OneStudyTeam

Senior Security Compliance Analyst

OneStudyTeam$110K — $140K *
US-AnywhereRemote in United States
Healthcare
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Information Security, Computer Science, Risk Management, or related field (or equivalent experience)
  • 8+ years of progressive experience in GRC, compliance, or security audit roles
  • Experience in healthcare or regulated industries strongly preferred
  • Certifications such as ISO 27001 Lead Auditor/Implementer, CISSP, CISM, CISA, HITRUST CCSFP, CRISC are strongly preferred
  • Strong understanding of security frameworks including NIST CSF, SOC 2, GDPR
  • Ability to perform risk assessments, policy reviews, and compliance gap analyses

Responsibilities

  • Lead and support customer security audits and respond to security questionnaires
  • Coordinate and manage ISO 27001 audits, including evidence collection and auditor engagement
  • Ensure ongoing compliance with HIPAA, NIST CSF, and other healthcare data security regulations
  • Develop and maintain policies and security documentation to meet regulatory obligations
  • Perform gap analyses and risk assessments to identify compliance risks
  • Manage security governance frameworks to align with best practices
  • Conduct third-party vendor risk assessments to ensure compliance

Benefits

  • Opportunity to drive significant impact in clinical research and patient care
  • Collaborative work environment emphasizing team success
  • Focus on continuous improvement in security governance
  • Engagement with key stakeholders in biopharmaceutical industry
  • Exposure to a diverse set of regulatory and security frameworks
Full Job Description
We are seeking a Senior Security Compliance Analyst with expertise in Governance, Risk, and Compliance (GRC) to support and enhance our security and compliance programs within the healthcare industry. This role is critical in ensuring adherence to industry regulations, responding to customer audits, and maintaining compliance with ISO 27001, HIPAA, and other security frameworks.

The ideal candidate will be a detail-oriented compliance expert who can navigate complex regulatory environments, assist with internal/external audits, and drive continuous improvement in security governance. The ideal candidate must be able to operate independently while delivering on the following duties.
What You'll Be Working On:
  • Lead and support customer security audits, responding to security questionnaires and demonstrating compliance with security frameworks.
  • Prepare, coordinate, and manage ISO 27001 audits, including evidence collection, control implementation, and auditor engagement.
  • Ensure ongoing compliance with HIPAA, NIST CSF, and other regulatory requirements applicable to healthcare data security.
  • Develop and maintain policies, procedures, and security documentation to meet regulatory and contractual obligations.
  • Perform gap analyses and risk assessments to identify and remediate compliance risks.
  • Manage and improve security governance frameworks, ensuring alignment with industry best practices and business objectives.
  • Conduct third-party vendor risk assessments, ensuring compliance with security policies and contractual obligations.
  • Monitor security controls, ensuring effectiveness and continuous improvement in alignment with security frameworks.
  • Support security awareness training initiatives, ensuring employees understand compliance responsibilities.
  • Stay current on ISO 27001, HIPAA, NIST 800-53, and other relevant standards, translating them into actionable security controls.
  • Assist in defining security metrics and reporting on compliance status and risk posture to leadership.
  • Work closely with legal, security, IT, and business teams to align compliance requirements with security operations.
What You'll Bring to OneStudyTeam:

  • Minimum of a Bachelor's degree in Information Security, Computer Science, Risk Management, or related field (or equivalent experience).
  • Minimum 8+ years of progressive experience in GRC, compliance, or security audit roles.
  • Experience in healthcare or regulated industries strongly preferred.
  • Certifications strongly preferred: ISO 27001 Lead Auditor/Implementer, CISSP, CISM, CISA, HITRUST CCSFP, CRISC.
  • Experience leading ISO 27001, SOC2, or HITRUST audits, including ISMS implementation and external audit coordination.
  • Strong understanding of NIST CSF, SOC 2, GDPR, and other security frameworks.
  • Hands-on experience with customer security audits, including responding to security questionnaires and managing security assessments.
  • Ability to perform risk assessments, policy reviews, and compliance gap analyses.
  • Strong written and verbal communication skills, with the ability to explain technical concepts to non-technical stakeholders.
  • Detail-oriented with excellent organizational and project management skills.
  • Ability to work independently and collaboratively in a remote environment.
  • Familiarity with GRC tools (e.g., OneTrust, LogicGate, Archer, Vanta, Drata) is a plus.

The expected pay range for this role is $110,000 - $140,000 USD per year for full time team members.

Note: OneStudyTeam is unable to sponsor work visas at this time. If you are a non-U.S. resident applicant, please note that OneStudyTeam works with a Professional Employer Organization.

As a condition of employment, you will abide by all organizational security and privacy policies.

About OneStudyTeam

OneStudyTeam, a member of the Reify Health family, provides the cloud-based platform StudyTeam to accelerate the development of new and life-saving therapies. StudyTeam brings research site workflows online and enables sites, sponsors, and other key stakeholders to work together more effectively using common technology. The suite of StudyTeam solutions reduces site burden and helps sites pre-screen and enroll more patients, provides sponsors with end-to-end visibility into recruitment activity across all channels, and guides sites in conducting the trial for patients who have been enrolled. StudyTeam is trusted by the largest global biopharmaceutical companies, used in over 5,000 research sites, and is available in over 100 countries. One mission. One team. That’s OneStudyTeam
Learn more about OneStudyTeam
Industry
Founded
2012

Similar Jobs

  • Black & Veatch
    Senior Analyst, GRC
    $85K — $110K *
    Black & Veatch
    Overland Park, KS 66212 (Johnson County)
  • Husch Blackwell
    Conflicts Analyst
    $63K — $128K *
    Husch Blackwell
    Phoenix, AZ 85032 (Maricopa County)
  • Husch Blackwell
    Conflicts Analyst
    $63K — $128K *
    Husch Blackwell
    Los Angeles, CA 90011 (Los Angeles County)
  • Husch Blackwell
    Conflicts Analyst
    $63K — $128K *
    Husch Blackwell
    Providence, RI 02902 (Providence County)
  • Husch Blackwell
    Conflicts Analyst
    $81K — $119K *
    Husch Blackwell
    Washington, DC 20011 (District Of Columbia County)
  • Husch Blackwell
    Conflicts Analyst
    $57K — $110K *
    Husch Blackwell
    Chicago, IL 60629 (Cook County)

More Jobs at OneStudyTeam

More Healthcare Jobs

Find similar Senior Security Compliance Analyst jobs: