Job Closed

This listing is no longer active.

TherapyNotes, LLC logo
TherapyNotes, LLC

TherapyNotes™ is the industry-preferred online EHR for behavioral health. Try one month free!

Lead GRC Analyst

ComplianceComplianceOtherRemoteSeniorTeam 51-200Since 2010H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

94 days ago

Salary

$125K - $165K / year

Seniority

Senior

Bachelor Degree5 yrs expEnglish

Job Description

Lead GRC Analyst

TherapyNotes, LLC

• Architect, implement, and continuously mature the organization’s Governance, Risk, and Compliance (GRC) program • Lead organization-wide risk identification, analysis, and treatment processes • Lead end-to-end third-party risk management activities • Conduct formal risk assessments across infrastructure, application, vendor, and business process domains • Collaborate with cross-functional teams to integrate GRC principles into business processes and systems • Monitor evolving regulatory requirements, enforcement trends, and industry best practices • Provide guidance and training to employees on GRC policies, procedures, and best practices • Oversee the execution of audits, assessments, and compliance activities • Ensure documentation artifacts support evidentiary requirements for regulatory examinations and certification audits • Act as a liaison with external auditors, regulators, and stakeholders on GRC-related matters • Develop and maintain key performance indicators (KPIs) and metrics to measure the effectiveness of GRC initiatives • Mentor and coach GRC analysts, fostering their professional development and growth within the organization • Drive continual improvement of the organization’s information security program • Identify and document cyber risks and manage mitigation • Assist with ad-hoc compliance reporting • Provide support to Information Security Incident Response team • Review architectural designs and new technology initiatives

Job Requirements

  • BS degree in Information Security, Risk Management, Business Administration, or related field
  • 5+ years of experience in GRC, risk management, or related fields, with demonstrated leadership experience
  • Certified Information Systems Security Professional (CISSP), Certified Information Security Auditor (CISA), Certified Information Security Manager (CISM) or Certified in Risk and Information Systems Control (CRISC) strongly preferred
  • Strong knowledge of regulatory requirements (e.g., GDPR, HIPAA, PCI-DSS, CPRA) and industry standards (e.g., ISO 27001, NIST).
  • Expert in designing, implementing, and maintaining security solutions
  • Understanding of modern approaches to GRC such as Policy-as-Code and Compliance-as-Code
  • Experience developing and implementing GRC frameworks, policies, and procedures
  • Excellent analytical skills with the ability to assess complex risks and develop effective mitigation strategies
  • Exceptional communication and interpersonal skills, with the ability to effectively collaborate with stakeholders at all levels of the organization
  • Proven ability to lead and manage projects, including coordinating cross-functional teams and delivering results on time
  • Ability to adapt to a fast-paced and dynamic environment, with a focus on continuous improvement and innovation
  • Proficiency with security standards and secure configuration baselines such as CIS or OWASP
  • Proficiency with cloud-based solutions and web related technologies.

Benefits

  • Employer sponsored health, dental, vision, life, and disability insurance
  • Retirement plan with company contribution
  • Annual company profit sharing
  • Personal development/training budget
  • Open, collaborative work environment
  • Extensive 2-week onboarding plan
  • Comprehensive mentorship program

