{"schemaVersion":"jobsearcher.job.v1","id":"d8a5b3dc52d5b9959eecff8b","url":"https://jobsearcher.com/jobs/d8a5b3dc52d5b9959eecff8b","canonicalUrl":"https://jobsearcher.com/jobs/d8a5b3dc52d5b9959eecff8b","title":"IT GRC Analyst","description":"Remote, USACompensation: $55 - $80 per hourContract Length: 6-month Contract to HireHours: Standard full-time schedule, 8 hours/day, 5 days/week; potential for extended hours under heavy audit or incident response activity.Start Date: ASAPAbout The RoleOur client is a healthcare organization providing primary and post-acute care services to seniors across assisted living, life plan communities, independent living, skilled nursing, and long-term care settings nationwide. The organization is value-driven, offering competitive pay, comprehensive benefits, and flexible scheduling, with a mission to improve the health, happiness, and dignity of the seniors it serves.We are seeking an IT GRC Analyst to join the IT Security and Governance team on a 6-month contract-to-hire basis, working remotely within the USA. The IT GRC Analyst will play a key role in supporting the organization's IT Governance, Risk, and Compliance (GRC) program, focusing on security governance, regulatory compliance, risk management, audit readiness, policy administration, and control monitoring. This position collaborates with IT, Security, Privacy, Compliance, Legal, and business stakeholders to enhance the organization's security posture and ensure compliance with healthcare regulations such as HIPAA, SOC 2, and NIST. The role also contributes to business continuity, disaster recovery, and AI governance initiatives. Up to 10% travel may be required.What You'll DoPerform information security risk assessments and document identified risks, control gaps, and remediation recommendationsSupport administration and maintenance of the organization's IT Governance, Risk, and Compliance (GRC) programAssist with development, review, maintenance, and periodic evaluation of security policies, standards, procedures, and guidelinesCoordinate evidence collection, control validation, documentation activities, and remediation tracking for internal and external audits and assessmentsMaintain and map security controls against applicable regulatory, contractual, and industry frameworks (e.g., HIPAA, SOC 2, NIST, CMS, URAC)Assist with security exception review processes and document risk acceptance decisionsMaintain compliance metrics, risk registers, issue logs, corrective action plans, and other governance documentationCollaborate with technology teams to identify and remediate security vulnerabilities, control deficiencies, and compliance gapsAnalyze emerging cybersecurity, privacy, and regulatory requirements and provide recommendations for program improvementsSupport security awareness, compliance training, and organizational education initiativesSupport security governance forums, risk committees, and related working groups through agenda preparation, risk presentation, meeting facilitation, and documentation of decisions and action itemsFacilitate risk intake, scoring, prioritization, escalation, and ongoing monitoring activities in accordance with organizational risk management proceduresSupport administration, data quality, workflow management, reporting, and continuous improvement of GRC tooling and platformsParticipate in security and compliance reviews for new technologies, systems, projects, AI initiatives, and significant change requests to identify regulatory and security requirements early in the lifecycleSupport business continuity, disaster recovery, resilience planning, testing, and associated governance activitiesSupport AI governance, risk assessments, control validation, and compliance reviews for approved AI technologies and use casesDevelop and maintain key risk indicators (KRIs), key performance indicators (KPIs), and executive reporting packages supporting leadership and governance oversightPerform other related duties as assigned to support departmental and organizational objectivesWhat You Bring3-5 years of experience in information security, risk management, compliance, audit, or GRC functionsHealthcare industry experience requiredStrong understanding of information security governance, risk management, compliance, and control frameworksKnowledge of healthcare regulatory requirements, including HIPAA Privacy and Security RulesFamiliarity with industry frameworks and standards such as NIST CSF, SOC 2, HIPAA, and CISExperience conducting risk assessments, compliance reviews, and control evaluationsUnderstanding of third-party risk management and vendor security review processesAbility to interpret laws, regulations, contractual requirements, and industry standardsStrong analytical, organizational, and problem-solving skills with exceptional attention to detail and critical thinkingExperience preparing audit-ready documentation and maintaining evidence repositoriesExcellent written and verbal communication skills, including executive-level reporting and presentationsAbility to prioritize multiple assignments and manage deadlines in a