Sr Information Security GRC Analyst

Masimo Medical Technologies (Malaysia) Sdn. Bhd.

Irvine (CA)

On-site

USD 130,000 - 170,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical Insurance
Dental Insurance
Vision Insurance
Life/AD&D Insurance
Disability Insurance
401(k)
Vacation
Sick Leave
Holiday
Paid Maternity Leave
On-site Wellness Clinic
Fitness Center
Café
Pet Insurance

Job summary

Masimo is seeking a Senior Information Security GRC Analyst to lead governance, risk, and compliance across enterprise security. You will coordinate audits, manage third‑party risk, and support policy development in a regulated healthcare and medical device environment.

You will partner with Information Security, IT, Engineering, Quality, Legal, and business teams to ensure compliance with HIPAA, HITRUST, ISO 27001, SOC 2, and NIST frameworks, and drive continuous improvement in governance

Qualifications

  • 7+ years in information security GRC, risk, audits, or related areas.
  • Experience leading security audits or compliance initiatives (HITRUST, ISO 27001, SOC 2, NIST).
  • Experience with third‑party security assessments and vendor risk reviews.
  • Strong understanding of information security principles, risk management, and security control frameworks.
  • Ability to discuss IAM, encryption, vulnerability management, cloud security, and network security.
  • Strong analytical, organizational, documentation, communication, and stakeholder management skills.
  • Ability to manage multiple priorities in a regulated environment.

Responsibilities

  • Support the strategic execution and continuous improvement of the enterprise information security GRC program.
  • Lead coordination of external security audits and certification activities (HITRUST, ISO 27001, SOC 2).
  • Gather documentation, evidence, remediation updates, and corrective action plans for audits and assessments.
  • Conduct third‑party and supply chain cybersecurity risk assessments; evaluate vendor security posture.
  • Collaborate with business and technical teams to respond to customer security assessments and inquiries.
  • Lead information security risk assessments and track remediation activities to resolution.
  • Manage review of security exceptions and risk acceptance requests with documented controls.
  • Assist in developing and maintaining information security policies, standards, procedures, guidelines.
  • Collaborate to evaluate, document, and validate security controls and compliance requirements.
  • Maintain audit findings, remediation plans, compliance documentation, risk registers, and governance records.
  • Develop monitoring processes, governance reporting metrics, dashboards, and ongoing reporting.
  • Conduct internal security assessments, readiness reviews, and governance maturity initiatives.
  • Support governance and risk management for cloud platforms, SaaS, and emerging technologies.
  • Promote a risk-aware security culture with leadership.
  • Stay informed of evolving threats and regulatory requirements relevant to healthcare and medical devices.

Skills

GRC governance
Security audits
Vendor risk management
NIST CSF
HIPAA compliance
IAM / encryption
Communication
Regulatory requirements

Education

Bachelor's degree in Information Security / related

Tools

GRC tools

Job description

Job Summary

The Senior Information Security GRC Analyst supports and advances Masimo’s enterprise information security governance, risk, and compliance (GRC) program through leadership of security compliance initiatives, third‑party risk management, policy governance, audit readiness, and risk assessment activities. This role partners closely with Information Security, IT, Engineering, Quality, Legal, and business stakeholders to strengthen security governance processes, support regulatory and customer requirements, and maintain alignment with industry frameworks and healthcare security expectations. The Senior Information Security GRC Analyst contributes to the continuous improvement of governance processes, compliance monitoring, and enterprise risk management activities within a regulated healthcare and medical device environment. This position requires strong knowledge of information security principles, compliance frameworks, and risk management practices, along with the ability to communicate effectively across both technical and non‑technical audiences.

Duties & Responsibilities
  • Support the strategic execution and continuous improvement of the enterprise information security governance, risk, and compliance (GRC) program
  • Lead coordination of external security audits and certification activities, including HITRUST, ISO 27001, SOC 2, and related compliance initiatives
  • Partner with internal stakeholders to gather documentation, evidence, remediation updates, and corrective action plans for audits and assessments
  • Conduct third‑party and supply chain cybersecurity risk assessments, including evaluation of vendor security posture, due diligence questionnaires, and supporting security documentation
  • Collaborate with business and technical teams to respond to customer security assessments, compliance inquiries, and due diligence requests
  • Lead information security risk assessments and track remediation activities through resolution
  • Manage the review and tracking of security exceptions and risk acceptance requests, ensuring appropriate compensating controls and approvals are documented
  • Assist in the development, maintenance, and communication of information security policies, standards, procedures, and guidelines
  • Collaborate with technical teams to evaluate, document, and validate security controls and compliance requirements
  • Maintain audit findings, remediation plans, compliance documentation, risk registers, and governance tracking records
  • Develop and maintain compliance monitoring processes, governance reporting metrics, dashboards, and ongoing reporting activities
  • Conduct internal security assessments, readiness reviews, and governance maturity initiatives
  • Support governance and risk management activities related to cloud platforms, SaaS environments, emerging technologies, and evolving cybersecurity threats
  • Partner with leadership and cross‑functional stakeholders to promote a risk‑aware security culture and support enterprise governance initiatives
  • Stay informed of evolving cybersecurity threats, regulatory requirements, and industry best practices relevant to healthcare and medical device environments
  • Support cross‑functional initiatives related to information security awareness, governance, operational maturity, and compliance readiness
Minimum & Preferred Qualifications and Experience
Minimum Qualifications
  • 7+ years of experience in information security governance, risk, and compliance (GRC), cybersecurity risk management, IT audit, compliance, or related areas
  • Experience leading or managing security audits or compliance initiatives related to HITRUST, ISO 27001, SOC 2, NIST, or similar frameworks
  • Experience conducting third‑party security assessments and vendor risk reviews
  • Strong understanding of information security principles, risk management concepts, and security control frameworks
  • Ability to understand and discuss technical security concepts including identity and access management (IAM), encryption, vulnerability management, endpoint security, logging/monitoring, cloud security, and network security
  • Strong analytical, organizational, documentation, communication, and stakeholder management skills
  • Ability to manage multiple priorities and work collaboratively in a fast‑paced, highly regulated environment
Preferred Qualifications
  • Experience within healthcare, medical device, biotechnology, or other highly regulated industries
  • Familiarity with HIPAA, FDA‑regulated environments, HITRUST, NIST CSF, PCI DSS, UK Cyber Essentials, NIS2 Directive, or related cybersecurity and privacy requirements
  • Experience using GRC tools and platforms for audit, compliance, risk management, or governance reporting activities
  • Experience supporting enterprise security governance or compliance maturity initiatives
  • Industry‑recognized certifications such as CISSP, CISA, CRISC, CISM, or similar preferred
Education

