GRC/IT Compliance Analyst

Cleerly
$108,000 - $130,000Remote

About The Position

Cleerly is revolutionizing heart disease diagnosis and treatment through AI-driven precision diagnostic solutions. We are a growing healthcare company that has secured significant funding to support our mission. While many of our teams work remotely, we have offices in Denver, New York, Dallas, and Lisbon. Our technology quantifies and characterizes atherosclerosis, aiming to prevent heart attacks. We utilize various digital collaboration tools like Google Workspace, Slack, Confluence/Jira, and Zoom. Travel may be required for team meetings and projects. Cleerly is committed to providing safe and effective medical software, adhering to regulatory requirements, and continuously improving our products and processes to manage risks and ensure compliance throughout the software lifecycle. Understanding the importance of this role is critical to achieving Cleerly's quality objectives.

Requirements

  • 5-7 years of experience in security or compliance analysis, IT risk assessment, risk management, or assurance/advisory experience over IT/IS general controls
  • BS degree in Management Information Systems, Computer Science, Accounting with ITGC experience, Engineering, Cybersecurity, Bio-Medical Engineering, or a related field
  • Experience with GRC software implementation
  • Experience with FDA regulatory submissions and SaMD (Software as a Medical Device) regulations
  • Proven experience in enterprise risk management (ERM) frameworks, risk identification, and qualitative/quantitative risk assessment methodologies
  • Previous experience working within a startup environment
  • Experience with Agile/Scrum environments and integrating security/compliance into the SDLC
  • Strong understanding of internal controls necessary to meet compliance frameworks such as ISO 27001, HITRUST, and SOC 2
  • Excellent verbal and written communication skill sets for addressing security concerns from internal stakeholders within the company

Nice To Haves

  • CISA, CISM, CISSP, CRISC, or related certifications
  • Experience in the digital healthcare industry
  • Experience with open-source GRC tooling such as CISO Advisor or Eramba is a plus

Responsibilities

  • Build and implement a new enterprise risk assessment platform to streamline compliance workflows
  • Continuously monitor and update the risk platform to reflect evolving threats and regulatory requirements
  • Participate in risk analysis and features development processes to proactively identify risks to our regulated products
  • Continuously monitor and evaluate internal controls for areas of improvement
  • Conduct user access reviews to applications and services
  • Periodically review policies and procedures for compliance with best practices and compliance frameworks
  • Assist in owning and drafting documents for FDA regulatory submissions

Benefits

  • Stock options
  • Paid benefits
  • Employee perks
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service