Senior GRC Analyst
closed
TherapyNotes
Summary
Join TherapyNotes, a leading provider of behavioral health software, as a Cybersecurity professional. You will be responsible for developing and implementing GRC strategies, managing risks, collaborating with cross-functional teams, and ensuring compliance with regulatory standards. The role involves leading audits, providing employee training, and supporting the information security incident response team. You will also evaluate third-party solutions and identify areas for improvement in risk management. This position requires a strong understanding of regulatory requirements, risk management frameworks, and industry best practices. The ideal candidate will have a BS degree in a related field and 5+ years of experience.
Requirements
- BS degree in Information Security, Risk Management, Business Administration, or related field
- 5+ years of experience in GRC, risk management, or related fields
- Experience supporting and/or leading audit discussions
- Strong knowledge of regulatory requirements (e.g., GDPR, HIPAA, PCI-DSS, CPRA) and industry standards (e.g., ISO 27001, NIST)
- Expert in designing, implementing, and maintaining security solutions
- Experience developing and implementing GRC frameworks, policies, and procedures
- Excellent analytical skills with the ability to assess complex risks and develop effective mitigation strategies
- Exceptional communication and interpersonal skills, with the ability to effectively collaborate with stakeholders at all levels of the organization
- Proven ability to lead and manage projects, including coordinating cross-functional teams and delivering results on time
- Ability to adapt to a fast-paced and dynamic environment, with a focus on continuous improvement and innovation
- Expert in OWASP, CIS and/or other security standards and secure configuration baselines
- Proficiency with cloud-based solutions and web related technologies
Responsibilities
- Develop and implement GRC strategies, policies, and procedures to ensure compliance with regulatory standards and industry best practices
- Lead the assessment and management of risks across the organization, including conducting risk assessments, identifying gaps, and developing mitigation plans
- Collaborate with cross-functional teams to integrate GRC principles into business processes and systems
- Monitor regulatory changes and industry trends to ensure the organization remains compliant and proactive in addressing emerging risks
- Provide guidance and training to employees on GRC policies, procedures, and best practices
- Support the execution of audits, assessments, and compliance activities through validation of adherence to compliance standards
- Mentor and coach GRC analysts, fostering their professional development and growth within the organization
- Support the execution and continual improvement of the companyβs information security program, with an emphasis on meeting HIPAA-HITECH, state, and GDPR compliance requirements
- Identify and document cyber risks and manage mitigation, follow up on open security risks, and report issues to leadership
- Assist with ad-hoc compliance reporting and follow up with customers and/or support partners to ensure all identified vulnerabilities are being addressed
- Provide support to Information Security Incident Response team during cyber/privacy incidents
- Validate that information security requirements are built into architectures and new technology projects
- Ensures the running application and developing codebase protects the confidentiality, integrity, and availability of our customer's data
- Evaluate the technical security posture of newly proposed third-party solutions
- Identify areas of improvement related to third party risk management to drive maturity
Preferred Qualifications
Certified Information Systems Security Professional (CISSP), Certified Information Security Auditor (CISA), Certified Information Security Manager (CISM) or Certified in Risk and Information Systems Control (CRISC) strongly preferred
Benefits
- Competitive salary - $95,000-$135,000
- Employer sponsored health, dental, vision, life, and disability insurance
- Retirement plan with company contribution
- Annual company profit sharing
- Personal development/training budget
- Open, collaborative work environment
- Extensive 2-week onboarding plan
- Comprehensive mentorship program