Sr. Staff Risk Management Analyst
Jobgether · United States · Yesterday
RemoteRemoteFinanceFull-time
About the role
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Sr. Staff Risk Management Analyst based in the United States. This is a senior leadership opportunity to build and operate an enterprise risk management program within a fast-growing, technology-driven healthcare environment.
Responsibilities
- Own and mature the enterprise risk management program, maintaining an enterprise-wide risk register that is distinct from the cyber risk register.
- Develop, refine, and operationalize the enterprise risk appetite statement, ensuring it informs business decisions and priority-setting.
- Establish and operate the ERM policy and enterprise risk assessment methodology, conducting assessments across the organization and maintaining accountability among designated risk owners.
- Present enterprise risk posture, emerging risks, and mitigation progress to executives and the Enterprise Risk Committee.
- Produce governance and risk-assessment evidence supporting security and compliance frameworks, including SOC 2, HITRUST, HIPAA, NIST CSF 2.0, and future control frameworks.
- Govern reporting for the security program portfolio, tracking commitments, dependencies, priority initiatives, delivery risks, and progress against strategic objectives.
- Maintain the multi-year security risk-reduction roadmap and provide regular visibility into progress, dependencies, and areas of concern.
- Own the security organization’s OKRs from definition through measurement, reporting, and follow-up.
- Track critical dependencies and drive priority initiatives through completion, influencing stakeholders across teams without direct authority.
- Build and manage the security awareness program, establishing sustainable processes and recurring communications.
- Manage insurance-related responsibilities, including property and casualty renewals, claims, certificates of insurance, carrier audits, and insurance requirements in customer contracts.
- Extend second-line risk coverage into areas such as pharmacy, financial, and clinical risk in partnership with relevant domain owners.
- Partner with third-party risk and business resilience stakeholders to ensure vendor, concentration, and resilience risks are appropriately represented in the enterprise risk view.
- Automate recurring activities across risk-register maintenance, assessment intake, evidence collection, and reporting to improve efficiency and scalability.
- Support first-line teams during cybersecurity compliance audits and contribute to the continued development of the broader GRC program.
- Identify opportunities to strengthen governance, improve risk visibility, and enable the organization to move quickly while maintaining appropriate controls.
Requirements
- 10+ years of experience in information security, risk management, governance, risk, and compliance (GRC), or a closely related field.
- Demonstrated ownership of a GRC or enterprise risk program, including risk registers, policies, assessment methodologies, and governance processes.
- Hands-on experience conducting risk and control self-assessments (RCSA) or a comparable enterprise risk assessment methodology.
- Proven experience developing and maintaining a multi-year risk-reduction roadmap and reporting progress against strategic objectives.
- Experience preparing and presenting risk reports and recommendations to executive leadership and a board, risk committee, or equivalent governing body.
- Demonstrated ability to establish accountability and drive commitments across teams without relying on direct reporting authority.
- Experience working with security and compliance frameworks such as SOC 2, HITRUST, HIPAA, NIST CSF, or comparable control frameworks.
- Experience serving as the first dedicated full-time owner of a function, operating independently without an established team or dedicated budget structure.
- Strong understanding of enterprise risk, security governance, compliance, controls, and business risk management.
- Excellent executive communication skills, with the ability to translate complex risk information into concise, actionable business insights.
- Strong organizational, analytical, and program management capabilities, with the ability to manage multiple priorities and stakeholders.
- High degree of autonomy, ownership, and initiative, particularly in ambiguous or evolving environments.
- A continuous-improvement mindset and a demonstrated preference for automating repeatable processes wherever practical.
Preferred
- CRISC, CISA, CISSP, or an equivalent professional certification.
- Experience in healthcare or other environments involving highly sensitive or regulated data.
- Experience building AI or agentic AI systems to automate governance intake, evidence gathering, reporting, or related GRC activities.
- Direct involvement in SOC 2, HITRUST, or HIPAA assurance cycles.
- Experience developing a security awareness program from the ground up.
- Experience implementing, owning, or administering a GRC platform.
Benefits
- Medical, dental, and vision insurance plans.
- Flexible Spending Accounts (FSA) and Health Savings Accounts (HSA).
- Flexible paid time off (PTO).
- 401(k) retirement plan with company match.
- Life insurance.
- Pet insurance.
- Additional benefits and support designed to promote employee well-being.
- Opportunity to work in a relatively flat organization with significant autonomy and ownership.
- Collaborative environment that encourages employees to bring forward ideas and drive meaningful initiatives.
- Broad exposure to enterprise risk, security, compliance, and business operations within a growing healthcare technology environment.
- Opportunity to build and shape a function with expanding organizational scope.