Lead Security Analyst-GRC
At Collective Health, we’re transforming how employers and their people engage with their health benefits by seamlessly integrating cutting-edge technology, compassionate service, and world-class user experience design.
As our Lead Security Analyst - GRC, you’ll lead initiatives that address the company’s—and some of our industry’s—most sophisticated and meaningful security engineering challenges. You will build relationships across all parts of the business and drive multi-functional initiatives to continuously improve our security and privacy posture. You will be responsible for building and implementing controls that can scale and optimize as we move into a context-aware security environment.
What you'll do:
Governance & Compliance:
Evaluate and implement security controls based on frameworks such as NIST, CIS, HIPAA, SOC 2, and HITRUST.Develop and maintain policies, procedures, and documentation (controls, narratives, matrices).Lead SOC 2 and HITRUST audit engagements, from audit planning through remediation.Coordinate and monitor third-party risk assessments and compliance reviews.Own and lead BCP (Business Continuity Planning) and BIA (Business Impact Assessments) efforts.Build and maintain security risk registry