Jobs and Careers
EV

Senior Analyst, Governance Risk & Compliance

Evolent
Work at Home, United States, United Statesfull_timeVerifiedPosted 14 Feb 2025
💰 $131,800/yr($110,000/yr$131,800/yr)

About the role

Your Future Evolves Here

Evolent partners with health plans and providers to achieve better outcomes for people with most complex and costly health conditions. Working across specialties and primary care, we seek to connect the pieces of fragmented health care system and ensure people get the same level of care and compassion we would want for our loved ones.

Evolent employees enjoy work/life balance, the flexibility to suit their work to their lives, and autonomy they need to get things done. We believe that people do their best work when they're supported to live their best lives, and when they feel welcome to bring their whole selves to work. That's one reason why diversity and inclusion are core to our business.

Join Evolent for the mission. Stay for the culture.

What You’ll Be Doing:

Value Proposition Statement: Join our dynamic Information & Cyber Security team as a Senior Governance Risk and Compliance (GRC) Analyst and contribute to reducing risk and improving the company's security posture. You will be the focal point for all healthcare compliance activities, ensuring the company meets HIPAA, HITECH, contractual requirements, and relevant state laws. Additionally, you will work on AI compliance and develop new capabilities to enhance our security framework.

Collaboration Opportunities: You will work closely with key stakeholders across the company and its affiliates daily, including IT, legal, and operational teams. This role offers ample opportunities for teamwork and collaboration to enhance our security and compliance efforts.

What You Will Be Doing:

  • Lead and participate in compliance audits: Oversee annual internal and external audits, including ISO, HIPAA, SOC, and HITRUST requirements.
  • Audit and evaluate security practices: Audit applications, configurations, and internal practices against standards such as HIPAA and HITRUST.
  • Develop and implement security policies: Collaborate with business units to create and enforce forward-thinking information security policies, standards, and processes.
  • Ensure regulatory compliance: Maintain Evolent Health’s compliance with industry and regulatory requirements, including HIPAA, HITECH, HITRUST, NIST-800-53, and CMMI.
  • Documentation and management: Create and maintain documentation to track, manage, and report on compliance notifications, issues, corrective action plans, and audit results.
  • Perform risk assessments: Conduct continuous gap analysis, identify risks, and perform risk assessments to mitigate potential security threats.
  • Stakeholder collaboration and corrective actions: Work with business units to ensure corrective actions are taken for compliance deficiencies and highlight risks in contractual obligations.
  • Respond to security inquiries and manage third-party risks: Address customer security questionnaires, RFP/RFI’s, and manage Third-Party Risk Management assessments against regulatory requirements, generating monthly compliance reports.
  • AI Compliance: Develop and implement AI compliance frameworks to ensure the ethical and secure use of AI technologies within the organization.
  • Additional Capabilities: Work on enhancing the organization's security capabilities by integrating new technologies and methodologies.
  • Manage Technical Vulnerabilities: Oversee the management of technical vulnerabilities through configuration management using vulnerability management tools like Tenable.io.

Qualifications - Required and Preferred:

  • Mandatory Skills:
  • Knowledge of the latest HITRUST, ISO 27001 standards, SOC 1 & 2 Type 2 audits.
  • Internal and external audit experience of ISO 27001 standards.
  • Knowledge of risk assessment and treatment methods.
  • Strong stakeholder management and excellent written and verbal communication skills.
  • Intermediate knowledge of Excel.

Educational Qualifications/Skills/Experience:

  • 2-3+ years of experience in GRC.
  • Certifications in Information Security: CISM, CRISC, CISA (at least one).
  • Working and implementation knowledge of ISO 27001, HIPAA, and SOC 1 & 2.
  • Experience in the US healthcare business, banking, or regulatory environment.
  • Understanding of various infrastructure security tools/technologies (e.g., firewalls, IPS, endpoint detection and response, identity and access management, vulnerability management, data leakage prevention, application security, cloud security, incident, and threat management).
  • Strong interpersonal skills and ability to communicate effectively with senior management.
  • Good presentation and reporting skills.
  • Self-starter willing to deal with complex situations.

Technical R

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Evolent

View company profile →