dynamic healthcare environmentProficiency with Microsoft Office applications, governance tools, and compliance management platformsBachelor's degree in Information Security, Information Technology, Cybersecurity, Computer Science, Healthcare Informatics, or a related field (or equivalent experience)Nice To HavesExperience supporting HIPAA, SOC 2, CIS, NIST Cybersecurity Framework, or similar regulatory and security frameworksExperience participating in audits, risk assessments, control testing, or compliance monitoring activitiesWhat's In It For YouCompetitive pay and comprehensive benefitsFlexible scheduling and remote workOpportunity to contribute to a mission-driven organization improving the lives of seniorsProfessional growth in a dynamic healthcare environmentPotential for contract-to-hire conversionDisclaimerBrooksource, Medasource, and Calculated Hire are part of the Eight Eleven Group family of companies and operate under Eight Eleven Group, LLC. All employees receive the same benefits, policies, and terms of employment.EeoWe are committed to creating an inclusive environment for all employees and applicants. We do not discriminate on the basis of race, color, religion, creed, sex, sexual orientation, gender identity or expression, national origin, ancestry, age, disability, genetic information, marital status, military or veteran status, citizenship, pregnancy (including childbirth, lactation, and related conditions), or any other protected status in accordance with applicable federal, state, and local laws.Benefits & PerksCalculated Hire offers competitive medical, dental, vision, Health Savings Account, Dependent Care FSA, and supplemental coverage with plans that can fit each employee’s needs. We offer a 401k plan that includes a company match and is fully vested after you become eligible, paid time off, sick time, and paid company holidays. We also offer an Employee Assistance Program (EAP) that provides services like virtual counseling, financial services, legal services, life coaching, etc.Pay DisclaimerThe pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.","company":"Medasource","rawCompany":"medasource","city":"Dallas","state":"TX","isRemote":false,"isActive":false,"createdAt":"2026-08-14T14:59:36.425Z","occupations":[{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"11-9199.02","title":"Compliance Managers","slug":"compliance-managers"},{"code":"13-1199.07","title":"Security Management Specialists","slug":"security-management-specialists"}],"industries":[{"code":"541611","title":"Administrative Management and General Management Consulting Services","slug":"administrative-management-and-general-management-consulting-services"},{"code":"541618","title":"Other Management Consulting Services","slug":"other-management-consulting-services"},{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"IT GRC Analyst","description":"Remote, USACompensation: $55 - $80 per hourContract Length: 6-month Contract to HireHours: Standard full-time schedule, 8 hours/day, 5 days/week; potential for extended hours under heavy audit or incident response activity.Start Date: ASAPAbout The RoleOur client is a healthcare organization providing primary and post-acute care services to seniors across assisted living, life plan communities, independent living, skilled nursing, and long-term care settings nationwide. The organization is value-driven, offering competitive pay, comprehensive benefits, and flexible scheduling, with a mission to improve the health, happiness, and dignity of the seniors it serves.We are seeking an IT GRC Analyst to join the IT Security and Governance team on a 6-month contract-to-hire basis, working remotely within the USA. The IT GRC Analyst will play a key role in supporting the organization's IT Governance, Risk, and Compliance (GRC) program, focusing on security governance, regulatory compliance, risk management, audit readiness, policy administration, and control monitoring. This position collaborates with IT, Security, Privacy, Compliance, Legal, and business stakeholders to enhance the organization's security posture and ensure compliance with healthcare regulations such as HIPAA, SOC 2, and NIST. The role also contributes to business continuity, disaster recovery, and AI governance initiatives. Up to 10% travel may be required.What You'll DoPerform information security risk assessments and document identified risks, control gaps, and remediation recommendationsSupport administration and maintenance of the organization's IT Governance, Risk, and Compliance (GRC) programAssist with development, review, maintenance, and periodic evaluation of security policies, standards, procedures, and guidelinesCoordinate evidence collection, control validation, documentation activities, and remediation tracking for internal and external audits and assessmentsMaintain and map security controls against applicable regulatory, contractual, and industry frameworks (e.g., HIPAA, SOC 2, NIST, CMS, URAC)Assist with security exception review processes and document risk acceptance decisionsMaintain compliance metrics, risk registers, issue