← Все вакансии/Lead/jobgether
LeadRemoteUS

Risk Management Analyst

J
jobgether
Уровень
Lead
Формат
Remote
О роли

Описание вакансии

About the company

Our partner is looking for a Sr. Staff Risk Management Analyst based in the United States. This is a senior leadership opportunity to build and operate an enterprise risk management program within a fast-growing, technology-driven healthcare environment.

Responsibilities
  • Own and mature the enterprise risk management program, maintaining an enterprise-wide risk register that is distinct from the cyber risk register.
  • Develop, refine, and operationalize the enterprise risk appetite statement, ensuring it informs business decisions and priority-setting.
  • Establish and operate the ERM policy and enterprise risk assessment methodology, conducting assessments across the organization and maintaining accountability among designated risk owners.
  • Present enterprise risk posture, emerging risks, and mitigation progress to executives and the Enterprise Risk Committee.
  • Produce governance and risk-assessment evidence supporting security and compliance frameworks, including SOC 2, HITRUST, HIPAA, NIST CSF 2.0, and future control frameworks.
  • Govern reporting for the security program portfolio, tracking commitments, dependencies, priority initiatives, delivery risks, and progress against strategic objectives.
  • Maintain the multi-year security risk-reduction roadmap and provide regular visibility into progress, dependencies, and areas of concern.
  • Own the security organization’s OKRs from definition through measurement, reporting, and follow-up.
  • Track critical dependencies and drive priority initiatives through completion, influencing stakeholders across teams without direct authority.
  • Build and manage the security awareness program, establishing sustainable processes and recurring communications.
  • Manage insurance-related responsibilities, including property and casualty renewals, claims, certificates of insurance, carrier audits, and insurance requirements in customer contracts.
  • Extend second-line risk coverage into areas such as pharmacy, financial, and clinical risk in partnership with relevant domain owners.
  • Partner with third-party risk and business resilience stakeholders to ensure vendor, concentration, and resilience risks are appropriately represented in the enterprise risk view.
  • Automate recurring activities across risk-register maintenance, assessment intake, evidence collection, and reporting to improve efficiency and scalability.
  • Support first-line teams during cybersecurity compliance audits and contribute to the continued development of the broader GRC program.
  • Identify opportunities to strengthen governance, improve risk visibility, and enable the organization to move quickly while maintaining appropriate controls.
Requirements
  • 10+ years of experience in information security, risk management, governance, risk, and compliance (GRC), or a closely related field.
  • Demonstrated ownership of a GRC or enterprise risk program, including risk registers, policies, assessment methodologies, and governance processes.
  • Hands-on experience conducting risk and control self-assessments (RCSA) or a comparable enterprise risk assessment methodology.
  • Proven experience developing and maintaining a multi-year risk-reduction roadmap and reporting progress against strategic objectives.
  • Experience preparing and presenting risk reports and recommendations to executive leadership and a board, risk committee, or equivalent governing body.
  • Demonstrated ability to establish accountability and drive commitments across teams without relying on direct reporting authority.
  • Experience working with security and compliance frameworks such as SOC 2, HITRUST, HIPAA, NIST CSF, or comparable control frameworks.
  • Experience serving as the first dedicated full-time owner of a function, operating independently without an established team or dedicated budget structure.
  • Strong understanding of enterprise risk, security governance, compliance, controls, and business risk management.
  • Excellent executive communication skills, with the ability to translate complex risk information into concise, actionable business insights.
  • Strong organizational, analytical, and program management capabilities, with the ability to manage multiple priorities and stakeholders.
  • High degree of autonomy, ownership, and initiative, particularly in ambiguous or evolving environments.
  • A continuous-improvement mindset and a demonstrated preference for automating repeatable processes wherever practical.
  • Preferred: CRISC, CISA, CISSP, or an equivalent professional certification.
  • Preferred: Experience in healthcare or other environments involving highly sensitive or regulated data.
  • Preferred: Experience building AI or agentic AI systems to automate governance intake, evidence gathering, reporting, or related GRC activities.
  • Preferred: Direct involvement in SOC 2, HITRUST, or HIPAA assurance cycles.
  • Preferred: Experience developing a security awareness program from the ground up.
  • Preferred: Experience implementing, owning, or administering a GRC platform.
Conditions
  • Opportunity to shape a maturing GRC organization while helping a regulated healthcare business scale responsibly.
  • Significant autonomy to design programs, establish accountability, and introduce scalable processes.
  • Collaborative and relatively flat environment with a strong emphasis on ownership, initiative, automation, and continuous improvement.
Стек и навыки

С чем работаем