Bachelor’s degree in Information Security, Cybersecurity, Information Systems, Computer Science, or related field required; or equivalent combination of education, certifications, and relevant experience.

Language Requirements
  • Ability to read, write, and communicate effectively in English.
  • Ability to interpret technical documents, schematics, and written instructions.
  • Ability to clearly document technical findings and communicate with cross‑functional team members.
Compensation

The anticipated range for this position is $130,000 – $170,000. Actual placement within the range is dependent on multiple factors, including but not limited to skills, education, and experience. This position also qualifies for up to a 10% annual bonus based on Company, department, and individual performance.

Masimo offers benefits such as Medical, Dental, Vision, Life/AD&D, Disability Insurance, 401(k), Vacation, Sick, Holiday, Paid Maternity Leave, Flexible Spending Accounts, voluntary Accident, Critical Illness, Hospital, Long‑Term Care, Employee Assistance Program, Pet Insurance, on‑site Wellness Clinic, Fitness Center, Café. All benefits are subject to eligibility requirements.

Physical Requirements/Work Environment

This position primarily works in an office environment and requires frequent sitting, standing, and walking. Daily use of a computer and other digital devices is required. This role may require standing for extended periods when facilitating meetings or walking through facilities. The physical demands of the position described herein are essential functions of the job and employees must be able to successfully perform these tasks for extended periods. Reasonable accommodations may be made for those individuals with real or perceived disabilities to perform the essential functions of the job described.

Masimo is proud to be an EEOE/, M/F/D/V, and we are committed to Diversity at the corporate level.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Quality Engineer
Cybersecurity Quality Engineer

Masimo Corporation • Irvine (CA)

On-site
USD 85,000 - 105,000
Medical, Dental, Vision Insurance
401(k)
Paid Maternity Leave
+2
IT GRC Analyst
IT GRC Analyst

Eightelevengroup • Town of Texas (WI), Northern (KY)

Hybrid
USD 76,000 - 110,000
Director, Quality Systems
Director, Quality Systems

Masimo Corporation • Irvine (CA)

On-site
USD 170,000 - 210,000
Medical, Dental and Vision Insurance
401(k) Plan
Paid Maternity Leave
+2
Cybersecurity Quality Engineer
Cybersecurity Quality Engineer

Masimo • Irvine (CA)

On-site
USD 85,000 - 105,000
Medical, Dental, Vision Insurance
401(k) plan
Paid Maternity Leave
+1
Director, Quality Systems
Director, Quality Systems

Masimo Medical Technologies (Malaysia) Sdn. Bhd. • Irvine (CA)

On-site
USD 170,000 - 210,000
Medical benefits
Dental benefits
Vision benefits
+1
Director, Quality Systems
Director, Quality Systems

Masimo • Irvine (CA)

On-site
USD 170,000 - 210,000
Medical Insurance
Dental Insurance
401(k)
+2
Sr Regulatory Affairs Specialist
Sr Regulatory Affairs Specialist

Masimo Corporation • Irvine (CA)

On-site
USD 85,000 - 110,000
Medical
Dental
Vision
+17
Sr Regulatory Affairs Specialist
Sr Regulatory Affairs Specialist

Masimo Medical Technologies (Malaysia) Sdn. Bhd. • Irvine (CA)

On-site
USD 85,000 - 110,000
Medical
Dental
Vision
+11
Sr Regulatory Affairs Specialist
Sr Regulatory Affairs Specialist

Masimo • Irvine (CA)

On-site
USD 85,000 - 110,000
Medical benefits
401(k) plan
Paid time off
Sr HR Business Partner
Sr HR Business Partner

Masimo Corporation • Irvine (CA), Northern (KY)

Hybrid
USD 150,000 - 190,000
Medical Insurance
Dental Insurance
Vision Insurance
+7