Governance Risk and Compliance (GRC) Analyst

TurnCare™
$60,000 - $70,000

About The Position

TurnCare is seeking a GRC Analyst to support security operations, audit readiness, and process maturity. This role is designed to streamline, drive, and maintain compliance and risk management workflows, including regular control activities, evidence collection, policy/procedure maintenance, and execution of gap closure projects. The ideal candidate is process-driven, learns by doing, is able to take a risk-based approach, familiar with the data privacy and security landscape, and eager to help strengthen TurnCare’s risk governance approach.

Requirements

  • Bachelor's degree and demonstrated role alignment such as in coursework, research, labs, internships, work experience, certifications, or special interest.
  • Relevant experience may include: security operations, IT support and system admin, audit/risk/compliance/GRC roles, and project management & operations.
  • Experience or familiarity with healthcare or other regulated environments (data processors, tech law, government contracts)
  • Projects involving security monitoring, access control, policy development, risk assessments, or regulatory research.
  • Very strong verbal and written skills: You think critically and are able to communicate effectively and authoritatively about GRC risk.
  • Business Acumen: You understand and respond to the needs of the business with a risk-based approach.
  • Strong grasp of security fundamentals: least privilege, separation of duties, identification and assessment, vulnerabilities, response, monitoring.
  • Systems: Windows and macOS basics; Microsoft 365 familiarity, system administration experience is a plus.
  • Compliance/audit: Understanding of control-based frameworks; SOC2 Type II evidence lifecycle, HITRUST is a plus.
  • Tools: JIRA or similar project management / ticketing platforms.

Nice To Haves

  • Bonus if degree in cybersecurity, IT/Information Systems, Computer Science, or related field of study.
  • HIPAA Security/Privacy rule familiarity.
  • OneTrust Tech Risk and Compliance GRC experience.
  • Progress toward CompTIA Security+, healthcare security/privacy certifications, or IAPP certifications.
  • Exposure to audit processes, control frameworks, cloud security fundamentals, Microsoft 365/Sharepoint.

Responsibilities

  • Conduct risk and impact analyses; gather evidence and inform recommendations to the business.
  • Collect, organize, and validate audit evidence for SOC2 Type II and other frameworks; help identify and remediate gaps.
  • Support compliance with HIPAA, HITRUST, NIST, and other applicable frameworks; document safeguards and impact assessments.
  • Vendor Due Diligence: assess new and renewing vendors (software, apps, contractors) handling production and non-production data.
  • Policies & Documentation: Develop, maintain, and review security policies and procedures, ensuring alignment with operations, audits, and regulations.
  • Maintain strong documentation and drive process improvement.
  • Support security operations: review employee access, triage alerts/escalations, monitor and validate control effectiveness (access controls, logging, endpoint protection).
  • Support IAM tasks, including access reviews and least-privilege validation.
  • Execute long-term projects against milestones; mature workflows to support TurnCare's growth.
  • Maintain accurate tickets, statuses, and supporting artifacts; improve consistency across security and compliance work.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service