Collective Health

Lead Security Analyst-GRC

Collective Health$138K — $172K *
Lehi, UT 84043In-Person
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years of experience in cybersecurity, GRC, audit, or risk/compliance roles.
  • Proven experience managing SOC 2 and HITRUST audits in cloud-native environments.
  • Strong knowledge of security frameworks (NIST, CIS, HIPAA) and regulatory requirements.
  • Demonstrated abilities in policy creation, data management, and risk mitigation.
  • Familiarity with GRC tools and audit processes.
  • Excellent communication and collaboration skills across different business functions.

Responsibilities

  • Evaluate and implement security controls based on various compliance frameworks.
  • Develop and document essential policies, procedures, and controls.
  • Lead SOC 2 and HITRUST audit engagements from planning to remediation.
  • Coordinate third-party risk assessments and compliance reviews.
  • Manage Business Continuity Planning (BCP) and Business Impact Assessments (BIA).
  • Conduct audit readiness assessments and support both internal and external audits.
  • Act as a liaison between technical teams and non-technical stakeholders.

Benefits

  • Health insurance coverage.
  • 401(k) plan with company matching.
  • Generous paid time off policy.
  • Stock options (205,000 options offered).
  • Flexible hybrid working model with in-office requirements.
Full Job Description
As our Lead Security Analyst - GRC, you'll lead initiatives that address the company's-and some of our industry's-most sophisticated and meaningful security engineering challenges. You will build relationships across all parts of the business and drive multi-functional initiatives to continuously improve our security and privacy posture. You will be responsible for building and implementing controls that can scale and optimize as we move into a context-aware security environment. **What you'll do:** **Governance & Compliance:** Evaluate and implement security controls based on frameworks such as NIST, CIS, HIPAA, SOC 2, and HITRUST.Develop and maintain policies, procedures, and documentation (controls, narratives, matrices).Lead SOC 2 and HITRUST audit engagements, from audit planning through remediation.Coordinate and monitor third-party risk assessments and compliance reviews.Own and lead BCP (Business Continuity Planning) and BIA (Business Impact Assessments) efforts.Build and maintain security risk registry **Audit & Risk Management:** Perform audit readiness assessments, and support internal/external audits.Partner with external auditors, control owners, and leadership to minimize business disruption.Track and drive remediation plans based on audit findings and compliance gaps.Maintain and communicate exception documentation for policy deviations.Educate and guide control/risk owners on their responsibilities. **Advisory & Communication:** Act as a liaison between technical and non-technical stakeholders.Respond to security questionnaires, RFIs, and client compliance inquiries.Develop and deliver security awareness and training programs.Provide executive reporting on program status, risks, and overall health. **To be successful in this role, you'll need:** **Required:** 8+ years in cybersecurity, GRC, audit, or risk/compliance roles.Experience managing SOC 2 / HITRUST audits, especially in cloud-native environments.Strong working knowledge of security frameworks and regulatory requirements.Demonstrated policy, data management, and risk mitigation capabilities.Familiarity with GRC tools and audit processes.Excellent communication and cross-functional collaboration skills. **Preferred (Nice to Haves):** Big 4 accounting firm background.Professional certifications: CISSP, CISA, CRISC, CISM, or similar. **Pay Transparency Statement** This is a hybrid position based out of one of our offices: Plano, TX, or Lehi, UT. Hybrid employees are expected to be in the office two days per week.#LI-hybrid The actual pay rate offered within the range will depend on factors including geographic location, qualifications, experience, and internal equity. In addition to the [salary/hourly rate], you will be eligible for 205,000 stock options and benefits like health insurance, 401k, and paid time off. Learn more about our benefits at https://jobs.collectivehealth.com/benefits/. San Francisco, CA Pay Range $172,500-$215,625 USD Lehi, UT Pay Range $138,000-$172,500 USD Plano, TX Pay Range $151,800-$189,750 USD

About Collective Health

Collective Health is a technology company that provides a cloud-based platform for self-insured employers to manage their employee health benefits. The platform includes tools for plan design, enrollment, claims processing, and member engagement. Collective Health was founded in 2013 and is headquartered in San Francisco, California. The company has raised over $400 million in funding and has partnerships with several major insurance carriers, including Aetna, Cigna, and Anthem.
Learn more about Collective Health
Size
500 employees
Industry
Founded
2013

Similar Jobs

More Jobs at Collective Health

More Information Technology Jobs

Find similar Lead Security Analyst-GRC jobs: