Senior GRC Analyst

Posted 2 Hours Ago
Easy Apply
Be an Early Applicant
Hiring Remotely in USA
Remote
132K-165K Annually
Senior level
Big Data • Healthtech • HR Tech • Machine Learning • Software • Telehealth • Big Data Analytics
Garner uses data science to steer employees to the best-performing doctors.
The Role
Lead GRC efforts to maintain SOC 2, HITRUST, and ISO 27001 compliance. Run internal audits, coordinate external assessments, manage risk register, maintain policies, report to leadership, and drive automation of GRC processes with engineering using scripting and LLMs.
Summary Generated by Built In

Garner’s mission is to transform the healthcare economy, delivering high-quality and affordable care for all. 

We are fundamentally reimagining how healthcare works in the U.S. by partnering with employers to redesign healthcare benefits using clear incentives and powerful, data-driven insights. Our approach guides employees to higher-quality, lower-cost care, creating a system that works better for everyone. Patients achieve better health outcomes, employers spend healthcare dollars more effectively, and physicians are rewarded for delivering exceptional care rather than performing more procedures. 

Garner is one of the fastest-growing healthcare technology companies in the country. Our products are trusted by the most sophisticated employers and providers in the industry, and we are building a team of talented, mission-driven individuals who are motivated to make a meaningful impact on healthcare at scale.

About the role:

We are looking for a Senior GRC Analyst to join our Technical Compliance team to ensure Garner’s compliance posture across security frameworks such as ISO 27001, SOC 2, HITRUST, and HIPAA. As a Senior GRC Analyst, you will run our internal audits, guide our external assessments, and partner with teams across Engineering, Product, People, and Legal so that our controls are designed well, operating effectively, and continuously improving. Our Technical Compliance team safeguards Garner’s sensitive healthcare data and protects the trust of our members, clients, and partners by maintaining a strong control environment and regulatory compliance. The work you do here has a direct impact on our ability to win and retain enterprise customers, expand into new lines of business, and scale securely as we grow.

Where you will work:

This role is open to remote candidates across the U.S. For candidates based in New York City, the position follows a hybrid schedule with in-office work required Tuesday, Wednesday, and Thursday each week.

What you will do:
  • Manage and support our compliance certifications, including SOC 2, HITRUST, and ISO 27001 audits and run control testing across the audit lifecycle
  • Serve as the subject matter expert across the company on our compliance frameworks
  • Serve as the primary point of contact for external auditors and assessors
  • Manage Garner’s Security and Privacy trust center
  • Maintain the risk register and drive risk identification, scoring, and reporting
  • Manage the maintenance of our compliance policies, standards, and procedures
  • Report on our compliance posture to senior leadership
  • Scale our GRC function with AI and automation, building quick wins and scoping requirements for Engineering to fully automate the rest
The ideal candidate has:
  • 5+ years of experience in GRC, IT audit, or information security compliance
  • Prior experience with HITRUST, SOC 2, and ISO 27001 audits
  • Hands-on experience with control design, evidence collection, and remediation in a cloud-native engineering environment
  • Proven ability to adapt your communication style across engineers, operators, and executives
  • A GRC Engineering mindset with prior experience using scripting and LLMs to automate repetitive tasks
  • Industry certifications such as CISA, CISM, CISSP, CRISC, or ISO 27001 Lead Auditor preferred
  • A desire to be a part of a high-performing, mission-driven team that operates with intense urgency, a strong sense of individual accountability, and a commitment to authentic feedback
Technologies we use: 
  • AWS, Okta, Datadog, Retool, Gitlab, Vanta

This is a unique opportunity to join a fast-growing company in a transformative role, helping shape the future of healthcare.

Compensation Transparency:

The target salary range for this position is $132,000 - $165,000. Individual compensation for this role will depend on various factors, including qualifications, skills, and applicable laws. In addition to base compensation, this role is eligible to participate in our equity incentive and competitive benefits plans, including but not limited to: flexible PTO, Medical/Dental/Vision plan options, 401(k), Teladoc Health and more.

Fraud and Security Notice: 

Please be aware of recent job scam attempts. Our recruiters use getgarner.com and garnerhealth.com email domains exclusively. If you have been contacted by someone claiming to be a Garner recruiter or a hiring manager from a different domain about a potential job, please report it to law enforcement here and to [email protected].

Equal Employment Opportunity:Garner Health is proud to be an Equal Employment Opportunity employer and values diversity in the workplace. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics.

Garner Health is committed to providing accommodations for qualified individuals with disabilities in our recruiting process. If you need assistance or an accommodation due to a disability, you may contact us at [email protected]

Skills Required

  • 5+ years of experience in GRC, IT audit, or information security compliance
  • Prior experience with HITRUST, SOC 2, and ISO 27001 audits
  • Hands-on experience with control design, evidence collection, and remediation in a cloud-native engineering environment
  • Proven ability to adapt communication style across engineers, operators, and executives
  • Experience using scripting and LLMs to automate repetitive GRC tasks (GRC Engineering mindset)
  • Industry certifications such as CISA, CISM, CISSP, CRISC, or ISO 27001 Lead Auditor

What the Team is Saying

Pedro
Joanna
Megan
James
Bhavya
Chris
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
350 Employees
Year Founded: 2019

What We Do

Garner Health is a health tech startup that is transforming the healthcare economy by enabling patients to receive high-quality and affordable care. Garner Health has two core offerings: Garner, a benefit program that uses a new approach to data science and incentive accounts to help employees find the best doctors in their communities, and Garner DataPro, a provider recommendation platform that serves referrals based on the most accurate provider performance and directory data in the industry. Garner Health’s offerings utilize over 75% of the medical claims data in the United States to objectively examine patient outcomes based on more than 500 specialty-specific quality and efficiency measures. By analyzing millions of healthcare journeys across 82 distinct medical specialties, Garner Health sets a new industry standard in delivering reliable, actionable referrals and navigating patients to the highest-quality providers. Garner Health is a remote-first company based in NYC.

Why Work With Us

Our values connect us in caring deeply about doing something different and hard — transforming the healthcare economy. They create an actionable set of norms for how we operate, including how we make decisions and support one another. Learn about our values here: https://www.getgarner.com/about.

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

Garner Health Offices

Remote Workspace

Employees work remotely.

Typical time on-site: None
US
New York, NY
Learn more

Similar Jobs

Garner Health Logo Garner Health

Strategic Accounts Director, Large Group

Big Data • Healthtech • HR Tech • Machine Learning • Software • Telehealth • Big Data Analytics
Easy Apply
Remote
USA
350 Employees
190K-250K Annually

Garner Health Logo Garner Health

VP Channel Partner Sales

Big Data • Healthtech • HR Tech • Machine Learning • Software • Telehealth • Big Data Analytics
Easy Apply
Remote
USA
350 Employees
315K-356K Annually

Garner Health Logo Garner Health

Clinical Researcher

Big Data • Healthtech • HR Tech • Machine Learning • Software • Telehealth • Big Data Analytics
Easy Apply
Remote
USA
350 Employees
90K-115K Annually

Garner Health Logo Garner Health

Regional Sales Director - West

Big Data • Healthtech • HR Tech • Machine Learning • Software • Telehealth • Big Data Analytics
Easy Apply
Remote
USA
350 Employees
300K-325K Annually

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account