About the job
ABOUT THE ROLE:
Rightway Healthcare is seeking a Senior Security Governance, Risk, and Compliance (GRC) Analyst who is eager to elevate their career within a dynamic healthcare setting. If you have experience managing GRC programs in a fast-paced or startup culture, this is your opportunity to leverage that agility while contributing to a pioneering organization in healthcare. You will play a pivotal role in addressing emerging concerns related to AI risk and governance as we integrate cutting-edge technologies into our platform.
In this position, reporting to the Security GRC Manager, you will be responsible for essential deliverables that ensure the seamless operation of our security and compliance initiatives. Your work will bolster customer assurance, facilitate vendor risk assessments, and manage ongoing governance processes. This role is perfect for someone who thrives in hands-on GRC environments and aspires to grow as a senior individual contributor in a mission-driven organization that is transforming pharmacy benefit management and care navigation.
WHAT YOU’LL DO:
Core GRC Operations
- Oversee and execute regular GRC tasks, including quarterly access reviews, audit evidence collection, and risk register reconciliation.
- Document and monitor the completion of control activities while escalating issues as necessary.
- Support internal and external audits, ensuring timely and comprehensive evidence collection and review.
Customer Assurance
- Collaborate with Sales, Legal, and Product teams to lead responses to customer security inquiries and RFPs, progressively managing more complex requests as your expertise grows.
- Continuously enhance a centralized repository of frequently requested security documentation and artifacts (e.g., SOC 2, SIG, CAIQ).
Vendor Risk Management
- Engage with various business leaders to conduct initial and periodic vendor risk assessments, ensuring third parties align with Rightway's security and compliance standards.
- Track and follow up on remediation and risk treatment plans for vendors that present unacceptable risk.
- Facilitate and promote the automation and optimization of the vendor risk assessment lifecycle using both AI and traditional tools.
AI Governance
- Assist in the implementation and operationalization of AI risk and governance controls in accordance with ISO/IEC 42001 (AI Management System) and newly emerging regulatory standards such as the CAIA (Colorado AI Act).
- Monitor AI systems to ensure compliance with ethical and legal standards.
