience working in health tech or other highly regulated industries (banking, insurance, etc)
  • You have experience leading SOC 2 audits and/or HITRUST certifications with minimal findings
  • You have experience deploying GRC solutions (Drata or equivalent), putting in place a unified control framework enabling evidence collection automation and continuous compliance
  • You strongly understand security best practices and controls frameworks (NIST CSF, NIST 800-53, AICPA Trust Services Criteria, HITRUST CSF, PCI DSS, HIPAA Security Rule, and Breach Notification)
  • You have experience implementing security controls and policies that align with AWS security best practices
  • You have experience driving security awareness programs, including phishing simulation tools (KnowBe4 or equivalent)
  • You have experience performing risk assessments, with an understanding of quantitative risk analysis frameworks (FAIR)
  • You have experience writing customer-facing materials in partnership with product and marketing teams
  • You have strong written and verbal communication skills and can convey complex technical topics to non-technical stakeholders clearly and concisely
  • You feel a passion for Alma's mission – to improve the experience of therapy for providers and their clients and simplify access to care

Salary Band: $145,000 - $174,000

Alma’s compensation philosophy is driven by our company value of building equity. To best ensure pay equity, we typically bring in new hires near the middle of our listed salary bands and we do not negotiate our compensation (i.e. all people hired at the same level & role are brought in at the same salary, equity, and benefits). The recruiter you work with can provide more details on our philosophy.

Apply for this job

All Alma jobs are listed on our careers page. We do not use outside applications or automated text messaging in our recruiting process. We will not ask for any sensitive financial or identification information throughout the recruiting process. Any communication during the recruitment process, including interview requests or job offers, will come directly from a recruiting team member with a helloalma.com email address.

Diversity, Equity and Inclusion at Alma

At Alma, we work hard to bring together people from a vast set of backgrounds and identities. We aspire to champion diversity, amplify inclusive cultures and build equitably.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Senior Analyst, Security Governance Risk & Compliance (GRC)

BlackSky

Washington

Remote

USD 135,000 - 150,000

3 days ago
Be an early applicant

Senior Security Governance Risk & Compliance (GRC) Analyst

Alma Mental Health

Remote

USD 145,000 - 174,000

30+ days ago