Governance, Risk & Compliance Analyst

3 weeks, 5 days ago
Full-time
Senior
Legal
SWORD Health

SWORD Health

SWORD Health provides AI-powered digital physical therapy solutions designed to prevent pain, support recovery, and enhance overall health, while also aiming to transform the rehabilitation industry through innovative technology and clinical oversight.

Health Care Providers & Services
251-1K
Founded 2015
$324M raised

Description

  • Act as the primary subject matter expert for security and compliance inquiries, including security questionnaires, RFPs, and M&A due diligence.
  • Build and maintain a knowledge base to support accurate and efficient responses to partners and clients.
  • Own certification lifecycles end to end, including ISO 27001 and Cyber Essentials, and maintain year-round audit readiness.
  • Lead external audits and manage certification processes from start to finish.
  • Work with the GRC team to improve programs and keep control-to-process mappings robust and scalable.
  • Partner with the Quality Assurance & Regulatory Affairs team to align security frameworks with medical device compliance and AI Act requirements.
  • Collaborate with product teams on current and future initiatives to ensure security-by-design.
  • Work with Security, Product, Engineering, and IT teams to integrate security controls into workflows with minimal operational friction.
  • Provide subject matter expertise and support for security and compliance training and other GRC initiatives as needed.

Requirements

  • 5+ years of hands-on experience in GRC, with a track record of leading audits and maintaining internationally recognized security certifications.
  • Hands-on experience with at least three frameworks or standards, such as ISO 27001, SOC 2, HITRUST, NIS2, Cyber Resilience Act, FedRAMP, CMMC, NIST SP 800-171, NIST SP 800-53, GDPR, HIPAA, or PCI DSS.
  • Exceptional written and spoken English, with the ability to communicate complex security concepts clearly and authoritatively.
  • Strong understanding of how security controls apply to infrastructure and product environments, including mapping requirements to technical work instructions.
  • Ability to quickly learn new products or initiatives and define the appropriate compliance path forward.
  • Familiarity with the intersection of cybersecurity and privacy/regulatory frameworks, such as GDPR, AI Act, or medical device regulations.
  • Familiarity with medical device certifications and regulations, such as ISO 13485 and FDA Good Manufacturing Practices (GMP).
  • Proven experience using LLMs to speed up personal GRC workflows.
  • Strong plus: experience designing and implementing AI-driven automations or integrated workflows that replace manual processes and improve team productivity.
  • Experience working across teams such as Legal, Quality, and IT to align on compliance goals.
  • Must be based in Portugal and hold a valid EU visa; relocation assistance is not provided.

Benefits

  • Competitive salary with a total compensation range of €35,000 - €70,000 a year, including base, variable, and equity.
  • Health, dental, and vision insurance.
  • Meal allowance.
  • Equity shares / stock options.
  • Remote work allowance and work-from-home support.
  • Flexible working hours and a remote or hybrid work policy.
  • Discretionary vacation / unlimited vacation.
  • Access to a health and well-being program, including digital therapist sessions.
  • Snacks and beverages.
  • English classes.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Risk Analyst

Pavago IT Services

A remote Risk Analyst / Risk Manager at a client organization will identify, assess, and mitigate financial, operational, compliance, and enterprise risks while supporting reporting, controls, and leadership decision-making.

HIPAA Looker Power BI Python R SQL Tableau
19 minutes ago

[Wattpad] Trust & Safety Contractor (Independent Contractor)

Wattpad 51-250 Internet Software & Services

Wattpad is hiring an independent Trust & Safety Contractor in Toronto to investigate copyright infringement reports and help enforce platform policies across its global storytelling platform.

19 minutes ago

Senior Manager, Compliance Product Data

Coinbase 1K-5K Capital Markets

Coinbase is hiring a Compliance Product Data Lead to build and lead the compliance data product function, shaping the data ecosystem that supports transaction monitoring, customer risk, screening, and regulatory reporting.

Databricks GCP Generative AI Machine Learning Snowflake SQL
1 hour, 43 minutes ago

Global Indirect Tax Compliance

Stripe 5K-10K Diversified Financial Services

Stripe is seeking a seasoned International Indirect Tax professional in Bangalore to lead global VAT/GST compliance as the company scales its international business.

LLM
2 hours, 22 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers