MENU
  • Remote Jobs
  • Companies
  • Go Premium
  • Job Alerts
  • Post a Job
  • Log in
  • Sign up
Working Nomads logo Working Nomads
  • Remote Jobs
  • Companies
  • Post Jobs
  • Go Premium
  • Get Free Job Alerts
  • Log in

Senior Security Governance Risk & Compliance (GRC) Analyst

Alma

Full-time
USA
$145k-$174k per year
security
analyst
compliance
risk management
infosec
Apply for this position

Senior Security Governance Risk & Compliance (GRC) Analyst

Alma is seeking a mission-driven Senior Security Governance Risk and Compliance (GRC) Analyst to join our team.  We are dedicated to building secure and compliant tools and services that help providers more easily manage and grow their practice.

Acting as a principal aide to the VP of Security and IT, this role will play a critical role in enabling a culture of security at Alma, making security a product differentiator that builds confidence and trust with our providers, and preparing Alma for annual audits and certifications (such as SOC 2 and HITRUST). In this role you will perform risk assessments, create and maintain our security policies, educate our staff by developing a security awareness program, respond to security assessments, and review our vendor’s security. 

What you’ll do:

  • Perform risk assessments and reports on Alma’s risk management program

  • Collaborate with stakeholders to identify and facilitate the implementation of mitigating controls

  • Streamline and maintain Alma’s security policies and standards

  • Prepare the organization and facilitate annual audits and certifications (SOC 2, PCI)

  • Educate Alma’s staff by creating and managing an effective security awareness program

  • Develop our vendor risk program, ensuring our vendors meet Alma security standards

  • Develop Alma’s Trust program, preparing materials and responses to security assessments, and making security a product differentiator that builds confidence and instills trust in our providers 

  • Develop and measure key metrics, and coordinate activities in support of cybersecurity priorities

Who you are:

  • You have 5+ years of work experience in Information Security, especially in a GRC analysis role

  • You have experience working in health tech or other highly regulated industries (banking, insurance, etc)

  • You have experience leading SOC 2 audits and/or HITRUST certifications with minimal findings

  • You have experience deploying GRC solutions (Drata or equivalent), putting in place a unified control framework enabling evidence collection automation and  continuous compliance  

  • You strongly understand security best practices and controls frameworks (NIST CSF, NIST 800-53, AICPA Trust Services Criteria, HITRUST CSF,  PCI DSS, HIPAA Security Rule, and Breach Notification)

  • You have experience implementing security controls and policies that align with AWS security best practices

  • You have experience driving security awareness programs, including phishing simulation tools (KnowBe4 or equivalent)

  • You have experience performing risk assessments, with an understanding of quantitative risk analysis frameworks (FAIR)

  • You have experience writing customer-facing materials in partnership with with product and marketing teams

  • You have strong written and verbal communication skills and can convey complex technical topics to non-technical stakeholders clearly and concisely

  • You feel a passion for Alma's mission – to improve the experience of therapy for providers and their clients and simplify access to care

Benefits:

  • We’re a remote-first company

  • Health insurance plans through Aetna (medical and dental) and MetLife (vision), including FSA and HSA plans

  • 401K plan (ADP)

  • Monthly therapy and wellness stipends

  • Monthly co-working space membership stipend

  • Monthly work-from-home stipend

  • Financial wellness benefits through Northstar

  • Pet discount program through United Pet Care

  • Financial perks and rewards through BenefitHub

  • EAP access through Aetna

  • One-time home office stipend to set up your home office

  • Comprehensive parental leave plans

  • 11 paid holidays, 1 Alma Mental Health Day, and 1 Alma Volunteering Day

  • Flexible PTO 

Salary Band: $145,000 - $174,000 

Alma’s compensation philosophy is driven by our company value of building equity. To best ensure pay equity, we typically bring in new hires near the middle of our listed salary bands and we do not negotiate our compensation (i.e. all people hired at the same level & role are brought in at the same salary, equity, and benefits). The recruiter you work with can provide more details on our philosophy.

All Alma jobs are listed on our careers page. We do not use outside applications or automated text messaging in our recruiting process. We will not ask for any sensitive financial or identification information throughout the recruiting process. Any communication during the recruitment process, including interview requests or job offers, will come directly from a recruiting team member with a helloalma.com email address.

Apply for this position
Bookmark Report

About the job

Full-time
USA
$145k-$174k per year
1 Applicants
Posted 13 hours ago
security
analyst
compliance
risk management
infosec

Apply for this position

Bookmark
Report
Enhancv advertisement

30,000+
REMOTE JOBS

Unlock access to our database and
kickstart your remote career
Join Premium

Senior Security Governance Risk & Compliance (GRC) Analyst

Alma

Senior Security Governance Risk & Compliance (GRC) Analyst

Alma is seeking a mission-driven Senior Security Governance Risk and Compliance (GRC) Analyst to join our team.  We are dedicated to building secure and compliant tools and services that help providers more easily manage and grow their practice.

Acting as a principal aide to the VP of Security and IT, this role will play a critical role in enabling a culture of security at Alma, making security a product differentiator that builds confidence and trust with our providers, and preparing Alma for annual audits and certifications (such as SOC 2 and HITRUST). In this role you will perform risk assessments, create and maintain our security policies, educate our staff by developing a security awareness program, respond to security assessments, and review our vendor’s security. 

