Senior GRC / Third-Party Risk / Data Protection Analyst

Peraton

$104K — $166K *
US-AnywhereRemote in United States
Healthcare
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in information systems, cybersecurity, or business with a focus on security; 4 additional years of experience can substitute for a degree.
  • 8+ years in security governance, risk, and compliance (GRC), third-party risk management, or data protection.
  • Active CISA or CGRC certification required.
  • Experience in control assessment and gap analysis against NIST SP 800-53 Rev. 5, managing the POA&M lifecycle.
  • Demonstrated experience in vendor security risk management, including the use of assessment frameworks.
  • Hands-on experience with data classification and enterprise DLP tools such as Microsoft Purview or Netskope.
  • Strong compliance writing skills for policies, control narratives, and deficiency documentation.

Responsibilities

  • Own and update security policy and control documents.
  • Perform control testing and manage the POA&M from identification to closure.
  • Ensure the program remains audit-ready at all times with clear evidence documents.
  • Conduct comprehensive third-party security risk evaluations and continuous monitoring.
  • Take lead on data protection initiatives, including data cataloging and DLP implementation.
  • Contribute to the development of insider threat monitoring and response procedures.
  • Support compliance with IRS Publication 1075 and other data privacy obligations.

Benefits

  • Comprehensive health, dental, and vision insurance.
  • 401(k) plan with company match.
  • Professional development opportunities and certifications reimbursement.
  • Flexible work arrangements and paid time off.
  • Employee assistance program and wellness initiatives.
Full Job Description
Responsibilities

**Position Is Contingent Upon Award**

Peraton Labs is hiring a Senior GRC / Third-Party Risk / Data Protection Analyst to own the governance, risk, and compliance engine of the engagement — policy, control testing, and POA&M management — together with third-party security risk management and the data protection and insider threat program for the California health benefit exchange and the CalHEERS eligibility and enrollment system.

You will work with Covered California security leadership and privacy stakeholders, vendors and their security teams, our on-site security engineering and incident response colleagues, and the independent assessment team, for whom you are the operational-side evidence provider. The goal is that the program's compliance posture against NIST SP 800-53 Rev. 5, ARC-AMPE, and IRS Publication 1075 is real, evidenced, and audit-ready on any given day rather than reconstructed once a year.

What You Will Do In This Role:

  • Own policy and control documentation. Author and maintain security policies, procedures, standards, plans, and control documentation for the environment.
  • Test controls and close POA&Ms. Perform control testing and gap analysis against NIST SP 800-53 Rev. 5, document deficiencies, and manage POA&Ms through remediation and verified closure.
  • Keep the program audit-ready. Maintain the control evidence library and GRC platform records, control mappings, and compliance reporting; support the annual independent assessment as the operational-side evidence provider, without acting as an assessor.
  • Run third-party security risk management. Conduct vendor security due diligence and assessments, contract and control reviews, continuous monitoring, and risk reporting.
  • Lead data protection. Discover and catalog confidential data, define and apply the data classification scheme, and implement protective controls including DLP, encryption, and access controls.
  • Support the insider threat program. Contribute to insider threat use cases, monitoring, and escalation procedures in coordination with privacy, HR, and legal stakeholders.
  • Carry the regulated-data obligations. Support IRS Publication 1075 and ARC-AMPE compliance activities and the privacy obligations of the contract's Privacy Addendum; participate in the on-call incident response rotation.
Qualifications

Required:

  • Bachelor's degree in information systems, cybersecurity, or business with a security concentration. In lieu of a degree, an additional 4 years of relevant experience will be considered.
  • 8+ years of experience in security governance, risk, and compliance, third-party risk management, or data protection.
  • Active CISA or CGRC certification.
  • Demonstrated experience performing control assessment and gap analysis against NIST SP 800-53 Rev. 5, and managing the POA&M lifecycle from deficiency identification through closure.
  • Demonstrated third-party and vendor security risk management experience, including questionnaire-based assessment frameworks such as SIG or CAIQ, contract and control review, and continuous monitoring.
  • Hands-on experience with data classification and data-flow mapping, and with an enterprise DLP platform such as Microsoft Purview, Netskope, or Forcepoint.
  • Precise compliance writing ability — policies, control narratives, and deficiency write-ups that withstand external review — and working knowledge of an enterprise GRC platform.
  • US Citizenship and the abillity to pass a California criminal background clearance (Gov. Code a71043 / 10 CCR a76456) before starting work or accessing any confidential information, PII, PHI, federal tax information, or financial information.

Desired:

  • CIPP/US certification. CRISC, CIPT, or CISM are also valued.
  • Experience with ARC-AMPE security and privacy requirements.
  • Experience with IRS Publication 1075 and FTI safeguarding, including participation in a Safeguard Review.
  • Working knowledge of HIPAA/HITECH and the California Consumer Privacy Act.
  • Experience with CMS requirements and Authority to Connect support, including Security Assessment Workbooks (SAWs), security assessment reports, and control evidence packages.
  • Experience in California state government compliance environments.
  • Experience with health benefit exchange or Medicaid eligibility systems.
  • Experience with encryption and key management concepts and with insider threat program design.
Target Salary Range$104,000 - $166,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individuale28099s experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

Similar Jobs

More Jobs at Peraton

More Healthcare Jobs

Find similar Senior GRC / Third-Party Risk / Data Protection Analyst jobs: