Job Closed

This listing is no longer active.

TherapyNotes.com logo
TherapyNotes.com

TherapyNotes is the go-to superhero for behavioral health Practice Management and EHR software! Our top-notch SaaS solution handles scheduling, billing, documenting, telehealth, and more so clinicians can focus on awesome patient care. We're a dynamic team of pros who love to innovate and push the envelope, keeping our software cutting-edge. Join us, and let's revolutionize behavioral health software together while making a real difference!

Lead GRC Analyst

Location

United States

Posted

75 days ago

Salary

$125K - $165K / year

Seniority

Lead

English

Job Description

Lead GRC Analyst

TherapyNotes.com

About Us TherapyNotes is the go-to superhero for behavioral health Practice Management and EHR software! Our top-notch SaaS solution handles scheduling, billing, documenting, telehealth, and more so clinicians can focus on awesome patient care. We're a dynamic team of pros who love to innovate and push the envelope, keeping our software cutting-edge. Join us, and let's revolutionize behavioral health software together while making a real difference! About The Position TherapyNotes is seeking an experienced cyber security professional to join our team of technology enthusiasts.  The right candidate should have a focus on cybersecurity compliance, security control implementation, risk/vulnerability management, continuous monitoring, and security awareness training. The role will serve as the liaison for external audits, oversee an internal cybersecurity audit program, and lead a team of GRC Analysts. This role requires a strong understanding of regulatory requirements, risk management frameworks, and industry best practices. What You'll Do - Architect, implement, and continuously mature the organization’s Governance, Risk, and Compliance (GRC) program, aligning it with HIPAA-HITECH, HITRUST CSF, state privacy regulations, GDPR, and other applicable regulatory frameworks. - Lead organization-wide risk identification, analysis, and treatment processes using structured methodologies to conduct risk assessment, identify gaps, and develop mitigation plans. - Lead end-to-end third-party risk management activities, including structured vendor security assessments, evaluation of assurance artifacts (SOC 2, ISO 27001, penetration tests), risk impact analysis and residual risk determination. - Conduct formal risk assessments across infrastructure, application, vendor, and business process domains. - Collaborate with cross-functional teams to integrate GRC principles into business processes and systems. - Monitor evolving regulatory requirements, enforcement trends, and industry best practices to proactively adjust the organization’s compliance program. - Provide guidance and training to employees on GRC policies, procedures, and best practices. - Oversee the execution of audits, assessments, and compliance activities to validate adherence to compliance standards. - Ensure documentation artifacts support evidentiary requirements for regulatory examinations and certification audits. - Act as a liaison with external auditors, regulators, and stakeholders on GRC-related matters. - Develop and maintain key performance indicators (KPIs) and metrics to measure the effectiveness of GRC initiatives. - Mentor and coach GRC analysts, fostering their professional development and growth within the organization. - Drive continual improvement of the organization’s information security program, ensuring alignment with HITRUST CSF, HIPAA, GDPR, ISO 27701, and other frameworks as required. - Identify and document cyber risks and manage mitigation, follow up on open security risks, and report issues to leadership. - Assist with ad-hoc compliance reporting and follow up with customers and/or support partners to ensure all identified vulnerabilities are being addressed. - Provide support to Information Security Incident Response team during cyber/privacy incidents. - Review architectural designs and new technology initiatives to validate alignment with regulatory and internal security requirements. - Ensures the running application and developing codebase protects the confidentiality, integrity, and availability of our customer's data. - Evaluate the technical security posture of newly proposed third-party solutions. What We're Looking For - BS degree in Information Security, Risk Management, Business Administration, or related field - 5+ years of experience in GRC, risk management, or related fields, with demonstrated leadership experience - Certified Information Systems Security Professional (CISSP), Certified Information Security Auditor (CISA), Certified Information Security Manager (CISM) or Certified in Risk and Information Systems Control (CRISC) strongly preferred - Strong knowledge of regulatory requirements (e.g., GDPR, HIPAA, PCI-DSS, CPRA) and industry standards (e.g., ISO 27001, NIST). - Expert in designing, implementing, and maintaining security solutions - Understanding of modern approaches to GRC such as Policy-as-Code and Compliance-as-Code - Experience developing and implementing GRC frameworks, policies, and procedures - Excellent analytical skills with the ability to assess complex risks and develop effective mitigation strategies - Exceptional communication and interpersonal skills, with the ability to effectively collaborate with stakeholders at all levels of the organization - Proven ability to lead and manage projects, including coordinating cross-functional teams and delivering results on time - Ability to adapt to a fast-paced and dynamic environment, with a focus on continuous improvement and innovation - Proficiency with security standards and secure configuration baselines such as CIS or OWASP - Proficiency with cloud-based solutions and web related technologies What We Offer - Competitive salary - $125,000-$165,000 - Employer sponsored health, dental, vision, life, and disability insurance - Retirement plan with company contribution - Annual company profit sharing - Personal development/training budget - Open, collaborative work environment - Extensive 2-week onboarding plan - Comprehensive mentorship program Equal Opportunity Employer Statement & Applicant Rights TherapyNotes LLC is an Equal Opportunity Employer and does not discriminate based on race, color, religion, sex, national origin, age, disability, genetic information, or any other protected status under federal, state, or local law. We are committed to providing a workplace free of discrimination and harassment.For more information about your rights under federal employment laws, please review the following: - Know Your Rights: Workplace Discrimination is Illegal - Family and Medical Leave Act (FMLA): Employee Rights Under FMLA If you require a reasonable accommodation during the application process, please contact humanresources@therapynotes.com. #LI-Remote 3/5/2026

