Position Summary
The Federal Exchange GRC Analyst owns federal Health Insurance Exchange and Enhanced Direct Enrollment compliance for the health business, including Audit Readiness Certification and Annual Marketplace Privacy Evaluation obligations and Centers for Medicare and Medicaid Services Direct Enrollment Entity requirements. This is specialist regulatory work with fixed federal deadlines and a direct line to whether the business retains its Exchange connection.
The role sits within Enterprise Compliance and Risk and serves the health segment, maintaining the control set, its evidence, and the audit and attestation cycles that sustain the connection. The ideal candidate has direct federal Exchange, Enhanced Direct Enrollment, or Centers for Medicare and Medicaid Services regulatory experience, disciplined evidence practices, and the ability to manage to an immovable deadline in a fast-moving environment.
Key Responsibilities
- Own Audit Readiness Certification and Annual Marketplace Privacy Evaluation compliance activities and the associated submission cycle
- Own Centers for Medicare and Medicaid Services Direct Enrollment Entity obligations applicable to the Exchange business
- Maintain the Enhanced Direct Enrollment control set, including control descriptions, ownership, testing evidence, and refresh cadence
- Maintain audit-ready evidence in the enterprise GRC platform to support federal and third-party review
- Prepare for and support federal audits, third-party audits, penetration testing coordination, and attestation cycles
- Track federal regulatory change affecting the Exchange environment and translate it into control, process, or documentation change
- Support scope discipline for the Enhanced Direct Enrollment environment so the audited perimeter remains deliberate and defensible
- Coordinate with Cybersecurity, Technology, and the external audit program on evidence collection and control testing
- Partner with the health segment compliance team on operational execution of Exchange requirements
- Track and validate remediation of control gaps and audit findings through to closure
- Report Exchange compliance status, deadlines, and risk into enterprise governance
- Support compliance review of Exchange-related change requests, releases, and vendor dependencies
Required Qualifications
- Bachelor's degree in Business, Health Administration, Information Systems, Public Policy, or a related field
- 5 to 8 years of experience in regulatory compliance, governance risk and compliance, or audit
- Direct experience with federal Exchange, Enhanced Direct Enrollment, or Centers for Medicare and Medicaid Services regulatory requirements
- Working knowledge of control frameworks and evidence standards sufficient to support an external audit
- Demonstrated ability to manage to firm external deadlines with no tolerance for slippage
- Experience coordinating across technology, security, and compliance stakeholders
Skills
- Exceptional attention to detail and documentation discipline
- Strong written communication, including control narratives and regulator-facing documentation
- Ability to interpret federal regulatory guidance and translate it into operational requirements
- Organizational skills sufficient to manage a fixed annual compliance calendar
- Collaborative approach across technical and non-technical stakeholders
- Proficiency in Microsoft Office Suite (Excel, Word, PowerPoint)
- Preferred Qualifications
- Professional certifications such as CISA, CRISC, CHC, or similar
- Healthcare, health insurance, or Centers for Medicare and Medicaid Services compliance background
- Direct Audit Readiness Certification, Annual Marketplace Privacy Evaluation, or Direct Enrollment Entity audit experience
- Experience with enterprise GRC platforms for control and evidence management
- Familiarity with SOC 2, HITRUST, or NIST frameworks
- Experience supporting a technology environment subject to federal connectivity requirements