Bamboo Health is a healthcare technology solutions company that fosters care collaboration and provides actionable insights and information across the entire ca
Senior GRC Analyst
Location
United States
Posted
17 days ago
Salary
0
Seniority
Senior
Job Description
Senior GRC Analyst
Bamboo Health
• Evaluate organizational policies and standards, ensuring that external and internal compliance requirements are met. • Develop improvements to the compliance program, including the use of AI, automation, and process optimization. • Review security-relevant language in customer contracts (MSAs, DPAs, BAAs) and RFP/RFI security sections, providing recommendations to Legal and the broader GRC team. • Respond to customer security questionnaires using AI-assisted tools and trust content, exercising professional judgment to ensure responses are accurate and complete. • Work with external auditors and customers as necessary, providing them with required information and assistance. • Maintain and update trust center content and customer-facing security documentation. • Perform vendor security risk assessments and contribute to the third-party risk management program. • Assist in policy documentation upkeep and development, ensuring clarity and applicability. • Monitor and assist with the internal training programs on compliance requirements and best practices. • Ensure Bamboo Health’s security operations remain aligned with both internal and external compliance requirements, contributing to ongoing internal and external audit reviews. • Effectively communicate Bamboo Health’s compliance posture to both internal and external stakeholders, offering tangible proof of adherence to policy requirements. • Partner with the larger Information Security team to identify areas for continuous improvement within the compliance framework. • Stay curious about emerging AI tools and how they can streamline or enhance work within your function.
Job Requirements
- Bachelor’s degree in information security, computer science, or related field, or equivalent experience in a related field.
- Security compliance-related certifications such as CISSP, CISA, or CRISC are preferred.
- 5+ years of experience in information security, with substantial focus on compliance, audit, or risk management work.
- Direct experience with security frameworks and certifications like NIST SP 800-53, HITRUST, HIPAA, and/or FedRAMP.
- Experience responding to customer security questionnaires and supporting customer security due diligence activities.
- Experience reviewing security-relevant language in customer or vendor contracts.
- Familiarity with healthcare data protection requirements (HIPAA) and the compliance obligations they create.
- Demonstrated experience with security auditing and evidence gathering for compliance purposes.
- Experience evaluating security controls for compliance purposes.
- Familiarity with cloud security concepts and practices.
- Excellent written and verbal communication skills, with ability to build and communicate business rationale.
- Strong ability to learn quickly and work independently while being part of a team.
- Ability to build effective, sustainable working relationships internally, with customers, and external stakeholders.
- Comfort using or learning AI-supported tools (e.g., ChatGPT, CoPilot, or role-specific tools) to improve daily workflows.
- A forward-thinking, curious mindset with an openness to experimenting with new technologies.
- Strong analytical and problem-solving skills, with sound judgment and creativity in designing solutions.
- Proven ability to thrive in fast-paced, high-growth, and rapidly evolving environments.
- Ability to work effectively in a remote-first environment, ensuring high-quality virtual interactions with minimal distractions.
Benefits
- Competitive compensation, including health, dental, vision and other benefits
Related Guides
Related Categories
Related Job Pages
More Compliance Jobs
Compliance Specialist - Regulatory Expert
MercorCincinnatus is an enterprise staffing company that partners with leading technology companies to source and employ highly skilled professionals for full-time and long-term contingent roles. Cincinnatus serves as the employer of record for these engagements, providing W-2 employment, payroll, benefits, and compliance, while placing employees directly within client teams to work on high-impact initiatives. Roles hired through Cincinnatus are not project-based or freelance engagements. They are structured, role-based positions that typically involve full-time or fixed-term commitments, close collaboration with a client's internal teams, and integration into standard enterprise workflows. Cincinnatus is a legal entity separate from Mercor. While opportunities may be discovered through Mercor's platform, employment, onboarding, payroll, and benefits for these roles are administered by Cincinnatus. Equal Employment Opportunity Cincinnatus is proud to be an Equal Employment Opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or any other legally protected characteristic. Cincinnatus is committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans throughout the job application process.
Role Description - Design LLM prompts and evaluate model outputs for compliance and legal operations. - Develop and refine Rubric style tasks to ensure accuracy and compliance in outputs. - Collaborate with regulatory and audit specialists to enhance model performance. - Provide structured feedback to improve AI model training and evaluation processes. - Work independently and asynchronously to meet project deadlines. - Ensure compliance with legal standards and regulations in all outputs. Qualifications - Experience in compliance, legal operations, and regulatory audits. - Confidence in designing LLM prompts and evaluating model outputs. Company Description Mercor connects elite creative and technical talent with leading AI research labs. Headquartered in San Francisco, our investors include Benchmark, General Catalyst, Peter Thiel, Adam D'Angelo, Larry Summers, and Jack Dorsey.