Related Categories

Related Job Pages

More Compliance Jobs

Full TimeRemoteTeam 201-500

TDXi, LLC, a subsidiary of Tanadgusix Corporation (TDX), an Alaska Native Corporation, is currently recruiting for the position of Quality/Safety Manager. This position is located in Newport News, VA and is a Full Time, exempt position and will report to the President, TDX Government Services. An outstanding opportunity with an established defense contractor that is looking for motivated and results oriented individuals to grow with the company! TDX Government Services (TGS) is an innovative force performing a variety of industry leading services for our military and associated defense contractors. We currently provide specialized technical expertise to fulfill Range Management responsibilities and enhance Combat Training Support services across the globe. TGS enjoys a proud history delivering high quality, customer focused, and cost-conscious operations, maintenance, engineering, and mission support to the world’s finest warfighters enhancing our national defense. For more information, visit our website at: https://tdxservices.tdxcorp.net/ JOB SUMMARY: Support Lead Quality/Safety Manager to implement program specific quality control and safety plans within overarching programs to ensure services are performed in accordance with commonly accepted commercial practices, manufacturer recommendations, contract specifications and all federal, state, and local laws and regulations, as well as respond to customer feedback. Inspect all phases of operations and maintenance for conformity to established quality, health and safety, and other operational standards. The ideal candidate will have a United States Air Force maintenance background with Quality Assurance/Inspector General experience in addition to time spent in a dedicated safety billet and/or safety training. Position could be eligible for remote work for the right candidate. ESSENTIAL DUTIES AND RESPONSIBILITIES: Responsibilities of this position include, but are not limited to: - Perform on-going work review to ensure all services listed in contract Performance Work Statement Service Summary are performed in a satisfactory manner. - Implement proactive procedures (scheduled and unscheduled) to identify, prevent, correct, and ensure non-recurrence of defective services. - Maintain Quality Control files and document results of all inspections. - Identify trends with equipment reliability, Product Quality Deficiency Reports, and repeated deficiencies found during inspections, and ensure accuracy, thoroughness, and timeliness of all required reports. MINIMUM REQUIREMENTS: - Requires successful completion of an accredited Associate Degree and/or Technical Apprentice Program in Electronics, or equivalent - A minimum of ten (10) years’ experience at the journeyman level, with three (3) years’ experience at the Craftsman level - Applicants must be able to exercise independent judgment, demonstrate knowledge of quality management principles, understand processes and interrelationships, interpret and verify system/equipment physical condition and functional performance indicators, assess procedural compliance, compile and analyze trends, as well as track and resolve corrective and preventive action - Applicants must be able to demonstrate aptitude using internet-based technology and information management systems, as well as industry standard, full-featured office-related applications, such as word processing programs to create and edit documents, spreadsheet programs to perform data calculation and analytical functions, presentation programs for graphically supported visual aids, and email and scheduling - Implement specific quality control and safety plans within overarching programs to ensure services are performed in accordance with commonly accepted commercial practices, manufacturer recommendations, contract specifications and all federal, state, and local laws and regulations - Inspect all phases of operations and maintenance for conformity to established quality, health and safety, and other operational standards Additional Requirements - US Citizen // Secret Clearance (or ability to obtain) is required to start - Applicants must have a valid state driver’s license - Ability to travel up to 40% of the time COMPETENCIES: To perform the job successfully, an individual should demonstrate the following competencies to perform the essential functions of this position. - Ability to speak, read, and write English To Apply: Visit our Website at the following link to apply online and upload your resume: http://bsetak.com/employment.html You may email any questions to tsd-hiring@bseak.com, call us at 757-223-1446, or fax our hiring team at (757)-223-4141. Please indicate the position you are applying for and location on any correspondence. TDX offers a full range of benefits including health, dental, vision and 401K to full-time employees. Details will be made available during the hiring process as appropriate. Note: This job description in no way states or implies that these are the only duties to be performed by this employee. This employee will be required to follow any other instructions and to perform any other duties requested by their supervisor. The statements herein intend to describe the general nature and level of work being performed by the employee in this position. These statements are not to be construed as an exhaustive list of responsibilities, duties, and skills required of a person in this position. Furthermore, these statements do not establish a contract for employment and are subject to change at the discretion of Tanadgusix Corporation (TDX) and its subsidiaries. BSEt, LLC is an Equal Employment Opportunity Employer with an Alaska Native Hiring Preference (PL93-638). We do not discriminate based on marital status, sex, race, color, religion, national origin, age, disability, or veteran status. Prior to employment, successful completion of a background investigation may be required. Accommodation Request If you are a job seeker with a disability and require accessibility assistance or an accommodation to apply for one of our jobs, please submit a request by telephone or via email. In order to appropriately assist you with an accommodation, we ask that you please specify the assistance needed in order to access our jobsite and post for a position. The dedicated email and telephonic options are listed below and are reserved only for individuals with disabilities needing accessibility assistance. To request an accommodation, contact an HR representative at (907) 278-2312 or at HR@TDXCorp.com. Location Newport News, Virginia Department TDX International, LLC Employment Type Full-Time Regular Minimum Experience Experienced Compensation market

United States
Job Closed
Coinbase logo

Regulatory Policy, Senior Associate

Coinbase

We're building an open financial system for the world.