What you’ll do:

  • Perform risk assessments and reports on Alma’s risk management program

  • Collaborate with stakeholders to identify and facilitate the implementation of mitigating controls

  • Streamline and maintain Alma’s security policies and standards

  • Prepare the organization and facilitate annual audits and certifications (SOC 2, PCI)

  • Educate Alma’s staff by creating and managing an effective security awareness program

  • Develop our vendor risk program, ensuring our vendors meet Alma security standards

  • Develop Alma’s Trust program, preparing materials and responses to security assessments, and making security a product differentiator that builds confidence and instills trust in our providers 

  • Develop and measure key metrics, and coordinate activities in support of cybersecurity priorities

Who you are:

  • You have 5+ years of work experience in Information Security, especially in a GRC analysis role

  • You have experience working in health tech or other highly regulated industries (banking, insurance, etc)

  • You have experience leading SOC 2 audits and/or HITRUST certifications with minimal findings

  • You have experience deploying GRC solutions (Drata or equivalent), putting in place a unified control framework enabling evidence collection automation and  continuous compliance  

  • You strongly understand security best practices and controls frameworks (NIST CSF, NIST 800-53, AICPA Trust Services Criteria, HITRUST CSF,  PCI DSS, HIPAA Security Rule, and Breach Notification)

  • You have experience implementing security controls and policies that align with AWS security best practices

  • You have experience driving security awareness programs, including phishing simulation tools (KnowBe4 or equivalent)

  • You have experience performing risk assessments, with an understanding of quantitative risk analysis frameworks (FAIR)

  • You have experience writing customer-facing materials in partnership with with product and marketing teams

  • You have strong written and verbal communication skills and can convey complex technical topics to non-technical stakeholders clearly and concisely

  • You feel a passion for Alma's mission – to improve the experience of therapy for providers and their clients and simplify access to care

Benefits:

  • We’re a remote-first company

  • Health insurance plans through Aetna (medical and dental) and MetLife (vision), including FSA and HSA plans

  • 401K plan (ADP)

  • Monthly therapy and wellness stipends

  • Monthly co-working space membership stipend

  • Monthly work-from-home stipend

  • Financial wellness benefits through Northstar

  • Pet discount program through United Pet Care

  • Financial perks and rewards through BenefitHub

  • EAP access through Aetna

  • One-time home office stipend to set up your home office

  • Comprehensive parental leave plans

  • 11 paid holidays, 1 Alma Mental Health Day, and 1 Alma Volunteering Day

  • Flexible PTO 

Salary Band: $145,000 - $174,000 

Alma’s compensation philosophy is driven by our company value of building equity. To best ensure pay equity, we typically bring in new hires near the middle of our listed salary bands and we do not negotiate our compensation (i.e. all people hired at the same level & role are brought in at the same salary, equity, and benefits). The recruiter you work with can provide more details on our philosophy.

All Alma jobs are listed on our careers page. We do not use outside applications or automated text messaging in our recruiting process. We will not ask for any sensitive financial or identification information throughout the recruiting process. Any communication during the recruitment process, including interview requests or job offers, will come directly from a recruiting team member with a helloalma.com email address.

Working Nomads

Post Jobs
Premium Subscription
Sponsorship
Free Job Alerts

Job Skills
API
FAQ
Privacy policy
Terms and conditions
Contact us
About us

Jobs by Category

Remote Administration jobs
Remote Consulting jobs
Remote Customer Success jobs
Remote Development jobs
Remote Design jobs
Remote Education jobs
Remote Finance jobs
Remote Legal jobs
Remote Healthcare jobs
Remote Human Resources jobs
Remote Management jobs
Remote Marketing jobs
Remote Sales jobs
Remote System Administration jobs
Remote Writing jobs

Jobs by Position Type

Remote Full-time jobs
Remote Part-time jobs
Remote Contract jobs

Jobs by Region

Remote jobs Anywhere
Remote jobs North America
Remote jobs Latin America
Remote jobs Europe
Remote jobs Middle East
Remote jobs Africa
Remote jobs APAC

Jobs by Skill

Remote Accounting jobs
Remote Assistant jobs
Remote Copywriting jobs
Remote Cyber Security jobs
Remote Data Analyst jobs
Remote Data Entry jobs
Remote English jobs
Remote Spanish jobs
Remote Project Management jobs
Remote QA jobs
Remote SEO jobs

Jobs by Country

Remote jobs Australia
Remote jobs Argentina
Remote jobs Brazil
Remote jobs Canada
Remote jobs Colombia
Remote jobs France
Remote jobs Germany
Remote jobs Ireland
Remote jobs India
Remote jobs Japan
Remote jobs Mexico
Remote jobs Netherlands
Remote jobs New Zealand
Remote jobs Philippines
Remote jobs Poland
Remote jobs Portugal
Remote jobs Singapore
Remote jobs Spain
Remote jobs UK
Remote jobs USA


Working Nomads curates remote digital jobs from around the web.

© 2025 Working Nomads.