Back to Remote jobs   >   Compliance   >   grc analyst
Senior Governance, Risk & Compliance Analyst @Aya Healthcare
Compliance
Salary $105,000 to $13..
Remote Location
๐Ÿ‡บ๐Ÿ‡ธ USA Only
Employment Type full-time
Posted 3wks ago

[Hiring] Senior Governance, Risk & Compliance Analyst @Aya Healthcare

3wks ago - Aya Healthcare is hiring a remote Senior Governance, Risk & Compliance Analyst. ๐Ÿ’ธ Salary: $105,000 to $135,000 ๐Ÿ“Location: USA

Role Description

We are seeking a Senior Governance, Risk & Compliance (GRC) Analyst to help operate and mature Ayaโ€™s enterprise GRC program, with a strong emphasis on compliance automation, scalability, and operational excellence. In this role, you will own GRC projects and deliverables across the organization while serving as a subject-matter expert in compliance operations, risk management, and ServiceNow GRC / IRM.

This is a hands-on opportunity for someone energized by improving modern GRC capabilities and moving away from manual, point-in-time audit work toward automated, continuously operating compliance processes.

You will work cross-functionally across Information Security, IT, Legal, Privacy, Engineering, Finance, and Audit to:

  • Translate regulatory and framework requirements into practical controls
  • Improve evidence collection and reporting
  • Deliver clear, actionable insights to stakeholders and leadership

You will work in the Security organization and report to the Manager, Governance, Risk & Compliance. This role is remote and will work PST business hours.

Responsibilities

  • Own assigned GRC projects, compliance deliverables, and process improvements from planning through completion.
  • Support the day-to-day operation and continuous improvement of Ayaโ€™s enterprise GRC program.
  • Design and improve scalable workflows that translate regulatory and framework requirements into clear control activities and operational responsibilities.
  • Support compliance efforts for SOC 2 and ISO/IEC 27001:2022, including readiness activities, audit preparation, evidence coordination, control testing, auditor support, and remediation tracking.
  • Establish and maintain clear control ownership, traceability, documentation, and evidence requirements.
  • Identify opportunities to replace manual or spreadsheet-driven compliance activities with automated, system-driven processes.
  • Improve automated evidence collection, control testing, issue and remediation tracking, dashboards, and reporting.
  • Conduct control reviews, risk assessments, evidence evaluations, and compliance gap analyses.
  • Monitor remediation activities, follow up with control owners, identify delivery risks, and escalate issues when appropriate.
  • Build and maintain dashboards, metrics, and reports that communicate compliance status, trends, exceptions, risks, and remediation progress.
  • Partner with ServiceNow platform and engineering teams to ensure GRC solutions are scalable, supportable, and aligned with enterprise processes.
  • Engage with customers to respond to compliance, security, privacy, and risk-related questions in RFPs, due diligence requests, contracts, and customer meetings.
  • Collaborate with Security, IT, Engineering, Finance, Legal, Privacy, Internal Audit, and business stakeholders to resolve control and compliance issues.
  • Translate risk and compliance requirements into clear, business-relevant guidance that enables teams to take action.
  • Lead working sessions, walkthroughs, and process discussions with control owners and subject-matter experts.
  • Identify emerging risks, process dependencies, and long-term improvement opportunities within the GRC domain.
  • Guide and support junior analysts and teammates through collaboration, knowledge sharing, and example.
  • Review work products for accuracy, completeness, and alignment with established quality standards.
  • Document process improvements, design decisions, procedures, and lessons learned.

Qualifications

  • 4+ years of experience in Governance, Risk, and Compliance, Information Security, IT Audit, or a related discipline.
  • Hands-on experience operating or configuring GRC tools such as ServiceNow GRC / IRM, Drata, Vanta, or Hyperproof to automate and manage compliance workflows.
  • Demonstrated experience owning GRC projects, compliance deliverables, or process-improvement initiatives from planning through completion.
  • Strong working knowledge of SOC 2 or ISO/IEC 27001:2022. Familiarity with HIPAA and other healthcare-related compliance requirements is preferred.
  • Experience with control design, evidence evaluation, risk assessments, audit support, remediation tracking, or compliance testing.
  • Experience improving manual compliance processes through automation, workflow design, or system-based reporting.
  • Strong written and verbal communication skills, with the ability to explain risk and compliance concepts to both technical and non-technical audiences.
  • Demonstrated ability to work independently, manage competing priorities, anticipate next steps, and escalate risks early.
  • Experience collaborating across Information Security, IT, Engineering, Legal, Privacy, Finance, Audit, and business teams.
  • Bachelorโ€™s degree in IT / CS is preferred.
  • CISA, CISSP (or CISSP Associate), CCSP, ISO 27001 credential, or another relevant security or compliance certification is preferred.
  • Experience with additional security, compliance, AI governance, and privacy frameworks or regulatory requirements, such as ISO/IEC 42001, NIST AI RMF, NIST CSF, GDPR/UK GDPR, and CCPA/CPRA, is a plus.
  • Experience with ServiceNow GRC / IRM implementation, administration, configuration, or integration is preferred.
  • Experience developing GRC metrics, dashboards, key performance indicators, or leadership reporting is preferred.
  • Experience supporting internal or external audits in a regulated or healthcare-related environment is preferred.