Related Categories

Related Job Pages

More Compliance Jobs

BlueCross BlueShield of South Carolina logo

Government Audit Supervisor

BlueCross BlueShield of South Carolina

South Carolina’s largest and oldest health insurance company

Compliance94 days ago
OtherRemoteTeam 10,001+Since 1946H1B No Sponsor

Summary Responsible for supervising the receipt, review, and settlement of the Medicare cost report, ensuring all Centers for Medicare and Medicaid Services (CMS) requirements are met throughout the process. Description This position is a full-time remote position working Monday-Friday with typical work hours of 8:00 to 5:00. What You'll Do: - Performs supervisory review of all audit work papers completed by the team to ensure all work conforms to CMS and other government auditing standards. - Performs supervisory review of all cost report acceptances and desk reviews to ensure timeliness requirements are met and all CMS standards are adhered to. - Plans, monitors, and budgets all work assigned for the team, and evaluates and reports results. - Performs supervisory review of all settlement packages ensuring product meets all CMS standards. - Assists in developing the audit staff by providing on-the-job training as well as preparing and presenting formal staff training sessions. - Researches issues and responds to provider and CMS requests in a timely manner. Required Education: Bachelor's in a job related field. Required Work Experience: 5 years auditing or accounting experience including 1 year in a leadership role or equivalent military experience in grade E4 or above. Required Skills and Abilities: - Knowledge of cost accounting standards and Generally Accepted Accounting Principles. - Knowledge and use of auditing standards and statistical sampling techniques. Good planning, organization, and human relations skills. - Knowledge of the principles and practices of auditing. - Ability to analyze and determine the applicability of financial data. - Ability to gather information by examining records and documents and to interview individuals. - Strong interpersonal skills. - Ability to work professionally with persons at all levels. - Ability to maintain effective working relationships. - Ability to communicate clearly and effectively in oral and written form. - Ability to handle sensitive matters on a confidential basis. - Ability to make presentations and apply critical thinking skills. - Knowledge of provider reimbursement review board. - Ability to interpret and implement changes to Medicare program. - Thorough understanding of Uniform Contractor Evaluation Program guidelines. - Ability to adapt to changing environment. - Strong planning skills with the ability to makes sound decisions. Required Software and Tools: Microsoft Office. Preferred Education: Bachelor's degree- any major Preferred Licenses and Certificates: Certified Public Accountant (CPA) or Certified Internal Auditor (CIA) or Certified Management Accountant (CMA) Work Environment: Typical office environment. Some travel between office buildings. Some out of town travel. Our Comprehensive Benefits Package Includes The Following: We offer our employees great benefits and rewards. You will be eligible to participate in the benefits at the first of the month following 28 days of employment: - Subsidized health plans, dental and vision coverage - 401k retirement savings plan with company match - Life Insurance - Paid Time Off (PTO) - On-site cafeterias and fitness centers in major locations - Education Assistance - Service Recognition - National discounts to movies, theaters, zoos, theme parks and more What We Can Do for You: We understand the value of a diverse and inclusive workplace and strive to be an employer where employees across all spectrums have the opportunity to develop their skills, advance their careers and contribute their unique abilities to the growth of our company. What To Expect Next: After submitting your application, our recruiting team members will review your resume to ensure you meet the qualifications. This may include a brief telephone interview or email communication with our recruiter to verify resume specifics and salary requirements. Salary Range: Range Minimum $65,485.00 Range Midpoint $98,081.00 Range Maximum $130,677.00 Equal Employment Opportunity Statement BlueCross BlueShield of South Carolina and our subsidiary companies maintain a continuing policy of nondiscrimination in employment to promote employment opportunities for persons regardless of age, race, color, national origin, sex, religion, veteran status, disability, weight, sexual orientation, gender identity, genetic information or any other legally protected status. Additionally, as a federal contractor, the company maintains affirmative action programs to promote employment opportunities for individuals with disabilities and protected veterans. It is our policy to provide equal opportunities in all phases of the employment process and to comply with applicable federal, state and local laws and regulations. We are committed to working with and providing reasonable accommodations to individuals with disabilities, pregnant individuals, individuals with pregnancy-related conditions, and individuals needing accommodations for sincerely held religious beliefs, provided that those accommodations do not impose an undue hardship on the Company. If you need special assistance or an accommodation while seeking employment, please email mycareer.help@bcbssc.com or call 800-288-2227, ext. 47480 with the nature of your request. We will make a determination regarding your request for reasonable accommodation on a case-by-case basis. We participate in E-Verify and comply with the Pay Transparency Nondiscrimination Provision. We are an Equal Opportunity Employer. Here's more information. Some states have required notifications. Here's more information. Equal Employment Opportunity Statement BlueCross BlueShield of South Carolina and our subsidiary companies maintain a continuing policy of nondiscrimination in employment to promote employment opportunities for persons regardless of age, race, color, national origin, sex, religion, veteran status, disability, weight, sexual orientation, gender identity, genetic information or any other legally protected status. Additionally, as a federal contractor, the company maintains affirmative action programs to promote employment opportunities for individuals with disabilities and protected veterans. It is our policy to provide equal opportunities in all phases of the employment process and to comply with applicable federal, state and local laws and regulations. We are committed to working with and providing reasonable accommodations to individuals with disabilities, pregnant individuals, individuals with pregnancy-related conditions, and individuals needing accommodations for sincerely held religious beliefs, provided that those accommodations do not impose an undue hardship on the Company. If you need special assistance or an accommodation while seeking employment, please email mycareer.help@bcbssc.com or call 800-288-2227, ext. 47480 with the nature of your request. We will make a determination regarding your request for reasonable accommodation on a case-by-case basis. We participate in E-Verify and comply with the Pay Transparency Nondiscrimination Provision. We are an Equal Opportunity Employer. Here's more information. Some states have required notifications. Here's more information.

United States
$65.5K - $130K / year
Job Closed
Target Specialty Products logo

Regulatory Document Control Coordinator

Target Specialty Products

Target Specialty Products is a leading provider of Pest Management & Turf & Ornamental equipment and supplies.