Compliance75 days ago
Full TimeRemoteTeam 1,001-5,000Since 2012H1B Sponsor

Ready to be pushed beyond what you think you’re capable of? At Coinbase, our mission is to increase economic freedom in the world. It’s a massive, ambitious opportunity that demands the best of us, every day, as we build the emerging onchain platform — and with it, the future global financial system. To achieve our mission, we’re seeking a very specific candidate. We want someone who is passionate about our mission and who believes in the power of crypto and blockchain technology to update the financial system. We want someone who is eager to leave their mark on the world, who relishes the pressure and privilege of working with high caliber colleagues, and who actively seeks feedback to keep leveling up. We want someone who will run towards, not away from, solving the company’s hardest problems. Our work culture is intense and isn’t for everyone. But if you want to build the future alongside others who excel in their disciplines and expect the same from you, there’s no better place to be. While many roles at Coinbase are remote-first, we are not remote-only. In-person participation is required throughout the year. Team and company-wide offsites are held multiple times annually to foster collaboration, connection, and alignment. Attendance is expected and fully supported. As a Regulatory Policy, Senior Associate, you will work in a fast-paced environment supporting a wide variety of regulatory advocacy and the development of new policy positions by drafting written materials, such as consultation responses and presentations for external engagements. A successful candidate will have (1) excellent communication and writing skills, (2) previous experience with the public consultation or regulatory rulemaking process, and (3) familiarity with digital asset regulation or policy. Relevant knowledge areas include U.S. and global markets regulations, prudential regulation, and payments regulations. What you will be doing (i.e. job duties): - Work with cross functional product/legal/policy teams to establish internal policy views on emergent regulatory issues. - Draft superbly written materials in support of regulatory consultations and engagements. - Brief executive level audiences on the potential impact of new/proposed rules on products and practices. - Work with trade groups to establish consensus industry positions on alternative regulatory approaches. - Organize and lead external engagements with regulators and standard setters. What we look for in you (ie. job requirements): - Bachelor’s or non-US equivalent (required) + advanced degree in finance, economics, or law (preferred). - Minimum of 6 + years of financial services regulatory experience, ideally focused on CFTC, SEC and/or prudential regulation. - Understanding of blockchain-based technology, products, and services. - Demonstrated ability to manage cross-functional teams of subject matter experts. - You must be an exceptional communicator. You will be expected to produce original written work for both internal and external consumption. - Superb attention to detail. - Demonstrates the ability to responsibly use generative AI tools and copilots (e.g., LibreChat, Gemini, Glean) in daily workflows, continuously learn as tools evolve, and apply human‑in‑the‑loop practices to deliver business‑ready outputs and drive measurable improvements in efficiency, cost, and quality. Nice to haves: - Management consulting experience. - Experience working at a multi-client law firm. - Experience responding to regulatory consultations, or equivalent experience from the government side. - Experience with a government agency/authority. #LI-Remote P76484 Pay Transparency Notice: Depending on your work location, the target annual base salary for this position can range as detailed below. Total compensation may also include equity and bonus eligibility and benefits (including medical, dental, vision and 401(k)). Annual base salary range (excluding equity and bonus): $130,900—$154,000 USD Please be advised that each candidate may submit a maximum of four applications within any 30-day period. We encourage you to carefully evaluate how your skills and interests align with Coinbase's roles before applying. Commitment to Equal OpportunityCoinbase is proud to be an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, sex, gender expression or identity, sexual orientation or any other basis protected by applicable law. Coinbase will also consider for employment qualified applicants with criminal histories in a manner consistent with applicable federal, state and local law. For US applicants, you may view the Employee Rights and the Know Your Rights notices by clicking on their corresponding links. Additionally, Coinbase participates in the E-Verify program in certain locations, as required by law. Coinbase is also committed to providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation because of a disability for any part of the employment process, please contact us at accommodations[at]coinbase.com to let us know the nature of your request and your contact information. For quick access to screen reading technology compatible with this site click here to download a free compatible screen reader (free step by step tutorial can be found here). Global Data Privacy Notice for Job Candidates and ApplicantsDepending on your location, the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA) may regulate the way we manage the data of job applicants. Our full notice outlining how data will be processed as part of the application procedure for applicable locations is available here. By submitting your application, you are agreeing to our use and processing of your data as required. For US applicants only, by submitting your application you are agreeing to arbitration of disputes as outlined here. AI DisclosureFor select roles, Coinbase is piloting an AI tool based on machine learning technologies to conduct initial screening interviews to qualified applicants. The tool simulates realistic interview scenarios and engages in dynamic conversation. A human recruiter will review your interview responses, provided in the form of a voice recording and/or transcript, to assess them against the qualifications and characteristics outlined in the job description. For select roles, Coinbase is also piloting an AI interview intelligence platform to transcribe and summarize interview notes, allowing our interviewers to fully focus on you as the candidate. The above pilots are for testing purposes and Coinbase will not use AI to make decisions impacting employment. To request a reasonable accommodation due to disability, please contact accommodations[at]coinbase.com

