GRC Security Analyst

Curana Health, Inc.•Remote,
•Remote

About The Position

Curana Health is seeking an IT Governance, Risk, and Compliance Analyst to join our IT Security and Governance team. In this role, you will help strengthen our security and compliance programs by supporting risk management, audit readiness, policy administration, control monitoring, and regulatory compliance activities. You will work closely with IT, Security, Privacy, Compliance, Legal, and business teams to identify risks, support practical solutions, and help ensure Curana Health continues to meet security and regulatory expectations as we grow.

Requirements

  • Bachelor’s degree in Information Security, Cybersecurity, Information Technology, Computer Science, Healthcare Informatics, or a related field; equivalent experience will also be considered.
  • 2–5 years of experience in GRC, information security, risk management, audit, compliance, cybersecurity, or a related function.
  • Experience supporting risk assessments, compliance reviews, audits, control testing, or governance activities.
  • Experience working in a regulated industry or compliance-driven environment.
  • Knowledge of the HIPAA Security Rule.
  • Understanding of information security governance, risk management, and compliance concepts.
  • Strong analytical, organizational, and problem-solving skills.
  • Excellent written and verbal communication skills.
  • Ability to manage multiple priorities and deadlines in a fast-paced environment.

Nice To Haves

  • Healthcare industry experience.
  • Knowledge of the HIPAA Privacy Rule.
  • Experience with frameworks such as HIPAA, SOC 2, NIST Cybersecurity Framework, CIS Controls, CMS, URAC, HITRUST, or ISO 27001.
  • Experience with third-party risk management programs.
  • Experience with GRC platforms such as ServiceNow GRC, Archer, OneTrust, AuditBoard, LogicGate, or similar solutions.
  • Experience supporting AI governance, emerging technology risk reviews, or security governance initiatives.

Responsibilities

  • Conduct security risk assessments and help document risks, control gaps, and recommended next steps.
  • Support ongoing improvements to Curana Health’s Governance, Risk, and Compliance program.
  • Help maintain security policies, standards, procedures, and guidelines.
  • Coordinate audit and assessment activities, including evidence collection, control validation, documentation, and remediation tracking.
  • Map security controls to frameworks including HIPAA, SOC 2, NIST, CIS, CMS, and URAC.
  • Support compliance monitoring activities and assist with regulatory readiness initiatives.
  • Maintain risk registers, issue logs, corrective action plans, compliance metrics, and governance documentation.
  • Partner with technology teams to address security vulnerabilities, control deficiencies, and compliance gaps.
  • Participate in risk intake, assessment, prioritization, escalation, and ongoing monitoring activities.
  • Support third-party risk management and vendor security review processes.

Benefits

  • health insurance
  • paid time off
  • paid holidays
  • a 401(k) retirement savings plan
  • additional wellness and support programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service