Compliance94 days ago
OtherRemoteTeam 201-500H1B No Sponsor

• Systematically organize product labels and SDS documents for Federal, State, and County compliance • Track document revisions, ensuring the latest version is accessible • Maintain open communication with vendors and manufacturers for requests of documents, ensuring timely delivery • Communicate the need for updated vendor and/or manufacturer contact information (Procurement Manager or Buyer) • Distribution of label and SDS documents (Web Administrator, Sales, Service Center Manager, or customers) • Link documents into the NAV system • Create an electronic document system based on service location product inventory, including user access control and document workflows • Archive inactive documents as needed electronically • Monitor compliance with document control procedures and regulatory requirements • Provide administrative and day-to-day support

Tennessee
$22 - $32 / hour
Job Closed
Deciphex logo

Regulatory Affairs Specialist

Deciphex

Transforming Pathology using Tailored Workflows and Artificial Intelligence

Compliance94 days ago
Full TimeRemoteTeam 51-200H1B No Sponsor

• This is a remote role with some travel required to global offices. • Actively involved with the Laboratory Operations team, QA/RA team, Commercial, legal and R&D teams to generate regulatory plans and strategies for digital pathology products and services. • Maintain and implement the compliance plans to ensure continued compliance for our services and products in North America. • Make submissions for regulatory and accreditation applications for new products/services to project timelines to the applicable regulatory bodies. • Develop, compile and review the technical documentation required for regulatory submissions: USA, Canada. • Support Regulatory Affairs team with UK, EU, Rest of World submissions as needed. • Lead communications and engagement with Notified Bodies, Competent Authorities, and international regulatory authorities. • Coordinate post market surveillance (PMS) activities for products and services. • Write and submit periodic regulatory reports to authorities as required. • Establish, manage and monitor the global regulatory requirements database, keeping the product portfolio in compliance with global regulations. • Keep up to date on changing regulatory requirements and standards including FDA/LDT rule changes, emerging AI regulations, privacy/security regulations etc. • Conduct regulatory gap analyses and impact analysis. • Develop internal and global policies & procedures to ensure continuous compliance with all regulatory requirements. • Assist in maintaining the Regulatory Affairs Intranet site. • Collect and report on compliance metrics as directed by the Regulatory Affairs Manager. • Support other members of the Quality team to incorporate regulatory requirements into the Integrated Management System (IMS). • Review of Change Requests for product & service changes which may impact regulatory and customer filings. • Support employees with regulatory queries, customer audits, regulatory audits and inspections as required. • Perform internal & supplier audits as required. • Develop and deliver company training modules on regulatory processes. • Complete all mandatory company training and job specific training required for the role, including Information Security Management System (ISMS), GLP, DocuSign, SDLC as applicable.

United States
GoDaddy logo

Principal Compliance Engineer-PKI

GoDaddy

GoDaddy is a web services platform that helps individuals and businesses worldwide start, grow, and manage their online presence. GoDaddy employs team members across North America,

