[Hiring] Sr. GRC Analyst @Bamboo Health
Back to Remote jobs   >   Compliance   >   grc analyst
Sr. GRC Analyst @Bamboo Health
Compliance
Salary unspecified
Remote Location
🇺🇸 USA Only
Employment Type full-time
Posted 3d ago

[Hiring] Sr. GRC Analyst @Bamboo Health

3d ago - Bamboo Health is hiring a remote Sr. GRC Analyst. 💸 Salary: unspecified 📍Location: USA

Role Description

Bamboo Health Security designs forward-thinking security solutions across cloud services, identity and access management, virtualization, and third-party integrations. We focus on innovative, scalable practices that meet complex regulatory requirements and support the company’s growth. Our team is highly collaborative and committed to both business success and individual development.

We are seeking a Senior Governance, Risk and Compliance (GRC) Analyst to help mature our compliance program, contribute to our audit cycles, and serve as the security interface for our customers. You will:

  • Evaluate organizational policies and standards, ensuring that external and internal compliance requirements are met.
  • Develop improvements to the compliance program, including the use of AI, automation, and process optimization.
  • Review security-relevant language in customer contracts (MSAs, DPAs, BAAs) and RFP/RFI security sections, providing recommendations to Legal and the broader GRC team.
  • Respond to customer security questionnaires using AI-assisted tools and trust content, exercising professional judgment to ensure responses are accurate and complete.
  • Work with external auditors and customers as necessary, providing them with required information and assistance.
  • Maintain and update trust center content and customer-facing security documentation.
  • Perform vendor security risk assessments and contribute to the third-party risk management program.
  • Assist in policy documentation upkeep and development, ensuring clarity and applicability.
  • Monitor and assist with the internal training programs on compliance requirements and best practices.
  • Ensure Bamboo Health’s security operations remain aligned with both internal and external compliance requirements, contributing to ongoing internal and external audit reviews.
  • Effectively communicate Bamboo Health’s compliance posture to both internal and external stakeholders, offering tangible proof of adherence to policy requirements.
  • Partner with the larger Information Security team to identify areas for continuous improvement within the compliance framework.
  • Stay curious about emerging AI tools and how they can streamline or enhance work within your function.

Qualifications

  • Bachelor’s degree in information security, computer science, or related field, or equivalent experience in a related field.
  • Security compliance-related certifications such as CISSP, CISA, or CRISC are preferred.
  • 5+ years of experience in information security, with substantial focus on compliance, audit, or risk management work.
  • Direct experience with security frameworks and certifications like NIST SP 800-53, HITRUST, HIPAA, and/or FedRAMP.
  • Experience responding to customer security questionnaires and supporting customer security due diligence activities.
  • Experience reviewing security-relevant language in customer or vendor contracts.
  • Familiarity with healthcare data protection requirements (HIPAA) and the compliance obligations they create.
  • Demonstrated experience with security auditing and evidence gathering for compliance purposes.
  • Experience evaluating security controls for compliance purposes.
  • Familiarity with cloud security concepts and practices.
  • Excellent written and verbal communication skills, with ability to build and communicate business rationale.
  • Strong ability to learn quickly and work independently while being part of a team.
  • Ability to build effective, sustainable working relationships internally, with customers, and external stakeholders.
  • Comfort using or learning AI-supported tools (e.g., ChatGPT, CoPilot, or role-specific tools) to improve daily workflows.
  • A forward-thinking, curious mindset with an openness to experimenting with new technologies.
  • Strong analytical and problem-solving skills, with sound judgment and creativity in designing solutions.
  • Proven ability to thrive in fast-paced, high-growth, and rapidly evolving environments.
  • Ability to work effectively in a remote-first environment, ensuring high-quality virtual interactions with minimal distractions.

Requirements

  • In 3 months: Understand and be able to describe Bamboo Health's products, organizational structure, customer base, and compliance landscape (SOC 2, HITRUST, FedRAMP, etc.).
  • Develop familiarity with policies, risk register, and trust center content.
  • Independently respond to customer security questionnaires using established trust content and AI-assisted tools.
  • Independently perform vendor security reviews.
  • Build partnership with InfoSec team, Legal, Sales, and key cross-functional partners.
  • Incorporate AI-supported tools into your day-to-day work—whether through analysis, documentation, or task management.
  • In 6 months: Actively contribute to audit cycles, including evidence collection and control mapping.
  • Own recurring compliance tasks (e.g., periodic access reviews, policy reviews, evidence collection cycles).
  • Review security-relevant contract language and RFP security sections, providing actionable recommendations.
  • Identify compliance gaps and recommend remediation approaches.
  • Produce routine metrics and reporting on assigned work streams.
  • Support the team's efforts with educational security initiatives and objectives.
  • In 12 months: Independently lead customer security trust activities — questionnaires, trust content, and customer security review calls.
  • Own specific compliance frameworks or domains with minimal oversight.
  • Drive improvements to the GRC program, including expanded use of AI and automation.
  • Contribute meaningfully to audit cycle outcomes, including evidence quality and finding remediation.
  • Serve as a trusted subject matter expert and mentor within the Information Security team.

Benefits

  • Join one of the most innovative healthcare technology companies in the country.
  • Have the autonomy to build something with an enthusiastically supportive team.
  • Learn from working at the highest levels and on the most strategic priorities of the company, including from world class investors and advisors.
  • Receive competitive compensation, including health, dental, vision and other benefits.
Before You Apply
🇺🇸 Be aware of the location restriction for this remote position: USA Only
Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Back to Remote jobs   >   Compliance   >   grc analyst
Sr. GRC Analyst @Bamboo Health
Compliance
Salary unspecified
Remote Location
🇺🇸 USA Only
Employment Type full-time
Posted 3d ago
Apply for this position
Did not apply
Applied
Sent Follow-Up
Interview Scheduled
Interview Completed
Offer Accepted
Offer Declined
Application Denied
Unlock 160,000+ Remote Jobs
🇺🇸 Be aware of the location restriction for this remote position: USA Only
Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply
Applied
Sent Follow-Up
Interview Scheduled
Interview Completed
Offer Accepted
Offer Declined
Application Denied
Unlock 160,000+ Remote Jobs
×

Apply to the best remote jobs
before everyone else

Access 160,000+ vetted remote jobs and get daily alerts.

4.9 ★★★★★ from 500+ reviews
Unlock All Jobs Now

Maybe later