Security and Compliance Analyst

Pomelo Care Logo

Pomelo Care

💵 $120k-$140k
📍Remote - United States

Summary

Join Pomelo Care as a Security and Compliance Analyst to support the development and execution of our information security and Governance, Risk, and Compliance (GRC) program. Collaborate across departments to identify and mitigate cybersecurity risks, ensure regulatory compliance, and contribute to security and privacy initiatives. Implement and maintain Pomelo Care’s information security and GRC program, including policies, standards, and procedures. Perform security risk assessments and control evaluations, track remediation activities, and support third-party risk management. Participate in internal and external audits and manage compliance with healthcare regulations. Develop and maintain metrics and dashboards to communicate GRC program status. Manage GRC or security-related projects and provide support for security awareness and training initiatives. This role requires a minimum of 3 years of experience in a related field and excellent organizational and communication skills.

Requirements

  • Minimum 3 years of professional experience in GRC, cybersecurity, compliance, risk management, or a related field
  • Experience coordinating or managing projects, including developing plans, tracking progress, and collaborating with stakeholders
  • Excellent organizational skills and attention to detail
  • Strong written and verbal communication skills
  • Ability to work independently and prioritize multiple tasks in a fast-paced startup environment

Responsibilities

  • Support the implementation and maintenance of Pomelo Care’s information security and GRC program, including policies, standards, and procedures
  • Assist in performing security risk assessments and control evaluations across the organization
  • Track and coordinate remediation activities for identified risks or compliance gaps
  • Support third-party risk management activities, including vendor security reviews, user access reviews and due diligence assessments
  • Participate in internal and external audits (e.g., SOC 2, HITRUST), including evidence collection and responding to the auditor. inquiries
  • Help manage compliance with healthcare-specific regulations (e.g., HIPAA) and security frameworks
  • Support the development and project management of security compliance workflows, including implementation of technical and administrative controls
  • Develop and maintain metrics and dashboards to communicate GRC program status to stakeholders
  • Document processes, workflows, and control narratives to support governance and compliance efforts
  • Manage GRC or security-related projects, ensuring timely and quality delivery
  • Provide support for security awareness and training initiatives

Preferred Qualifications

  • Bachelor’s degree in Computer Science, Information Security, Information Systems, Business, or a related discipline
  • Professional certification such as CISA, CRISC, Security+, PMP or similar
  • Experience in healthcare technology startups or familiarity with healthcare regulatory requirements (e.g., HIPAA, HITRUST)
  • Experience with GRC tools and platforms, such as Vanta and MyCSF

Benefits

  • Competitive healthcare benefits
  • Generous equity compensation
  • Unlimited vacation
  • Membership in the First Round Network (a curated and confidential community with events, guides, thousands of Q&A questions, and opportunities for 1-1 mentorship)

Share this job:

Disclaimer: Please check that the job is real before you apply. Applying might take you to another website that we don't own. Please be aware that any actions taken during the application process are solely your responsibility, and we bear no responsibility for any outcomes.