Compliance94 days ago

Location Details: United States, Remote At GoDaddy the future of work looks different for each team. Some teams work in the office full-time; others have a hybrid arrangement (they work remotely some days and in the office some days) and some work entirely remotely. This is a remote position, so you’ll be working remotely from your home. You may occasionally visit a GoDaddy office to meet with your team for events or meetings. This position is not eligible to be performed in Alaska, Mississippi, North Dakota, or the Virgin Islands. Join our team At GoDaddy, we are seeking an exceptional Principal Compliance Engineer - PKI with deep technical expertise to define requirements and guide the evolution of our Certificate Authority (CA) platform. Reporting to GoDaddy's Vice President Engineering Partners, you will translate industry standards into technical requirements, define specifications for compliance automation, and provide technical guidance for next-generation cryptographic systems. This role combines technical leadership with strategic requirements development, focusing on post-quantum cryptography readiness, certificate lifecycle automation, and CA infrastructure resilience. What you'll get to do... Technical Standards & Requirements Leadership - Lead technical representation in the CA/Browser Forum and other industry standards bodies, contributing to protocol specifications and requirements development - Translate CAB Forum requirements into detailed technical specifications and engineering requirements for development teams - Define requirements for automated compliance validation systems and monitoring infrastructure CA Infrastructure & Systems Requirements - Conduct deep-dive technical assessments of CA infrastructure, identifying architectural gaps, security vulnerabilities, and performance bottlenecks - Define technical requirements for the evolution of certificate issuance pipelines, HSM integrations, and cryptographic key management systems - Specify requirements for automated testing frameworks for compliance validation, including CT log integration, OCSP responder infrastructure, and revocation mechanisms - Develop automation scripts for compliance testing and validation processes - Define SLIs/SLOs focused on certificate issuance latency, system availability, and compliance metrics - Document requirements for infrastructure-as-code solutions for CA deployment, disaster recovery, and high-availability architectures Cryptographic Systems & Innovation - Research and define requirements for post-quantum cryptographic algorithms (e.g., ML-KEM, ML-DSA, SLH-DSA) and hybrid certificate chains - Develop migration strategies and technical requirements for transitioning legacy cryptographic systems to next-generation algorithms - Create technical specifications for proof-of-concept implementations for emerging standards (ACME extensions, certificate transparency v2, delegated credentials) - Collaborate with cryptography researchers to evaluate algorithm performance, key sizes, and implementation trade-offs Platform Requirements & Automation - Define the technical requirements roadmap for CA platform capabilities including certificate lifecycle automation, API development, and integration frameworks - Specify requirements for scalable APIs and automation tools for certificate issuance, renewal, and revocation workflows - Document specifications for self-service platforms and tools to reduce manual intervention in certificate operations - Develop automated testing scripts and define requirements for continuous compliance monitoring systems with automated remediation capabilities Technical Collaboration & Documentation - Partner with security engineering teams on threat modeling, secure coding practices, and vulnerability management - Lead architecture reviews and technical design sessions with cross-functional engineering teams, providing requirements and guidance - Establish technical documentation standards and compliance engineering requirements for CA-related systems - Mentor engineers on PKI concepts, cryptographic implementations, and compliance engineering patterns Your experience should include... - 8+ years of hands-on engineering experience in PKI systems, applied cryptography, or security infrastructure with proven technical leadership and strong technical background in languages such as Go, Python, Java, or C++ - Deep expertise in PKI architecture including X.509 certificate structures, ASN.1 encoding, certificate chain validation, HSM operations, and cryptographic primitives - Proven experience translating CA/Browser Forum Baseline Requirements into technical specifications, including controls for key generation, certificate issuance, and audit logging - Systems engineering background with experience in distributed systems, API design, database architecture, and cloud infrastructure (AWS/GCP/Azure) - Strong ability to define requirements for PKI protocols (ACME, Certificate Transparency, OCSP/CRL) and translate compliance requirements into technical specifications, detailed engineering requirements, and test automation scripts You might also have... - - Advanced degree in Computer Science, Cryptography, Mathematics, or Electrical Engineering - Experience researching and evaluating post-quantum cryptographic algorithms (NIST PQC finalists, hybrid modes) - Security certifications such as CISSP, CEH, or specialized cryptography credentials - Experience with security audit processes (WebTrust for CAs, ETSI EN 319 411) from a technical implementation perspective - Contributions to PKI-related projects (Boulder, cert-manager, OpenSSL, BoringSSL, etc.) - Experience defining requirements for high-availability systems design, hardware security modules (HSMs), and secure key ceremony procedures - Knowledge of DevSecOps practices, CI/CD pipelines for security-critical systems, and infrastructure automation (Terraform, Kubernetes, Ansible) - Familiarity with cryptographic libraries (OpenSSL, BoringSSL, PKCS#11) and performance considerations for cryptographic operations - Experience developing test automation scripts for compliance validation We've got your back...  We offer a range of total rewards that may include paid time off, retirement savings (e.g., 401k, pension schemes), bonus/incentive eligibility, equity grants, participation in our employee stock purchase plan, competitive health benefits, and other family-friendly benefits including parental leave. GoDaddy’s benefits vary based on individual role and location and can be reviewed in more detail during the interview process. We also embrace our diverse culture and offer a range of Employee Resource Groups (Culture). Have a side hustle? No problem. We love entrepreneurs! Most importantly, come as you are and make your own way. About us... GoDaddy is empowering everyday entrepreneurs around the world by providing the help and tools to succeed online, making opportunity more inclusive for all. GoDaddy is the place people come to name their idea, build a professional website, attract customers, sell their products and services, and manage their work. Our mission is to give our customers the tools, insights, and people to transform their ideas and personal initiative into success. To learn more about the company, visit About Us. At GoDaddy, we know diverse teams build better products—period. Our people and culture reflect and celebrate that sense of diversity and inclusion in ideas, experiences and perspectives. But we also know that’s not enough to build true equity and belonging in our communities. That’s why we prioritize integrating diversity, equity, inclusion and belonging principles into the core of how we work every day—focusing not only on our employee experience, but also our customer experience and operations. It’s the best way to serve our mission of empowering entrepreneurs everywhere, and making opportunity more inclusive for all. To read more about these commitments, as well as our representation and pay equity data, check out our Diversity and Pay Parity annual report which can be found on our Diversity Careers page. GoDaddy is proud to be an equal opportunity employer. GoDaddy will consider for employment qualified applicants with criminal histories in a manner consistent with local and federal requirements. Refer to our full EEO policy. Our recruiting team is available to assist you in completing your application. If they could be helpful, please reach out to myrecruiter@godaddy.com. Colorado Residents: In any materials you submit, you may redact or remove age-identifying information such as age, date of birth, or dates of school attendance or graduation. You will not be penalized for redacting or removing this information. GoDaddy doesn’t accept unsolicited resumes from recruiters or employment agencies.

United States
Job Closed