Governance, Risk and Compliance Analyst
Travel + Leisure Co.Travel + Leisure Co. is the world’s leading membership and leisure travel company.
• Assist Travel + Leisure Information Technology (IT) Governance, Risk, & Compliance organization • Comply with T+L’s governing IT Security Policy & Standards • Support Services: Policy Violation Support, Vulnerability Support, Legal Support, Security Awareness, eGRC Support, Advisory Services • Policy Governance: Policies, standards, guidelines, and exception processing • Compliance Monitoring: PCI, SOX, GDPR, HIPAA, CCPA • Internal Compliance Reviews: Vendor, solution, 3rd party risk, M&A reviews • Travel Requirements: 5% for onsite reviews and conferences
• Develop, implement, and oversee the compliance program in accordance with the elements described by the Department of Justice and HHS Office of the Inspector General and the results of the annual compliance risk assessment • Hire, lead, and manage Compliance team and Privacy team staff • Manage suite of company policies and procedures, and oversee drafting, revising, deploying and training on policies and procedures in concert with relevant business units • Develop, implement and drive annual internal compliance risk assessment, annual work plan, and audit and monitoring plan • Work directly with MRO’s health system clients to communicate MRO compliance program elements, assist in understanding federal and state privacy laws and anticipated regulatory and legislative changes • Oversee and track required compliance trainings • Develop and report key compliance metrics across all business lines • Develop and manage appropriate governance structures for compliance, including running regular meetings of management compliance committee and presenting and reporting to the board of directors’ Compliance, Information Security, and Public Policy Committee • Work closely with (i) Legal team to ensure common understanding of applicable laws, and (ii) Government Affairs team to anticipate changes in laws that affect the company’s business and compliance program • Present compliance and health information management topics to industry groups and at MRO client summits • Creatively leverage the company’s technology resources to implement the above objectives • Other tasks and responsibilities as assigned by the CEO, CLO, or Board of Directors from time-to-time incident to the above
Senior Manager, CHQ Government Compliance
L3HHCM20L3Harris Australia excels as a prime defence contractor, providing integrated tech solutions for over four decades. Specialising in technology that connects and shapes operations spanning multiple domains: space, air, land, sea, cyber and first responders. Today, we employ over 500 professionals in all major cities who understand the region’s unique requirements.
Role Description The SSIHO Compliance department, located in Melbourne, FL is seeking a government compliance senior manager that will be responsible for preparation and oversight of all regulatory compliance requirements of L3Harris IT (ITSS) and Financial (GBS) Shared Services. Responsibilities include compiling, preparing, reviewing, and reporting various components of SSIHO regulatory requirements. - Working closely with the ITSS and GBS FP&A department during the development/update of SSIHO AOP and concurrently develop/update the CHQ Forward Pricing Rate submission. - Identifying and explaining variances and communicate potential issues related to the shared services model to management. - Preparing and submit quarterly cost monitoring reports to DCMA, comparing actual incurred costs to forward pricing, and perform variance analysis. - Coordinating with GBS department leads to validate and analyze base data in support of forward pricing and incurred cost submission. - Supervising and supporting the preparation of the incurred cost submission. - Leading responses to DCMA/DCAA audit requests for forward pricing proposal, incurred cost proposal and other audits. - Supporting accounting system and estimating system readiness and external audits. - Performing various ad hoc analyses as required to include trend analysis, effects of one-time events, “what if” scenarios, and support special projects as assigned. - This position will interface with SSIHO Financial Planning & Analysis, SSIHO Accounting, and Shared Services Department Leads. Qualifications - Bachelor’s Degree and minimum 15 years of prior relevant experience. Graduate Degree and a minimum of 13 years of prior related experience. In lieu of a degree, minimum of 19 years of prior related experience. - 12 years of prior government compliance experience. Requirements - Strong leadership and interpersonal skill set, capable of interfacing and forming strategic business partnerships with key stakeholders. - Strong communication skills (Oral, Written, Listening). - Ability to operate effectively in a dynamic environment and be flexible to meet the needs of the customer through detail analysis or summary reporting. - Ability to solve problems, develop and implement innovative and creative solutions to issues and situations that exist in a complex and changing environment. - Must be self-directed, proactive and possess ability to multi-task. - PeopleSoft and Hyperion experience are preferred, but not required. Benefits - Health and disability insurance. - 401(k) match. - Flexible spending accounts. - EAP (Employee Assistance Program). - Education assistance. - Parental leave. - Paid time off. - Company-paid holidays.


