Job Title: Senior Information Security Analyst (Governance, Risk & Compliance)
Remote position
W2 Requirement
Role Overview
Track and coordinate the work behind the HIPAA Security Risk Analysis and SOC 2 readiness, and support third-party risk, data inventory, and broader compliance programs. Identify and document gaps, then work with the business to drive remediation to closure.
Responsibilities
- *HIPAA Security Risk Analysis:* Support the annual SRA alongside an external assessor.
- Confirm scope covers every system that handles ePHI.
- Coordinate evidence and subject matter expert interviews.
- Track findings, corrective actions, and exceptions through to closure.
- *SOC 2:* Support readiness and audits through Type 1, Type 2, and ongoing annual cycles.
- Gap assessments against the Trust Services Criteria.
- Auditor requests and evidence collection.
- Control narratives and exception tracking.
- Monitoring controls between audits.
- *Remediation tracking:* Own the record for each gap (owner, due date, status, evidence), run check-ins with the teams doing the work, and report progress to leadership.
- *Control mapping:* Map controls across HIPAA, SOC 2, and NIST CSF 2.0 so evidence can be reused across frameworks, laying the groundwork for HITRUST.
- *Secondary focus:*
- Coordinate data, technology, and AI inventories, including where PHI lives, who owns it, and how it's classified.
- Support third-party risk management:
- Classify vendors by risk tier.
- Review SOC reports and security questionnaires.
- Research vendor risk signals.
- Coordinate BAAs, NDAs, and MSAs with Legal.
- Keep vendor onboarding, offboarding, and risk records audit-ready.
- Maintain the security risk register and risk acceptances, and act as liaison to the enterprise risk management program.
- Produce regular security metrics and status reporting, and coordinate evidence for periodic user access reviews.
- Help maintain security policies and procedures, handle first-pass intake for security reviews and RFP security requirements, and support customer security questionnaires.
- Keep records of approved AI tools and use cases current.
Qualifications
- 4+ years in security compliance, GRC, risk management, or audit, ideally in healthcare or another highly regulated industry.
- Direct experience supporting SOC 2 audits and HIPAA risk analyses with external auditors or assessors.
- Working knowledge of the HIPAA Security Rule and how PHI moves through cloud and SaaS environments.
- Hands-on experience with at least one GRC or compliance automation platform.
- Strong project coordination skills across multiple teams.
- Day-to-day proficiency using AI tools to streamline compliance work.
- Strong written and verbal communication skills.
*Extra Credit:*
- Familiarity with NIST AI RMF, OWASP SAMM, or HITRUST.
- Vendor security review or third-party risk experience.
- Experience on a small, high-performing team.
- Interest in growing toward security engineering or governance leadership.
- CISA, CRISC, or CISSP (not required).