United States
$130.9K - $154K / year
Job Closed
Full TimeRemoteTeam 1,001-5,000Since 1947H1B Sponsor

Role Description NV5 is seeking a CSST/CAC-Certified Industrial Hygiene Technician to join our Building Sciences Team. As an integral member of the team, you will contribute to a variety of projects focused on hazardous materials in the built environment, including lead, asbestos, and mold. Working under the guidance of a Senior Consultant, you will be responsible for: - Conducting comprehensive building-related hazardous materials surveys. - Developing scopes of work. - Overseeing remediation activities. - Providing technical assistance to clients. Qualifications - AA or BA/BS degree in environmental science, construction management, engineering, or industrial hygiene, with at least six months of relevant experience. - Current certification as a CSST (Certified Site Surveillance Technician) by Cal/OSHA or CAC (California Asbestos Consultants). - Strong working knowledge of identifying, controlling/abating, and overseeing the remediation of building-related hazardous materials. - Proficiency in building construction practices and familiarity with Cal/OSHA requirements. - Additional certifications such as NIOSH 582 (or equivalent), CDPH Inspector Assessor, and OSHA 40-hour HAZWOPER are highly desirable. Requirements - Conduct independent building inspections for hazardous materials such as asbestos, lead, and other building-related substances in various job-site settings. - Perform air monitoring and inspections during asbestos, lead, and other hazardous materials remediation processes. - Develop and implement sampling plans for hazardous materials. - Analyze and interpret hazardous materials sampling data. - Prepare and deliver reports on hazardous materials findings and recommendations. - Provide technical assistance to clients on hazardous materials issues. - Stay up-to-date on the latest hazardous materials regulations and best practices. Benefits - Competitive compensation package including medical, dental, and life insurance. - PTO. - 401(k). - Professional development/advancement opportunities. - Restricted stock units may be provided as part of the compensation package.

United States
$30 - $40 / hour
Job Closed
Highmark Health logo

Associate IT Audit Analyst

Highmark Health

Creating remarkable health experiences, freeing people to be their best.

