Lead Security Analyst-GRC at Collective Health | CA, US | Rezi

Lead Security Analyst-GRC at Collective Health

Lead Security Analyst-GRC

Collective Health · CA, US

1 weeks ago

Lead Security Analyst-GRC

Collective Health · CA, US

8 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now
Resume preview

Tailor your resume to this Lead Security Analyst-GRC role.

Rezi rewrites your resume against Collective Health's job description. Free.

Resume score gauge reading 58 out of 100

Don't guess if your resume is good enough.

See how it scores against the Lead Security Analyst-GRC posting at Collective Health — free, in seconds.

About the Role

As our Lead Security Analyst - GRC, you’ll lead initiatives that address sophisticated security engineering challenges. You will build relationships across all parts of the business and drive multi-functional initiatives to continuously improve our security and privacy posture. You will be responsible for building and implementing controls that can scale and optimize as we move into a context-aware security environment.

Responsibilities

  • Evaluate and implement security controls based on frameworks such as NIST, CIS, HIPAA, SOC 2, and HITRUST.
  • Develop and maintain policies, procedures, and documentation (controls, narratives, matrices).
  • Lead SOC 2 and HITRUST audit engagements, from audit planning through remediation.
  • Coordinate and monitor third-party risk assessments and compliance reviews.
  • Own and lead BCP (Business Continuity Planning) and BIA (Business Impact Assessments) efforts.
  • Build and maintain security risk registry.
  • Perform audit readiness assessments, and support internal/external audits.
  • Partner with external auditors, control owners, and leadership to minimize business disruption.
  • Track and drive remediation plans based on audit findings and compliance gaps.
  • Maintain and communicate exception documentation for policy deviations.
  • Educate and guide control/risk owners on their responsibilities.
  • Act as a liaison between technical and non-technical stakeholders.
  • Respond to security questionnaires, RFIs, and client compliance inquiries.
  • Develop and deliver security awareness and training programs.
  • Provide executive reporting on program status, risks, and overall health.

Requirements

  • 8+ years in cybersecurity, GRC, audit, or risk/compliance roles.
  • Experience managing SOC 2 / HITRUST audits, especially in cloud-native environments.
  • Strong working knowledge of security frameworks and regulatory requirements.
  • Demonstrated policy, data management, and risk mitigation capabilities.
  • Familiarity with GRC tools and audit processes.
  • Excellent communication and cross-functional collaboration skills.
  • Big 4 accounting firm background.
  • Professional certifications: CISSP, CISA, CRISC, CISM, or similar.

Skills

  • NIST
  • CIS
  • HIPAA
  • SOC 2
  • HITRUST
  • GRC tools
  • Business Continuity Planning (BCP)
  • Business Impact Assessments (BIA)
  • CISSP
  • CISA
  • CRISC
  • CISM

Location

  • Plano, TX
  • Lehi, UT

Work Type

  • Hybrid

Experience Level

  • 8+ years

Salary/Compensations

  • 205,000 stock options

Benefits

  • Health insurance
  • 401k
  • Paid time off

About the Company

  • At Collective Health, we’re transforming how employers and their people engage with their health benefits by seamlessly integrating cutting-edge technology, compassionate service, and world-class user experience design.
  • Mission-driven culture that values innovation, collaboration, and a commitment to excellence in healthcare.
  • Impactful projects that shape the future of our organization.
  • Opportunities for professional development through internal mobility opportunities, mentorship programs, and courses tailored to your interests.
  • Flexible work arrangements and a supportive work-life balance.

Equal Opportunity

  • We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.
  • Collective Health is committed to providing support to candidates who require reasonable accommodation during the interview process. If you need assistance, please contact recruiting-accommodations@collectivehealth.com.