GRC/IT Compliance Analyst

Cleerly$108K — $130K *
US-AnywhereRemote in United States
Healthcare
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in security or compliance analysis, IT risk assessment, or risk management
  • BS degree in relevant fields like Management Information Systems or Cybersecurity
  • Experience with GRC software implementation
  • Familiarity with FDA regulatory submissions and SaMD regulations
  • Strong understanding of compliance frameworks like ISO 27001 and SOC 2
  • Previous experience in a startup environment
  • Experience with Agile/Scrum methodologies

Responsibilities

  • Build and implement a new enterprise risk assessment platform
  • Continuously monitor and update the risk platform for evolving threats
  • Participate in risk analysis to identify risks to regulated products
  • Evaluate internal controls and recommend improvements
  • Conduct user access reviews for applications
  • Periodically review policies for compliance with best practices
  • Draft documents for FDA regulatory submissions

Benefits

  • XX% target annual bonus
  • Stock options available
  • Comprehensive paid benefits
  • Opportunities for professional growth and training
  • Flexible work environment
  • Collaborative and supportive team culture
Full Job Description
About the Opportunity

Our Information Security team is growing, and we have an immediate opening for a GRC and IT Compliance Analyst to help support and execute Cleerly's security and compliance objectives. Reporting to the Director of Information Security, this role will be a multi-faceted specialist function that focuses on GRC, IT compliance, and risk management, as well as executing on core security-related audits and control assessments. The ideal candidate is a self-motivated individual who is great at task and time management and is willing to learn and adapt to changing regulatory environments.

Responsibilities

You will work closely with our Information Security leadership and cross-functional teams to drive GRC initiatives and ensure the continuous monitoring of security controls. On any given day, you will be:
  • Build and implement a new enterprise risk assessment platform to streamline compliance workflows;
  • Continuously monitor and update the risk platform to reflect evolving threats and regulatory requirements;
  • Participate in risk analysis and features development processes to proactively identify risks to our regulated products;
  • Continuously monitor and evaluate internal controls for areas of improvement;
  • Conduct user access reviews to applications and services;
  • Periodically review policies and procedures for compliance with best practices and compliance frameworks;
  • Assist in owning and drafting documents for FDA regulatory submissions.

Requirements
  • 5-7 years of experience in security or compliance analysis, IT risk assessment, risk management, or assurance/advisory experience over IT/IS general controls;
  • BS degree in Management Information Systems, Computer Science, Accounting with ITGC experience, Engineering, Cybersecurity, Bio-Medical Engineering, or a related field;
  • Experience with GRC software implementation;
  • Experience with FDA regulatory submissions and SaMD (Software as a Medical Device) regulations;
  • Proven experience in enterprise risk management (ERM) frameworks, risk identification, and qualitative/quantitative risk assessment methodologies;
  • Previous experience working within a startup environment;
  • Experience with Agile/Scrum environments and integrating security/compliance into the SDLC;
  • Strong understanding of internal controls necessary to meet compliance frameworks such as ISO 27001, HITRUST, and SOC 2;
  • Excellent verbal and written communication skill sets for addressing security concerns from internal stakeholders within the company.

Impress us more
  • CISA, CISM, CISSP, CRISC, or related certifications;
  • Experience in the digital healthcare industry;
  • Experience with open-source GRC tooling such as CISO Advisor or Eramba is a plus.

Compensation

The base salary range for this role varies by location and is aligned to market benchmarks.
  • Candidates located in higher-cost labor markets, including California, Washington, New York, New Jersey, Connecticut, Massachusetts, and Washington, DC represent the middle to high end of the range, while candidates located in all other U.S. locations represent the low to middle end of the range.
  • Final compensation is determined based on location, experience, skills, and internal equity.

This role is eligible for a XX% target annual bonus, resulting in the following base salary and Total Target Compensation (TTC) ranges:
  • Base Salary: $108,000 - $130,000
  • TTC: $118,800 - $143,000

*Total Target Compensation (TTC): Total Cash Compensation (including base pay, variable pay, commission, bonuses, etc.) Additionally, stock options, paid benefits, and employee perks are part of your total rewards.

Working at Cleerly takes HEART. Discover our Core Values:
  • H: Humility- be a servant leader
  • E: Excellence- deliver world-changing results
  • A: Accountability- do what you say; expect the same from others
  • R: Remarkable- inspire & innovate with impact
  • T: Teamwork- together we win

Don't meet 100 percent of the qualifications? Apply anyway and help us diversify our candidate pool and workforce. We value experience, whether gained formally or informally on the job or through other experiences. Job duties, activities and responsibilities are subject to change by our company.

About Cleerly

Clearly is an online retailer of contact lenses, eyeglasses and sunglasses. The company was acquired by EssilorLuxottica Canada, and is headquartered in Vancouver, British Columbia. They are one of the largest online contact lens retailers in North America, and the largest seller of prescription eyeglasses online in the world. Founded in 2000 as Coastal Contacts by Roger Hardy and his sister Michaela Hardy, who bought the keyword "contact lens" from AltaVista, which meant that all searches for "contact lens" were accompanied with Coastal Contacts' banner ads. In the first day, they had 30 orders; within the first month, they had $68,000 in sales. In addition to their lower pricing, the firm provided same day fulfillment of online orders. In 2004, Coastal Contacts raised $6 million in an initial public offering, which they used to expand into the United Kingdom and parts of Europe. In late 2004, they acquired a mail order contact lens business in Europe, LensWay. In 2006, they acquired two more companies: one in the Netherlands and one in Japan. By 2009, the firm increased their revenue to $140 million. They moved into the eyeglasses market in 2008. They source parts for eyeglasses from independent manufactures across the globe, but maintains control over final assembly.
Learn more about Cleerly

Similar Jobs

More Jobs at Cleerly

More Healthcare Jobs

Find similar GRC/IT Compliance Analyst jobs: