Lead Security Analyst-GRC

Collective HealthPlano, TX
Hybrid

About The Position

At Collective Health, we’re transforming how employers and their people engage with their health benefits by seamlessly integrating cutting-edge technology, compassionate service, and world-class user experience design. As our Lead Security Analyst - GRC, you’ll lead initiatives that address the company’s—and some of our industry’s—most sophisticated and meaningful security engineering challenges. You will build relationships across all parts of the business and drive multi-functional initiatives to continuously improve our security and privacy posture. You will be responsible for building and implementing controls that can scale and optimize as we move into a context-aware security environment.

Requirements

  • 8+ years in cybersecurity, GRC, audit, or risk/compliance roles.
  • Experience managing SOC 2 / HITRUST audits, especially in cloud-native environments.
  • Strong working knowledge of security frameworks and regulatory requirements.
  • Demonstrated policy, data management, and risk mitigation capabilities.
  • Familiarity with GRC tools and audit processes.
  • Excellent communication and cross-functional collaboration skills.

Nice To Haves

  • Big 4 accounting firm background.
  • Professional certifications: CISSP, CISA, CRISC, CISM, or similar.

Responsibilities

  • Evaluate and implement security controls based on frameworks such as NIST, CIS, HIPAA, SOC 2, and HITRUST.
  • Develop and maintain policies, procedures, and documentation (controls, narratives, matrices).
  • Lead SOC 2 and HITRUST audit engagements, from audit planning through remediation.
  • Coordinate and monitor third-party risk assessments and compliance reviews.
  • Own and lead BCP (Business Continuity Planning) and BIA (Business Impact Assessments) efforts.
  • Build and maintain security risk registry.
  • Perform audit readiness assessments, and support internal/external audits.
  • Partner with external auditors, control owners, and leadership to minimize business disruption.
  • Track and drive remediation plans based on audit findings and compliance gaps.
  • Maintain and communicate exception documentation for policy deviations.
  • Educate and guide control/risk owners on their responsibilities.
  • Act as a liaison between technical and non-technical stakeholders.
  • Respond to security questionnaires, RFIs, and client compliance inquiries.
  • Develop and deliver security awareness and training programs.
  • Provide executive reporting on program status, risks, and overall health.

Benefits

  • health insurance
  • 401k
  • paid time off
  • 205,000 stock options
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service