Compliance75 days ago
Full TimeRemoteTeam 10,001+Since 1852H1B Sponsor

Company : Highmark HealthJob Description : JOB SUMMARY This job is actively involved in the execution of audit activities related to information technology security, system implementations, and data privacy to determine whether Highmark Health and its subsidiaries' network of risk management, control, and governance processes, as designed and operated by management, are adequate and functioning. Assesses whether the processes and controls provide reasonable assurance that information technology and security risks are identified and managed, and that significant financial, operational, and protected information is secure, accurate, reliable, and processed timely. Determine and assist with the development of recommendations to improve the implementation of business process and systems changes and project management controls. Execute the IT Assurance and Advisory programs aligned with the overall Internal Audit strategy. Comply with the Health Insurance Portability Accountability Act of 1996 (HIPAA) as it pertains to disclosures of protected health information (PHI) as described in the Notice of Privacy Practices and Privacy Policies and Procedures. As a component of job roles and responsibilities, employees in this role may have access to covered information, cardholder data, or other confidential customer information which must be protected at all times. In connection with this responsibility, employees in this role must adhere to all data security guidelines established within the Company’s Handbook of Privacy Policies and Practices and Information Security Policy. ESSENTIAL RESPONSIBILITIES - Assist with identifying and assessing the organization’s key information technology, security, and data privacy risk areas. - Plan and executes information technology, security, system implementation, and data privacy audit activities across Highmark Health enterprise while maintaining independence and adhering to professional industry standards. - Produce high-quality audit work papers, ensuring satisfactory documentation of results. - Effectively communicate with customers, supervisors, and subject matter experts to deliver on requests and tasks in a timely manner, and to ensure clarity on project status, deadlines, and deliverables throughout the project lifecycle. - Assist with the process to close-out and finalize audits / projects, including the identification and assessment of issues, development of audit reports, and review of supporting documentation and workpapers in accordance with Departmental standards - Contribute with maintaining a positive working environment through the building of solid relationships with team members. - Coordinate with independent auditors in executing audit procedures for the organization, where necessary. - Other duties as assigned or requested. ​ EDUCATION Minimum - Bachelor’s degree in accounting, Finance, Business Administration, Information Technology, Computer Science or Related Field or relevant experience and/or education as determined by the company in lieu of bachelor's degree. Preferred - None EXPERIENCE Required - Experience with Information Systems auditing OR - Experience in audit and an Information Systems related discipline, such as Information Security, Change Management, Systems Development, etc. Preferred - Familiarity with a wide variety of computer application platforms, including but not limited to: Oracle, SQL Server, DB2, RACF, Linux, and Windows. - Cybersecurity/ IT risk assurance expertise - Experience with Archer Governance, Risk, and Compliance (GRC) suite of products LICENSES OR CERTIFICATIONS Required - None Preferred - Certified Information System Auditor (CISA) - Certified Internal Auditor (CIA) - Certified Public Accountant (CPA) SKILLS - Knowledge of internal audit functions, particularly as applied to information technology and data security - Ability to apply