Core Role Criteria

  • GRC Subject-Matter Expertise: Demonstrates deep knowledge within GRC and understands how compliance activities affect related security, technology, privacy, legal, and business processes.
  • Project and Outcome Ownership: Owns assigned outcomes end to end, delivers high-quality work, and holds self and project participants accountable for commitments.
  • GRC Tool Capability: Experience with modern GRC tools such as ServiceNow, Drata, or Vanta. Experience with ServiceNow GRC / IRM beyond basic end-user activity is preferred.
  • Compliance Automation Mindset: Identifies opportunities to reduce manual effort and validates automation or process improvements through measurable results.
  • Analytical Judgment: Evaluates evidence, identifies control gaps and emerging risks, understands dependencies, and recommends practical solutions.
  • Cross-Functional Collaboration: Builds effective working relationships and guides stakeholders through compliance requirements using clear, business-relevant language.
  • Strategic Orientation: Understands emerging risks and long-term trends within GRC and connects day-to-day work to broader organizational objectives.
  • Informal Leadership: Leads projects from start to completion and guides teammates through collaboration, knowledge sharing, and example without requiring formal management authority.
  • Delivery and Initiative: Manages work independently, anticipates next steps, improves processes, and delivers projects on schedule.

Benefits

  • Free premium medical, dental, life and vision insurance
  • Generous 401(k) match
  • Aya also offers other benefits to those that are eligible and where required by applicable law, including reimbursements and discretionary bonuses
  • Aya provides paid sick leave in accordance with all applicable state, federal, and local laws. Ayaโ€™s general sick leave policy is that employees accrue one hour of paid sick leave for every 30 hours worked.
  • Celebrations! We hit our goals and reward ourselves.
  • Company-sponsored virtual events, happy hours and team-building activities are always on the horizon โ€” plus, you get a special treat on your birthday!
  • Unlimited DTO โ€” we believe in time off!
  • Virtual yoga, meditation or boot camp classes offered daily

Compensation

Aya reasonably anticipates the pay scale for this position to be an annual salary of $105,000 to $135,000. The pay scale for this position may vary if applicant possesses experience outside of what Aya reasonably anticipates for this position. Bonuses are subject to the role and your managerโ€™s discretion.

Aya is an Equal Opportunity Employer (EEO), including Disability / Vets, and welcomes all to apply.

Before You Apply
๏ธ
๐Ÿ‡บ๐Ÿ‡ธ Be aware of the location restriction for this remote position: USA Only
โ€ผ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Back to Remote jobs   >   Compliance   >   grc analyst
Senior Governance, Risk & Compliance Analyst @Aya Healthcare
Compliance
Salary $105,000 to $13..
Remote Location
๐Ÿ‡บ๐Ÿ‡ธ USA Only
Employment Type full-time
Posted 3wks ago
Apply for this position
Did not apply โœ“
Applied โœ“
Sent Follow-Up โœ“
Interview Scheduled โœ“
Interview Completed โœ“
Offer Accepted โœ“
Offer Declined โœ“
Application Denied โœ“
Unlock 120,000+ Remote Jobs
๏ธ
๐Ÿ‡บ๐Ÿ‡ธ Be aware of the location restriction for this remote position: USA Only
โ€ผ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply โœ“
Applied โœ“
Sent Follow-Up โœ“
Interview Scheduled โœ“
Interview Completed โœ“
Offer Accepted โœ“
Offer Declined โœ“
Application Denied โœ“
Unlock 120,000+ Remote Jobs
ร—
Apply to the best remote jobs
before everyone else

Access 120,000+ vetted remote jobs and get daily alerts.

4.9 โ˜…โ˜…โ˜…โ˜…โ˜… from 500+ reviews

โšก 123,996+ remote jobs, refreshed hourly

๐Ÿ”” Real-time alerts: Apply first

๐Ÿ›ก๏ธ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later