GRC - Security Analyst

Posted 10 Days Ago
Industrial Area SSI, Rajaji Nagar, Bengaluru Urban, Karnataka, IND
In-Office
Mid level
Insurance
The Role
Perform cybersecurity risk assessments, maintain security policies and controls, support audits and regulatory compliance, manage risk registers and remediation plans, assess third-party vendors, maintain control evidence, and develop GRC metrics and reports. The role collaborates with technical and business stakeholders to communicate risks, improve governance processes, and support security awareness, exceptions, and risk acceptance activities.
Summary Generated by Built In
Job Title:

Security Analyst I, GRC

Job Category:
Department/Group:

Information Technology

Job Code/ Req#:
Work Location:

Remote

Reports To:
Level/Salary Range:
Position Type:

Full Time

FLSA STATUS:
Travel:

10%, as needed

Date Posted:

Job Req. Category:


Job DescriptionAbout the role

This role will help identify and assess security risks, maintain compliance with applicable regulatory and industry requirements, support audits and assessments, and strengthen security governance across the organization. The ideal candidate has a strong understanding of cybersecurity risk, security controls, compliance frameworks, and third-party risk management. This individual will work closely with Information Security, IT, Legal, Privacy, Internal Audit, and business stakeholders to ensure security risks are appropriately identified, documented, communicated, and remediated.


What you will do

·        Perform cybersecurity and technology risk assessments to identify, document, and evaluate risks across systems, applications, vendors, and business processes.

·        Maintain and support the organization's information security policies, standards, procedures, and control framework.

·        Support compliance efforts related to frameworks and regulations such SOC 2, HIPAA, HITRUST, PCI DSS, as applicable.

·        Assist with internal and external audits, regulatory examinations, security assessments, and customer compliance reviews.

·        Gather, review, and maintain evidence demonstrating the effectiveness of security and compliance controls.

·        Track security risks, audit findings, control deficiencies, exceptions, and remediation plans through closure.

·        Partner with control owners to evaluate control effectiveness and recommend improvements.

·        Conduct third-party and vendor security risk assessments, including reviewing security questionnaires, certifications, audit reports, and supporting documentation.

·        Maintain the organization's risk register and help ensure risks are appropriately scored, assigned, monitored, and reported.

·        Support security awareness, policy acknowledgment, and governance initiatives.

·        Respond to customer and partner security questionnaires and due diligence requests.

·        Assist with monitoring changes to regulatory requirements, security standards, and industry best practices.

·        Develop and maintain GRC metrics, dashboards, reports, and documentation for management and other stakeholders.

·        Support security exception and risk acceptance processes.

·        Collaborate with technical security teams to translate technical vulnerabilities and security issues into understandable business risk.

·        Identify opportunities to automate and improve GRC processes.

You will be a good fit if:

·        You are enthusiastic about Security.

·        Some experience with Incident Response.

·        Curiosity and willingness to learn new things.

·        Excellent organization and planning skills, both technical and strategic.

·        Stay updated with the latest in technology and cybersecurity trends to recommend improvements to our IT and security infrastructure.

·        Ability to meet timeframes and solve issues.

Requirements

·        Bachelor's degree in Cybersecurity, Information Technology, Information Systems, Risk Management, or a related field, or equivalent professional experience.

·        3+ years of experience in cybersecurity, governance, risk management, compliance, IT audit, or a related discipline.

·        Relevant professional certification such as Security+, CISA, CRISC, or CGRC.

·        Working knowledge of cybersecurity frameworks and standards such as HITRUST, SOC 2, PCI-DSS or similar frameworks.

·        Experience performing security risk assessments or evaluating security controls.

·        Familiarity with regulatory and compliance requirements relevant to the organization's industry.

·        Strong analytical, organizational, and documentation skills.

·        Ability to communicate security and risk concepts effectively to both technical and non-technical stakeholders.

·        Strong attention to detail and ability to manage multiple assessments, findings, and deadlines simultaneously.

·        Proficiency with Microsoft Office or similar productivity and reporting tools.


Additional Notes


This role profile is not intended to be an exhaustive list of qualifications, skills, efforts, duties, responsibilities or working conditions associated with the position.

 

GetixHealth is an equal employment opportunity employer.

     

Approved By:

Name

Date:

Last Updated By:

Name

Date/Time:


Skills Required

  • Bachelor's degree in Cybersecurity, Information Technology, Information Systems, Risk Management, or a related field, or equivalent professional experience
  • 3+ years of experience in cybersecurity, governance, risk management, compliance, IT audit, or a related discipline
  • Relevant professional certification such as Security+, CISA, CRISC, or CGRC
  • Working knowledge of cybersecurity frameworks and standards such as HITRUST, SOC 2, PCI DSS, or similar frameworks
  • Experience performing security risk assessments or evaluating security controls
  • Familiarity with regulatory and compliance requirements relevant to the organization's industry
  • Strong analytical, organizational, and documentation skills
  • Ability to communicate security and risk concepts effectively to technical and non-technical stakeholders
  • Strong attention to detail and ability to manage multiple assessments, findings, and deadlines simultaneously
  • Proficiency with Microsoft Office or similar productivity and reporting tools
  • Some experience with incident response
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Houston, TX
793 Employees
Year Founded: 2012

What We Do

GetixHealth provides hospitals, clinics, university medical centers, and other healthcare facilities across the United States with comprehensive revenue cycle management (RCM) services. Our services are customized to the needs of our client and can either include all facets of the front and back office revenue cycle or a mixture of these services, including but not limited to: medical coding and billing, claims management, insurance eligibility services, medicaid/medicare specialized services, and self pay and bad debt collections.

Similar Jobs

Remote or Hybrid
2 Locations
289097 Employees
Hybrid
Bengaluru, Bengaluru Urban, Karnataka, IND
205000 Employees
Hybrid
Bengaluru, Bengaluru Urban, Karnataka, IND
205000 Employees

Wells Fargo Logo Wells Fargo

Operations Specialist

Fintech • Financial Services
Hybrid
Bengaluru, Bengaluru Urban, Karnataka, IND
205000 Employees

Similar Companies Hiring

MassMutual India Thumbnail
Big Data • Fintech • Information Technology • Insurance • Financial Services
Hyderabad, Telangana
Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Vega Thumbnail
Artificial Intelligence • Automotive • Insurance • Transportation
US
43 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account