OneStudyTeam
Better. Sooner. Together.
Senior Security Compliance Analyst
Location
United States
Posted
88 days ago
Salary
Not specified
Bachelor Degree8 yrs expEnglish
Job Description
• Lead and support customer security audits, responding to security questionnaires and demonstrating compliance with security frameworks.
• Prepare, coordinate, and manage ISO 27001 audits, including evidence collection, control implementation, and auditor engagement.
• Ensure ongoing compliance with HIPAA, NIST CSF, and other regulatory requirements applicable to healthcare data security.
• Develop and maintain policies, procedures, and security documentation to meet regulatory and contractual obligations.
• Perform gap analyses and risk assessments to identify and remediate compliance risks.
• Manage and improve security governance frameworks, ensuring alignment with industry best practices and business objectives.
• Conduct third-party vendor risk assessments, ensuring compliance with security policies and contractual obligations.
• Monitor security controls, ensuring effectiveness and continuous improvement in alignment with security frameworks.
• Support security awareness training initiatives, ensuring employees understand compliance responsibilities.
• Stay current on ISO 27001, HIPAA, NIST 800-53, and other relevant standards, translating them into actionable security controls.
• Assist in defining security metrics and reporting on compliance status and risk posture to leadership.
• Work closely with legal, security, IT, and business teams to align compliance requirements with security operations.
Job Requirements
- Bachelor's degree in Information Security, Computer Science, Risk Management, or related field (or equivalent experience).
- 8+ years of progressive experience in GRC, compliance, or security audit roles.
- Experience in healthcare or regulated industries strongly preferred.
- Certifications strongly preferred: ISO 27001 Lead Auditor/Implementer, CISSP, CISM, CISA, HITRUST CCSFP, CRISC.
- Experience leading ISO 27001, SOC2, or HITRUST audits, including ISMS implementation and external audit coordination.
- Strong understanding of NIST CSF, SOC 2, GDPR, and other security frameworks.
- Hands-on experience with customer security audits, including responding to security questionnaires and managing security assessments.
- Ability to perform risk assessments, policy reviews, and compliance gap analyses.
- Strong written and verbal communication skills, with the ability to explain technical concepts to non-technical stakeholders.
- Detail-oriented with excellent organizational and project management skills.
- Ability to work independently and collaboratively in a remote environment.
- Familiarity with GRC tools (e.g., OneTrust, LogicGate, Archer, Vanta, Drata) is a plus.
Benefits
- We value diversity and believe the unique contributions each of us brings drives our success. We do not discriminate on the basis of race, sex, religion, color, national origin, gender identity, age, marital status, veteran status, or disability status.
- As a condition of employment, you will abide by all organizational security and privacy policies.
- This organization participates in E-Verify (E-Verify's Right to Work guidance can be found here).
Related Guides
Related Categories
Related Job Pages
More Security Analyst Jobs
Cybersecurity Analyst – Onsite Government Support
Trigon CyberTrigon Cyber is a small business that provides a full range of engineering services including MBSE, Digital Engineering,
Security Analyst129 days ago
Full TimeRemoteTeam 11-50Since 2019H1B No Sponsor
Senior Cybersecurity Analyst providing on-site support to government customers
Cyber Security
Florida
Security Analyst130 days ago
Full TimeRemoteTeam 1,001-5,000Since 1979H1B Sponsor
Security Analyst responsible for managing firm’s security infrastructure at Crowell & Moring LLP
CloudFirewalls
District of Columbia + 1 moreAll locations: District of Columbia, Washington
$110K - $160K / year
Security Analyst131 days ago
Full TimeRemoteTeam 1,001-5,000H1B No Sponsor
Senior IT Security Compliance Analyst ensuring IT compliance for a fintech organization
OracleSQLUnix
Security Analyst II
Fanatics, Inc.We amplify pride and create connections for all fans around the world.
Security Analyst145 days ago
Full TimeRemoteTeam 1,001-5,000Since 2011H1B No Sponsor
Information Security Analyst II ensuring robust security compliance for FBG.
PythonSQL