IT GRC Analyst
Remote, USA
Compensation: $55 - $80 per hour
Contract Length: 6-month Contract to Hire
Hours: Standard full-time schedule, 8 hours/day, 5 days/week; potential for extended hours under heavy audit or incident response activity.
Start Date: ASAP
ABOUT THE ROLEOur client is a healthcare organization providing primary and post-acute care services to seniors across assisted living, life plan communities, independent living, skilled nursing, and long-term care settings nationwide. The organization is value-driven, offering competitive pay, comprehensive benefits, and flexible scheduling, with a mission to improve the health, happiness, and dignity of the seniors it serves.
We are seeking an IT GRC Analyst to join the IT Security and Governance team on a 6-month contract-to-hire basis, working remotely within the USA. The IT GRC Analyst will play a key role in supporting the organization's IT Governance, Risk, and Compliance (GRC) program, focusing on security governance, regulatory compliance, risk management, audit readiness, policy administration, and control monitoring. This position collaborates with IT, Security, Privacy, Compliance, Legal, and business stakeholders to enhance the organization's security posture and ensure compliance with healthcare regulations such as HIPAA, SOC 2, and NIST. The role also contributes to business continuity, disaster recovery, and AI governance initiatives. Up to 10% travel may be required.
WHAT YOU'LL DO- Perform information security risk assessments and document identified risks, control gaps, and remediation recommendations
- Support administration and maintenance of the organization's IT Governance, Risk, and Compliance (GRC) program
- Assist with development, review, maintenance, and periodic evaluation of security policies, standards, procedures, and guidelines
- Coordinate evidence collection, control validation, documentation activities, and remediation tracking for internal and external audits and assessments
- Maintain and map security controls against applicable regulatory, contractual, and industry frameworks (e.g., HIPAA, SOC 2, NIST, CMS, URAC)
- Assist with security exception review processes and document risk acceptance decisions
- Maintain compliance metrics, risk registers, issue logs, corrective action plans, and other governance documentation
- Collaborate with technology teams to identify and remediate security vulnerabilities, control deficiencies, and compliance gaps
- Analyze emerging cybersecurity, privacy, and regulatory requirements and provide recommendations for program improvements
- Support security awareness, compliance training, and organizational education initiatives
- Support security governance forums, risk committees, and related working groups through agenda preparation, risk presentation, meeting facilitation, and documentation of decisions and action items
- Facilitate risk intake, scoring, prioritization, escalation, and ongoing monitoring activities in accordance with organizational risk management procedures
- Support administration, data quality, workflow management, reporting, and continuous improvement of GRC tooling and platforms
- Participate in security and compliance reviews for new technologies, systems, projects, AI initiatives, and significant change requests to identify regulatory and security requirements early in the lifecycle
- Support business continuity, disaster recovery, resilience planning, testing, and associated governance activities
- Support AI governance, risk assessments, control validation, and compliance reviews for approved AI technologies and use cases
- Develop and maintain key risk indicators (KRIs), key performance indicators (KPIs), and executive reporting packages supporting leadership and governance oversight
- Perform other related duties as assigned to support departmental and organizational objectives
WHAT YOU BRING- 3-5 years of experience in information security, risk management, compliance, audit, or GRC functions
- Healthcare industry experience required
- Strong understanding of information security governance, risk management, compliance, and control frameworks
- Knowledge of healthcare regulatory requirements, including HIPAA Privacy and Security Rules
- Familiarity with industry frameworks and standards such as NIST CSF, SOC 2, HIPAA, and CIS
- Experience conducting risk assessments, compliance reviews, and control evaluations
- Understanding of third-party risk management and vendor security review processes
- Ability to interpret laws, regulations, contractual requirements, and industry standards
- Strong analytical, organizational, and problem-solving skills with exceptional attention to detail and critical thinking
- Experience preparing audit-ready documentation and maintaining evidence repositories
- Excellent written and verbal communication skills, including executive-level reporting and presentations
- Ability to prioritize multiple assignments and manage deadlines in a dynamic healthcare environment
- Proficiency with Microsoft Office applications, governance tools, and compliance management platforms
- Bachelor's degree in Information Security, Information Technology, Cybersecurity, Computer Science, Healthcare Informatics, or a related field (or equivalent experience)
Nice to Haves:- Experience supporting HIPAA, SOC 2, CIS, NIST Cybersecurity Framework, or similar regulatory and security frameworks
- Experience participating in audits, risk assessments, control testing, or compliance monitoring activities
WHAT'S IN IT FOR YOU- Competitive pay and comprehensive benefits
- Flexible scheduling and remote work
- Opportunity to contribute to a mission-driven organization improving the lives of seniors
- Professional growth in a dynamic healthcare environment
- Potential for contract-to-hire conversion
#LI-CM1