Sr. GRC Analyst
Bamboo HealthAbout the role
Bamboo Health is the leader in Real-Time Care Intelligence™ solutions aimed at improving lives for everyone experiencing physical and behavioral health challenges. We are driven by our mission to empower clients to deliver seamless, high-quality and cost-effective care during pivotal moments to improve health outcomes. From coast to coast, Bamboo Health partners with all major retail pharmacy chains, 52 states and territories, 100% of the top 10 best hospitals and more than half of the country’s largest health plans to improve more than 1 billion patient encounters annually. Join us in improving lives during pivotal care moments!
Summary:
Bamboo Health Security designs forward-thinking security solutions across cloud services, identity and access management, virtualization, and third-party integrations. We focus on innovative, scalable practices that meet complex regulatory requirements and support the company’s growth. Our team is highly collaborative and committed to both business success and individual development.
We are seeking a Senior Governance, Risk and Compliance (GRC) Analyst to help mature our compliance program, contribute to our audit cycles, and serve as the security interface for our customers. You will evaluate risks, conduct internal reviews, respond to customer security questionnaires, review security-relevant contract language, and use AI and automation to improve efficiency and maturity. Through this work, you will demonstrate Bamboo Health's security posture to prospective and existing customers, supporting our deals and ongoing customer relationships.
What You’ll Do:
- Evaluate organizational policies and standards, ensuring that external and internal compliance requirements are met.
- Develop improvements to the compliance program, including the use of AI, automation, and process optimization.
- Review security-relevant language in customer contracts (MSAs, DPAs, BAAs) and RFP/RFI security sections, providing recommendations to Legal and the broader GRC team.
- Respond to customer security questionnaires using AI-assisted tools and trust content, exercising professional judgment to ensure responses are accurate and complete.
- Work with external auditors and customers as necessary, providing them with required information and assistance.
- Maintain and update trust center content and customer-facing security documentation.
- Perform vendor security risk assessments and contribute to the third-party risk management program.
- Assist in policy documentation upkeep and development, ensuring clarity and applicability.
- Monitor and assist with the internal training programs on compliance requirements and best practices.
- Ensure Bamboo Health’s security operations remain aligned with both internal and external compliance requirements, contributing to ongoing internal and external audit reviews.
- Effectively communicate Bamboo Health’s compliance posture to both internal and external stakeholders, offering tangible proof of adherence to policy requirements.
- Partner with the larger Information Security team to identify areas for continuous improvement within the compliance framework.
- Stay curious about emerging AI tools and how they can streamline or enhance work within your function.
What Success Looks Like…
In 3 months…
- Understand and be able to describe Bamboo Health's products, organizational structure, customer base, and compliance landscape (SOC 2, HITRUST, FedRAMP, etc.).
- Develop familiarity with policies, risk register, and trust center content.
- Independently respond to customer security questionnaires using established trust content and AI-assisted tools.
- Independently perform vendor security reviews.
- Build partnership with InfoSec team, Legal, Sales, and key cross-functional partners.
- Incorporate AI-supported tools into your day-to-day work—whether through analysis, documentation, or task management.
In 6 months…
- Actively contribute to audit cycles, including evidence collection and control mapping.
- Own recurring compliance tasks (e.g., periodic access reviews, policy reviews, evidence collection cycles).
- Review security-relevant contract language and RFP security sections, providing actionable recommendations.
- Identify compliance gaps and recommend remedia
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s