Sr. GRC Analyst

🏢 Aya Healthcare · all Aya Healthcare jobs (13)
📍 United States
💰 USD 105,000 - 135,000 / annual
📅 Posted 2026-09-04 · via Himalayas
🏷 GRC-Analyst,Governance-Risk-And-Compliance,Compliance-Analyst,Information-Security-Compliance,IT-Audit,Senior-Security-GRC-Analyst,GRC-Senior-Analyst,Senior-GRC-Consultant,Cybersecurity-GRC-Analyst,Risk-and-Compliance-(GRC)-Analyst,IT-GRC-Analyst
Apply on original site ↗

Join Aya Healthcare , winner of multiple Top Workplace awards!

We are seeking a Senior Governance, Risk & Compliance (GRC) Analyst to help operate and mature Aya’s enterprise GRC program, with a strong emphasis on compliance automation, scalability, and operational excellence. In this role, you will own GRC projects and deliverables across the organization while serving as a subject-matter expert in compliance operations, risk management, and ServiceNow GRC / IRM.

This is a hands-on opportunity for someone energized by improving modern GRC capabilities and moving away from manual, point-in-time audit work toward automated, continuously operating compliance processes.

You will work cross-functionally across Information Security, IT, Legal, Privacy, Engineering, Finance, and Audit to translate regulatory and framework requirements into practical controls, improve evidence collection and reporting, and deliver clear, actionable insights to stakeholders and leadership.

You will work in the Security organization and report to the Manager, Governance, Risk & Compliance.

This role is remote and will work PST business hours.
Who We Are:

We’re an $8+ billion, rapidly growing workforce solutions provider in the healthcare industry. We deliver tech-enabled services that help healthcare organizations meet and manage their contingent labor needs. We build and manage tech-enabled marketplaces for national and local healthcare talent and deliver contingent labor management solutions through our proprietary software platform.

At Aya, we’re obsessed with creating exceptional experiences for our clients, clinicians, and employees. In fact, we put employee satisfaction above all else. Our team members are responsible for incomparable customer experience and we know that happy employees are critical to maintaining happy clients. We foster an entrepreneurial, high-energy, low-bureaucracy culture and value innovative thinking and creative problem-solving. We embrace diversity in thought and backgrounds unified by a commitment to high achievement. When you join Aya, you’ll be surrounded by teammates who care about you as an individual and leaders who will help you grow both personally and professionally.
Responsibilities:

- Own assigned GRC projects, compliance deliverables, and process improvements from planning through completion.

- Support the day-to-day operation and continuous improvement of Aya’s enterprise GRC program.

- Design and improve scalable workflows that translate regulatory and framework requirements into clear control activities and operational responsibilities.

- Support compliance efforts for SOC 2 and ISO/IEC 27001:2022, including readiness activities, audit preparation, evidence coordination, control testing, auditor support, and remediation tracking.

- Establish and maintain clear control ownership, traceability, documentation, and evidence requirements.

- Identify opportunities to replace manual or spreadsheet-driven compliance activities with automated, system-driven processes.

- Improve automated evidence collection, control testing, issue and remediation tracking, dashboards, and reporting.

- Conduct control reviews, risk assessments, evidence evaluations, and compliance gap analyses.

- Monitor remediation activities, follow up with control owners, identify delivery risks, and escalate issues when appropriate.

- Build and maintain dashboards, metrics, and reports that communicate compliance status, trends, exceptions, risks, and remediation progress.

- Partner with ServiceNow platform and engineering teams to ensure GRC solutions are scalable, supportable, and aligned with enterprise processes.

- Engage with customers to respond to compliance, security, privacy, and risk-related questions in RFPs, due diligence requests, contracts, and customer meetings.

- Collaborate with Security, IT, Engineering, Finance, Legal, Privacy, Internal Audit, and business stakeholders to resolve control and compli

← All remote jobs

Get remote legal jobs like this by email

One weekly digest. No spam, unsubscribe anytime.

Similar for you