Sr. Staff Risk Management Analyst

Jobgether

United States

On-site

USD 140,000 - 190,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, dental, and vision
401(k) retirement plan with company  匹
Flexible PTO
Life insurance
Pet insurance
Autonomy and ownership
Collaborative environment
Exposure to enterprise risk and GRC

Job summary

Jobgether, on behalf of a partner company, seeks a Sr. Staff Risk Management Analyst in the United States to design and operate an enterprise risk management program within a healthcare technology environment.

You will work with executives to translate complex risks into clear insights and drive governance across the security program portfolio. You will establish ERM policy, risk assessment methodologies, and a multi-year risk-reduction roadmap while maintaining accountability and scalable

Qualifications

  • 10+ years of experience in information security, risk management, governance, risk, and compliance (GRC).
  • Ownership of a GRC or enterprise risk program with risk registers and governance processes.
  • Experience conducting risk assessments and maintaining risk/controls mapping.
  • Ability to present risk to executives and board-level bodies.
  • Experience with SOC 2, HITRUST, HIPAA, NIST CSF or equivalent frameworks.

Responsibilities

  • Own and mature the enterprise risk management program across the organization.
  • Develop risk appetite statements and governance processes.
  • Present risk posture and mitigation to executives and risk committees.
  • Maintain risk registers and evidence supporting security/compliance frameworks.
  • Lead governance, risk, and assurance activities with cross-functional teams.

Skills

Executive communication
GRC program ownership
Risk governance
Analytical & program management
Automation mindset

Education

CRISC
CISA
CISSP

Tools

GRC platform

Job description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Sr. Staff Risk Management Analyst based in the United States.

This is a senior leadership opportunity to build and operate an enterprise risk management program within a fast-growing, technology-driven healthcare environment.

You will establish the frameworks, processes, and reporting that enable leaders to understand and act on business risk.

The role spans enterprise risk, security governance, compliance, resilience, awareness, insurance, and the broader security program portfolio.

You will work directly with executives and governing committees, translating complex risks into clear insights that support business decisions.

As an early dedicated owner of the function, you will have significant autonomy to design programs, establish accountability, and introduce scalable processes.

The environment is collaborative and relatively flat, with a strong emphasis on ownership, initiative, automation, and continuous improvement.

This is an opportunity to shape a maturing GRC organization while helping a regulated healthcare business scale responsibly.

