InfoSec GRC Analyst
Job Description
ExamWorks is seeking an experienced GRC Analyst to support information security governance, risk management, and compliance activities across the organization and its subsidiaries. This role is 100% remote within the United States and supports compliance and audit engagements including HITRUST and SOC 2.
Role Focus
The GRC Analyst will assess, implement, manage, and document security controls aligned to ExamWorks’ information security strategy and compliance expectations. The position also contributes to program effectiveness by supporting risk assessment activities, security standards and testing, and the development and maintenance of policies, standards, and procedures.
Key Responsibilities
- Assess, implement, manage, and document security controls supporting ExamWorks and subsidiary information security strategy and compliance requirements.
- Promote an effective security program, including system-wide security analysis, intrusion and vulnerability detection, standards and testing, risk assessment, awareness and education, and the development of policies, standards, and procedures.
- Support HITRUST and SOC 2 audit engagements through data and artifact collection, exception remediation, and ongoing monitoring.
- Respond to client assessments and RFPs, and conduct vendor risk assessments as well as reassessments.
- Participate in cross-training sessions with the IT Security team focused on management and configuration of security tools and technical controls.
Required Qualifications
- College Degree in Computer Science or a related field.
- 5+ years of experience across IT security, risk management, compliance, and audit.
- Subject matter expert knowledge and experience with compliance and security framework standards including SOX, PCI, SOC, NIST, ISO 27001, HITRUST, HIPAA, and HITECH.
- Experience coordinating compliance audit processes and IT security risk assessment programs.
- Ability to articulate general IT security policies, processes, and technical controls.
- Capability to provide input on controls design, implementation, and deficiency remediation.
- Excellent written and verbal communication skills.
Relevant Technologies and Standards
- SOX
- PCI
- SOC
- NIST
- ISO 27001
- HITRUST
- HIPAA
- HITECH
Location and Compensation
Location: Atlanta, GA (remote)
Salary: USD 60,000 - 90,000 per year
Experience Level: 5+ years
Benefits
- Competitive benefits including medical, vision, and dental
- Paid time off
- 401k