auditing (GAAS), accounting (GAAP) and/or IS industry standards to the evaluation of systems environments and processes (i.e., data center operations, information security, input, output and processing controls, back-up and recovery, business contingency planning, systems development, and the implementation of advanced technologies) - Effective resource and project planning, decision making, results delivery, team building, and staying current with relevant technology and innovation - Oral and written communication skills when interfacing and collaborating with clients, peers, and management to develop solutions, emphasizing a client-based focus to understand and respond appropriately to business requirements - Strong relationship building skills - Self-starter with the ability to work under pressure independently and as part of a team - Ability to think strategically and act proactively to create strong trust and confidence with business units - Ability to interact, build credibility and long-term relationships with senior management to understand the company’s culture, strategic direction, and goals. - Ability to manage multiple projects, meet deadlines while ensuring quality and exceeding client expectations. Language (Other than English): None TRAVEL REQUIREMENTS 0%-25% PHYSICAL, MENTAL DEMANDS AND WORKING CONDITIONS Position Type Office Based Teaches / trains others regularly Frequently Travel regularly from the office to various work sites or from site-to-site Rarely Works primarily out-of-the office selling products/services (sales employees) Never Physical work site required No Lifting: up to 10 pounds Constantly Lifting: 10 to 25 pounds Occasionally Lifting: 25 to 50 pounds Does Not Apply Disclaimer: The job description has been designed to indicate the general nature and essential duties and responsibilities of work performed by employees within this job title. It may not contain a comprehensive inventory of all duties, responsibilities, and qualifications required of employees to do this job. Compliance Requirement: This job adheres to the ethical and legal standards and behavioral expectations as set forth in the code of business conduct and company policies. As a component of job responsibilities, employees may have access to covered information, cardholder data, or other confidential customer information that must be protected at all times. In connection with this, all employees must comply with both the Health Insurance Portability Accountability Act of 1996 (HIPAA) as described in the Notice of Privacy Practices and Privacy Policies and Procedures as well as all data security guidelines established within the Company’s Handbook of Privacy Policies and Practices and Information Security Policy. Furthermore, it is every employee’s responsibility to comply with the company’s Code of Business Conduct. This includes but is not limited to adherence to applicable federal and state laws, rules, and regulations as well as company policies and training requirements. Pay Range Minimum: $58,100.00 Pay Range Maximum: $90,000.00 Base pay is determined by a variety of factors including a candidate’s qualifications, experience, and expected contributions, as well as internal peer equity, market, and business considerations. The displayed salary range does not reflect any geographic differential Highmark may apply for certain locations based upon comparative markets. Highmark Health and its affiliates prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities and prohibit discrimination against all individuals based on any category protected by applicable federal, state, or local law. We endeavor to make this site accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact the email below. For accommodation requests, please contact HR Services Online at HRServices@highmarkhealth.org California Consumer Privacy Act Employees, Contractors, and Applicants Notice

United States
$58.1K - $90K / year