USD 172500-215625/yr

Lead Security Analyst-GRC

United StatesUnited States·San Francisco,Lehi,Planolead
Security AnalystCybersecurity
1 views0 saves0 applied

Quick Summary

Key Responsibilities

Governance & Compliance: Evaluate and implement security controls based on frameworks such as NIST, CIS, HIPAA, SOC 2, and HITRUST.Develop and maintain policies, procedures,

Requirements Summary

Big 4 accounting firm background.Professional certifications: CISSP, CISA, CRISC, CISM, or similar. Pay Transparency Statement This is a hybrid position based out of one of our offices: Plano, TX,

Technical Tools
Security AnalystCybersecurity

At Collective Health, we’re transforming how employers and their people engage with their health benefits by seamlessly integrating cutting-edge technology, compassionate service, and world-class user experience design.

As our Lead Security Analyst - GRC, you’ll lead initiatives that address the company’s—and some of our industry’s—most sophisticated and meaningful security engineering challenges. You will build relationships across all parts of the business and drive multi-functional initiatives to continuously improve our security and privacy posture. You will be responsible for building and implementing controls that can scale and optimize as we move into a context-aware security environment.

Responsibilities

~1 min read

Evaluate and implement security controls based on frameworks such as NIST, CIS, HIPAA, SOC 2, and HITRUST.Develop and maintain policies, procedures, and documentation (controls, narratives, matrices).Lead SOC 2 and HITRUST audit engagements, from audit planning through remediation.Coordinate and monitor third-party risk assessments and compliance reviews.Own and lead BCP (Business Continuity Planning) and BIA (Business Impact Assessments) efforts.Build and maintain security risk registry

Perform audit readiness assessments, and support internal/external audits.Partner with external auditors, control owners, and leadership to minimize business disruption.Track and drive remediation plans based on audit findings and compliance gaps.Maintain and communicate exception documentation for policy deviations.Educate and guide control/risk owners on their responsibilities.

Act as a liaison between technical and non-technical stakeholders.Respond to security questionnaires, RFIs, and client compliance inquiries.Develop and deliver security awareness and training programs.Provide executive reporting on program status, risks, and overall health.

8+ years in cybersecurity, GRC, audit, or risk/compliance roles.Experience managing SOC 2 / HITRUST audits, especially in cloud-native environments.Strong working knowledge of security frameworks and regulatory requirements.Demonstrated policy, data management, and risk mitigation capabilities.Familiarity with GRC tools and audit processes.Excellent communication and cross-functional collaboration skills.

Nice to Have

~1 min read

Big 4 accounting firm background.Professional certifications: CISSP, CISA, CRISC, CISM, or similar.

This is a hybrid position based out of one of our offices: Plano, TX, or Lehi, UT. Hybrid employees are expected to be in the office two days per week.#LI-hybrid

The actual pay rate offered within the range will depend on factors including geographic location, qualifications, experience, and internal equity. In addition to the [salary/hourly rate], you will be eligible for 205,000 stock options and benefits like health insurance, 401k, and paid time off. Learn more about our benefits at https://jobs.collectivehealth.com/benefits/.

San Francisco, CA Pay Range
$172,500$215,625 USD
Lehi, UT Pay Range
$138,000$172,500 USD
Plano, TX Pay Range
$151,800$189,750 USD

What We Offer

~1 min read
Mission-driven culture that values innovation, collaboration, and a commitment to excellence in healthcare
Impactful projects that shape the future of our organization
Opportunities for professional development through internal mobility opportunities, mentorship programs, and courses tailored to your interests
Flexible work arrangements and a supportive work-life balance

For more information about why we need your data and how we use it, please see our privacy policy: https://collectivehealth.com/privacy-policy/.

Location & Eligibility

Where is the job
San Francisco, United States
On-site at the office
Who can apply
US

Listing Details

Posted
September 15, 2026
First seen
September 15, 2026
Last seen
September 15, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
60%
Scored at
September 15, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
collective health
Employees
750
Founded
2013
View company profile
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

collective healthLead Security Analyst-GRCUSD 172500-215625