logs, corrective action plans, and other governance documentationCollaborate with technology teams to identify and remediate security vulnerabilities, control deficiencies, and compliance gapsAnalyze emerging cybersecurity, privacy, and regulatory requirements and provide recommendations for program improvementsSupport security awareness, compliance training, and organizational education initiativesSupport security governance forums, risk committees, and related working groups through agenda preparation, risk presentation, meeting facilitation, and documentation of decisions and action itemsFacilitate risk intake, scoring, prioritization, escalation, and ongoing monitoring activities in accordance with organizational risk management proceduresSupport administration, data quality, workflow management, reporting, and continuous improvement of GRC tooling and platformsParticipate in security and compliance reviews for new technologies, systems, projects, AI initiatives, and significant change requests to identify regulatory and security requirements early in the lifecycleSupport business continuity, disaster recovery, resilience planning, testing, and associated governance activitiesSupport AI governance, risk assessments, control validation, and compliance reviews for approved AI technologies and use casesDevelop and maintain key risk indicators (KRIs), key performance indicators (KPIs), and executive reporting packages supporting leadership and governance oversightPerform other related duties as assigned to support departmental and organizational objectivesWhat You Bring3-5 years of experience in information security, risk management, compliance, audit, or GRC functionsHealthcare industry experience requiredStrong understanding of information security governance, risk management, compliance, and control frameworksKnowledge of healthcare regulatory requirements, including HIPAA Privacy and Security RulesFamiliarity with industry frameworks and standards such as NIST CSF, SOC 2, HIPAA, and CISExperience conducting risk assessments, compliance reviews, and control evaluationsUnderstanding of third-party risk management and vendor security review processesAbility to interpret laws, regulations, contractual requirements, and industry standardsStrong analytical, organizational, and problem-solving skills with exceptional attention to detail and critical thinkingExperience preparing audit-ready documentation and maintaining evidence repositoriesExcellent written and verbal communication skills, including executive-level reporting and presentationsAbility to prioritize multiple assignments and manage deadlines in a dynamic healthcare environmentProficiency with Microsoft Office applications, governance tools, and compliance management platformsBachelor's degree in Information Security, Information Technology, Cybersecurity, Computer Science, Healthcare Informatics, or a related field (or equivalent experience)Nice To HavesExperience supporting HIPAA, SOC 2, CIS, NIST Cybersecurity Framework, or similar regulatory and security frameworksExperience participating in audits, risk assessments, control testing, or compliance monitoring activitiesWhat's In It For YouCompetitive pay and comprehensive benefitsFlexible scheduling and remote workOpportunity to contribute to a mission-driven organization improving the lives of seniorsProfessional growth in a dynamic healthcare environmentPotential for contract-to-hire conversionDisclaimerBrooksource, Medasource, and Calculated Hire are part of the Eight Eleven Group family of companies and operate under Eight Eleven Group, LLC. All employees receive the same benefits, policies, and terms of employment.EeoWe are committed to creating an inclusive environment for all employees and applicants. We do not discriminate on the basis of race, color, religion, creed, sex, sexual orientation, gender identity or expression, national origin, ancestry, age, disability, genetic information, marital status, military or veteran status, citizenship, pregnancy (including childbirth, lactation, and related conditions), or any other protected status in accordance with applicable federal, state, and local laws.Benefits & PerksCalculated Hire offers competitive medical, dental, vision, Health Savings Account, Dependent Care FSA, and supplemental coverage with plans that can fit each employee’s needs. We offer a 401k plan that includes a company match and is fully vested after you become eligible, paid time off, sick time, and paid company holidays. We also offer an Employee Assistance Program (EAP) that provides services like virtual counseling, financial services, legal services, life coaching, etc.Pay DisclaimerThe pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.","datePosted":"2026-08-14T14:59:36.425Z","dateModified":"2026-08-14T14:59:36.425Z","hiringOrganization":{"@type":"Organization","name":"Medasource","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Dallas","addressRegion":"TX","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"d8a5b3dc52d5b9959eecff8b"},"url":"https://jobsearcher.com/jobs/d8a5b3dc52d5b9959eecff8b"}}