Accountabilities
  • Own and mature the enterprise risk management program, maintaining an enterprise-wide risk register that is distinct from the cyber risk register.
  • Develop, refine, and operationalize the enterprise risk appetite statement, ensuring it informs business decisions and priority-setting.
  • Establish and operate the ERM policy and enterprise risk assessment methodology, conducting assessments across the organization and maintaining accountability among designated risk owners.
  • Present enterprise risk posture, emerging risks, and mitigation progress to executives and the Enterprise Risk Committee.
  • Produce governance and risk-assessment evidence supporting security and compliance frameworks, including SOC 2, HITRUST, HIPAA, NIST CSF 2.0, and future control frameworks.
  • Govern reporting for the security program portfolio, tracking commitments, dependencies, priority initiatives, delivery risks, and progress against strategic objectives.
  • Maintain the multi-year security risk-reduction roadmap and provide regular visibility into progress, dependencies, and areas of concern.
  • Own the security organization’s OKRs from definition through measurement, reporting, and follow-up.
  • Track critical dependencies and drive priority initiatives through completion, influencing stakeholders across teams without direct authority.
  • Build and manage the security awareness program, establishing sustainable processes and recurring communications.
  • Manage insurance-related responsibilities, including property and casualty renewals, claims, certificates of insurance, carrier audits, and insurance requirements in customer contracts.
  • Extend second-line risk coverage into areas such as pharmacy, financial, and clinical risk in partnership with relevant domain owners.
  • Partner with third-party risk and business resilience stakeholders to ensure vendor, concentration, and resilience risks are appropriately represented in the enterprise risk view.
  • Automate recurring activities across risk-register maintenance, assessment intake, evidence collection, and reporting to improve efficiency and scalability.
  • Support first-line teams during cybersecurity compliance audits and contribute to the continued development of the broader GRC program.
  • Identify opportunities to strengthen governance, improve risk visibility, and enable the organization to move quickly while maintaining appropriate controls.
Requirements
  • 10+ years of experience in information security, risk management, governance, risk, and compliance (GRC), or a closely related field.
  • Demonstrated ownership of a GRC or enterprise risk program, including risk registers, policies, assessment methodologies, and governance processes.
  • Hands-on experience conducting risk and control self-assessments (RCSA) or a comparable enterprise risk assessment methodology.
  • Proven experience developing and maintaining a multi-year risk-reduction roadmap and reporting progress against strategic objectives.
  • Experience preparing and presenting risk reports and recommendations to executive leadership and a board, risk committee, or equivalent governing body.
  • Demonstrated ability to establish accountability and drive commitments across teams without relying on direct reporting authority.
  • Experience working with security and compliance frameworks such as SOC 2, HITRUST, HIPAA, NIST CSF, or comparable control frameworks.
  • Experience serving as the first dedicated full-time owner of a function, operating independently without an established team or dedicated budget structure.
  • Strong understanding of enterprise risk, security governance, compliance, controls, and business risk management.
  • Excellent executive communication skills, with the ability to translate complex risk information into concise, actionable business insights.
  • Strong organizational, analytical, and program management capabilities, with the ability to manage multiple priorities and stakeholders.
  • High degree of autonomy, ownership, and initiative, particularly in ambiguous or evolving environments.
  • A continuous-improvement mindset and a demonstrated preference for automating repeatable processes wherever practical.
  • Preferred: CRISC, CISA, CISSP, or an equivalent professional certification.
  • Preferred: Experience in healthcare or other environments involving highly sensitive or regulated data.
  • Preferred: Experience building AI or agentic AI systems to automate governance intake, evidence gathering, reporting, or related GRC activities.
  • Preferred: Direct involvement in SOC 2, HITRUST, or HIPAA assurance cycles.
  • Preferred: Experience developing a security awareness program from the ground up.
  • Preferred: Experience implementing, owning, or administering a GRC platform.
Benefits
  • Medical, dental, and vision insurance plans.
  • Flexible Spending Accounts (FSA) and Health Savings Accounts (HSA).
  • Flexible paid time off (PTO).
  • 401(k) retirement plan with company match.
  • Life insurance.
  • Pet insurance.
  • Additional benefits and support designed to promote employee well-being.
  • Opportunity to work in a relatively flat organization with significant autonomy and ownership.
  • Collaborative environment that encourages employees to bring forward ideas and drive meaningful initiatives.
  • Broad exposure to enterprise risk, security, compliance, and business operations within a growing healthcare technology environment.
  • Opportunity to build and shape a function with expanding organizational scope.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal/Senior Technology Risk Analyst
Principal/Senior Technology Risk Analyst

Berkshire Hathaway Specialty Insurance • Boston (MA)

On-site
USD 140,000 - 170,000
Health, Dental, Vision
Disability Insurance
Life Insurance
+8
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

LexisNexis • Raleigh (NC)

On-site
USD 118,000 - 220,000
IT GRC Analyst
IT GRC Analyst

Medasource • Town of Texas (WI), Northern (KY)

Hybrid
USD 76,000 - 110,000
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta Dental of Missouri • Missouri

Hybrid
USD 80,000 - 100,000
Manager, IT Security, Governance, Risk and Compliance
Manager, IT Security, Governance, Risk and Compliance

Burlington Stores, Inc. • Beverly (NJ)

Hybrid
USD 115,000 - 150,000
Medical, dental, and vision coverage
Paid time off and holidays
401(k) plan
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

RELX • Raleigh (NC)

On-site
USD 118,000 - 220,000
Annual incentive bonus
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta-Denta • St. Louis (MO)

Hybrid
USD 75,000 - 110,000
Director, Security Risk Management
Director, Security Risk Management

CardWorks Servicing LLC • United States

Hybrid
USD 151,000 - 168,000
Medical, Dental, and Vision coverage
401(k) Plan with Company Match
Paid vacation and sick days
Manager - Cybersecurity
Manager - Cybersecurity

Clinical Reference Laboratory • Lenexa (KS)

On-site
USD 110,000 - 245,000
Medical benefits
Dental benefits
Vision benefits
+4
Senior GRC Analyst
Senior GRC Analyst

Gilder Search Group • Atlanta (GA)

On-site
USD 90,000 - 120,000
Discretionary Annual Bonus
Comprehensive Benefits Package
401k and PTO