GRC Analyst
Overview
The GRC Analyst will play a critical role in strengthening the security posture of our growing organization by designing, implementing, and managing control and risk workflows, as well as performing third-party risk assessments. This position is pivotal in ensuring compliance with industry standards and regulations, identifying and mitigating risks, and supporting USAP’s overall security governance framework.
At this time, US Anesthesia Partners does not hire candidates residing in California, Hawaii, or Alaska.
The base pay estimate for this role is $80,900 - $137,600 annually. The final offer will depend on the skills, experience, and qualifications of the selected candidate. This range is for base pay only and does not include bonuses or other compensation. This position is eligible for an annual bonus. Bonuses are not guaranteed and are awarded based on company and individual performance.
Job Highlights
ESSENTIAL DUTIES AND RESPONSIBILITIES : ( The ideal candidate must be able to complete all physical requirements of the job with or without a reasonable accommodation)
- Leads the design, configuration, and governance of control frameworks and risk workflows within the GRC platform, ensuring alignment with organizational objectives and compliance requirements.
- Establishes and maintains control procedures, ensuring alignment with relevant frameworks (internal policy, HIPAA, HITRUST, PCI, SOC 2, NIST, and other applicable frameworks).
- Oversees the development and maintenance of control libraries, including control narratives, ownership assignments, testing frequency, and evidence requirements.
- Monitors and updates risk registers, ensuring accurate tracking, scoring, and prioritization of risks within the platform.
- Drives automation workflows to streamline control testing, evidence collection, attestations, and remediation processes.
- Tracks policy review cycles and ensures documentation remains current with regulatory and business changes.
- Leads and maintains information security risk assessments across IT, operational, and third-party domains.
- Performs control walkthroughs and operating effectiveness testing; documents results and identifies control gaps.
- Collaborates with internal teams and external auditors to facilitate audits and assessments using the GRC platform for evidence management, issue tracking, and reporting.
- Ensures ongoing compliance with regulatory requirements and industry standards by maintaining up-to-date documentation and control mappings.
- Prepares and presents reports, dashboards, and metrics on control effectiveness, risk status, and compliance gaps.
- Maps controls to applicable regulatory and framework requirements, identifying overlaps to reduce duplicative testing.
- Supports internal and external audits by gathering evidence, coordinating stakeholder responses, and tracking remediation through closure.
- Tracks and manages audit findings, corrective action plans (CAPs), and remediation timelines within the GRC platform.
- Guides risk assessments to identify potential vulnerabilities and threats, documenting findings and supporting evidence in the GRC platform.
- Partners with stakeholders to develop and implement risk mitigation strategies, tracking progress and ownership within the platform.
- Develops, monitors, and reports on key risk indicators (KRIs) and key performance indicators (KPIs) to proactively identify and address emerging risks.
- Maintains and applies consistent risk scoring methodologies, including likelihood, impact, and residual risk calculations.
- Escalates significant risks and control deficiencies to management and governance committees, providing recommendations for mitigation and improvement, in a timely manner.
- Leads the development, maintenance, and lifecycle management of information security policies, procedures, standards, and guidelines.
- Directs policy review and approval workflows with policy owners a
Get remote jobs like this by email
One weekly digest. No spam, unsubscribe anytime.