Sr. GRC Analyst

9 hours, 53 minutes ago
Full-time
Senior
Cybersecurity
Aya Healthcare

Aya Healthcare

Aya Healthcare is the largest healthcare staffing company in the U.S., offering travel nursing, allied staffing, and permanent placement services with a focus on excellence and innovation.

Professional Services
10K-50K

Description

  • Own GRC projects, compliance deliverables, and process improvements from planning through completion.
  • Operate and continuously improve the enterprise GRC program.
  • Design scalable workflows that translate regulatory and framework requirements into controls and operational responsibilities.
  • Support SOC 2 and ISO/IEC 27001:2022 readiness, audits, evidence coordination, control testing, and remediation tracking.
  • Improve automated evidence collection, control testing, issue tracking, dashboards, and reporting.
  • Conduct control reviews, risk assessments, evidence evaluations, and compliance gap analyses.
  • Monitor remediation activities, follow up with control owners, and escalate delivery risks.
  • Partner with ServiceNow platform and engineering teams to develop scalable GRC solutions.
  • Respond to customer compliance, security, privacy, and risk inquiries for RFPs, due diligence, contracts, and meetings.
  • Collaborate across Security, IT, Engineering, Finance, Legal, Privacy, Audit, and business teams while guiding junior analysts and documenting processes.

Requirements

  • 4+ years of experience in GRC, information security, IT audit, or a related discipline.
  • Hands-on experience with GRC tools such as ServiceNow GRC/IRM, Drata, Vanta, or Hyperproof.
  • Experience owning GRC projects, compliance deliverables, or process-improvement initiatives end to end.
  • Strong working knowledge of SOC 2 or ISO/IEC 27001:2022; healthcare or HIPAA experience preferred.
  • Experience with control design, evidence evaluation, risk assessments, audit support, remediation tracking, or compliance testing.
  • Experience automating manual compliance processes through workflow design or system-based reporting.
  • Strong written and verbal communication skills for technical and non-technical audiences.
  • Ability to work independently, manage competing priorities, anticipate next steps, and escalate risks early.
  • Experience collaborating across security, IT, engineering, legal, privacy, finance, audit, and business teams.
  • Bachelor’s degree in IT or computer science, relevant certification, ServiceNow implementation experience, GRC reporting experience, or familiarity with frameworks such as ISO 42001, NIST AI RMF, NIST CSF, GDPR/UK GDPR, and CCPA/CPRA are preferred or advantageous.

Benefits

  • Annual salary range of $105,000–$135,000, with potential discretionary bonuses.
  • Free premium medical, dental, life, and vision insurance.
  • Generous 401(k) match.
  • Unlimited DTO and paid sick leave in accordance with applicable laws.
  • Reimbursements and other eligible benefits.
  • Daily virtual yoga, meditation, and boot camp classes.
  • Company-sponsored virtual events, happy hours, team-building activities, and birthday recognition.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

GRC Analyst

Coretelligent 251-1K Internet Software & Services

Coretelligent is seeking a GRC Analyst to support client cybersecurity and compliance programs through security awareness initiatives, vendor risk assessments, controls framework maintenance, and governance activities across multiple environments.

Cybersecurity HIPAA
1 day, 9 hours ago

Security GRC Analyst

Pinterest 5K-10K Internet Software & Services

Pinterest is seeking a Security Engineer (GRC Senior Analyst) to strengthen its security governance, risk, compliance, audit, and assurance programs while helping cross-functional teams manage security risk effectively.

Cybersecurity
1 day, 9 hours ago

SOC L1 Analyst

Lion Hires Recruitment / staffing / talent acquisition

The client is seeking a SOC Analyst to monitor fintech infrastructure, detect and respond to threats, and strengthen security operations protecting sensitive financial data.

AWS Azure Cybersecurity ELK Stack SIEM Splunk
3 days, 10 hours ago

SOC L2 Analyst

Lion Hires Recruitment / staffing / talent acquisition

Join the client’s Information Security team as a SOC L2 Analyst, investigating and resolving advanced threats while strengthening security operations across its fintech ecosystem.

AWS Azure Cybersecurity ELK Stack Splunk
3 days, 10 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers