Sr. Lead Information Security Governance, Risk, and Compliance (GRC) Analyst

US Anesthesia Partners, Inc.Remote,
$89,000 - $151,300

About The Position

The Sr Lead Information Security Governance, Risk, and Compliance (GRC) Analyst will play a critical role in strengthening the security posture of our growing organization by designing, implementing, and managing control and risk workflows, as well as performing third-party risk assessments. This position is pivotal in ensuring compliance with industry standards and regulations, identifying and mitigating risks, and supporting USAP’s overall security governance framework.

Requirements

  • Bachelor’s degree in information security, cybersecurity, computer science, information technology, business administration, or a closely related field required. Equivalent experience may be considered in lieu of a degree (e.g., 4+ years of relevant experience in information security, compliance, or GRC roles).
  • Minimum of 8 years’ relevant experience in governance, risk, and compliance functions within IT or information security.
  • Prior experience implementing, managing, or auditing security policies and procedures.
  • Familiarity with compliance frameworks (HIPAA, NIST CSF, SOC 2, HITRUST, etc.).
  • Prior experience conducting risk assessments and supporting risk management activities.
  • Excellent written and verbal communication skills, including the ability to communicate technical concepts and compliance requirements to both technical and non-technical stakeholders.
  • Ability to manage multiple priorities, work independently, and collaborate effectively across cross-functional teams.

Nice To Haves

  • Certified Information Systems Auditor (CISA) preferred.
  • Certified Risk and Information Systems Control (CRISC) preferred.
  • Certified Information Security Manager (CISM) preferred.
  • Other relevant certifications (e.g., CompTIA Security+, ISO 27001 Lead Auditor) preferred.

Responsibilities

  • Leads the design, configuration, and governance of control frameworks and risk workflows within the GRC platform, ensuring alignment with organizational objectives and compliance requirements.
  • Establishes and maintains enterprise control procedures, ensuring alignment with relevant frameworks (Internal Policy, HIPAA, HITRUST, PCI, SOC 2, NIST, and other applicable frameworks).
  • Oversees the development and maintenance of control libraries, including control narratives, ownership assignments, testing frequency, and evidence requirements.
  • Monitors and updates risk registers, ensuring accurate tracking, scoring, and prioritization of risks within the platform.
  • Drives automation workflows to streamline control testing, evidence collection, attestations, and remediation processes.
  • Tracks policy review cycles and ensures documentation remains current with regulatory and business changes.
  • Leads and maintains information security risk assessments across IT, operational, and third-party domains.
  • Performs control walkthroughs and operating effectiveness testing; documents results and identifies control gaps.
  • Collaborates with internal teams and external auditors to facilitate audits and assessments using the GRC platform for evidence management, issue tracking, and reporting.
  • Ensures ongoing compliance with regulatory requirements and industry standards by maintaining up-to-date documentation and control mappings.
  • Prepares and presents reports, dashboards, and metrics on control effectiveness, risk status, and compliance gaps.
  • Maps controls to applicable regulatory and framework requirements, identifying overlaps to reduce duplicative testing.
  • Supports internal and external audits by gathering evidence, coordinating stakeholder responses, and tracking remediation through closure.
  • Tracks and manages audit findings, corrective action plans (CAPs), and remediation timelines within the GRC platform.
  • Guides risk assessments to identify potential vulnerabilities and threats, documenting findings and supporting evidence in the GRC platform.
  • Partners with stakeholders to develop and implement risk mitigation strategies, tracking progress and ownership within the platform.
  • Develops, monitors, and reports on key risk indicators (KRIs) and key performance indicators (KPIs) to proactively identify and address emerging risks.
  • Maintains and applies consistent risk scoring methodologies, including likelihood, impact, and residual risk calculations.
  • Escalates significant risks and control deficiencies to management and governance committees, providing recommendations for mitigation and improvement, in a timely manner.
  • Leads the development, maintenance, and lifecycle management of information security policies, procedures, standards, and guidelines.
  • Directs policy review and approval workflows with policy owners and stakeholders.
  • Ensures policies remain aligned with evolving regulatory requirements and organizational changes.
  • Leads evaluations of third-party vendors for security and compliance risks, including review of SOC reports, security questionnaires, and contractual requirements.
  • Tracks vendor risk assessments, reassessment cycles, and risk ratings within the GRC platform.
  • Works with business owners to develop and monitor vendor remediation action plans.
  • Supports vendor onboarding and offboarding risk reviews, ensuring appropriate due diligence is documented.
  • Identifies opportunities to enhance GRC processes and workflows to improve efficiency, accuracy, and effectiveness.
  • Stays current on industry trends, emerging threats, and best practices in GRC, recommending improvements to the security and compliance program.
  • Champions automation and integration initiatives to reduce manual effort.
  • Guides periodic program assessments and maturity benchmarking to guide roadmap priorities.
  • Performs other duties and responsibilities as assigned.

Benefits

  • Annual bonus
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service