Sr. GRC Analyst
Aya Healthcare · Remote
📍 Remote, US💰 $105,000 to $135,000via greenhousePosted 2026-09-02
Apply on company site ↗
Career Moonshot pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to Aya Healthcare.
Join Aya Healthcare, winner of multiple Top Workplace awards!
We are seeking a Senior Governance, Risk & Compliance (GRC) Analyst to help operate and mature Aya’s enterprise GRC program, with a strong emphasis on compliance automation, scalability, and operational excellence. In this role, you will own GRC projects and deliverables across the organization while serving as a subject-matter expert in compliance operations, risk management, and ServiceNow GRC / IRM.
This is a hands-on opportunity for someone energized by improving modern GRC capabilities and moving away from manual, point-in-time audit work toward automated, continuously operating compliance processes.
You will work cross-functionally across Information Security, IT, Legal, Privacy, Engineering, Finance, and Audit to translate regulatory and framework requirements into practical controls, improve evidence collection and reporting, and deliver clear, actionable insights to stakeholders and leadership.
You will work in the Security organization and report to the Manager, Governance, Risk & Compliance.
This role is remote and will work PST business hours.
Who We Are:
We’re an $8+ billion, rapidly growing workforce solutions provider in the healthcare industry. We deliver tech-enabled services that help healthcare organizations meet and manage their contingent labor needs. We build and manage tech-enabled marketplaces for national and local healthcare talent and deliver contingent labor management solutions through our proprietary software platform.
At Aya, we’re obsessed with creating exceptional experiences for our clients, clinicians, and employees. In fact, we put employee satisfaction above all else. Our team members are responsible for incomparable customer experience and we know that happy employees are critical to maintaining happy clients. We foster an entrepreneurial, high-energy, low-bureaucracy culture and value innovative thinking and creative problem-solving. We embrace diversity in thought and backgrounds unified by a commitment to high achievement. When you join Aya, you’ll be surrounded by teammates who care about you as an individual and leaders who will help you grow both personally and professionally.
Responsibilities:
Own assigned GRC projects, compliance deliverables, and process improvements from planning through completion.
Support the day-to-day operation and continuous improvement of Aya’s enterprise GRC program.
Design and improve scalable workflows that translate regulatory and framework requirements into clear control activities and operational responsibilities.
Support compliance efforts for SOC 2 and ISO/IEC 27001:2022, including readiness activities, audit preparation, evidence coordination, control testing, auditor support, and remediation tracking.
Establish and maintain clear control ownership, traceability, documentation, and evidence requirements.
Identify opportunities to replace manual or spreadsheet-driven compliance activities with automated, system-driven processes.
Improve automated evidence collection, control testing, issue and remediation tracking, dashboards, and reporting.
Conduct control reviews, risk assessments, evidence evaluations, and compliance gap analyses.
Monitor remediation activities, follow up with control owners, identify delivery risks, and escalate issues when appropriate.
Build and maintain dashboards, metrics, and reports that communicate compliance status, trends, exceptions, risks, and remediation progress.
Partner with ServiceNow platform and engineering teams to ensure GRC solutions are scalable, supportable, and aligned with enterprise processes.
Engage with customers to respond to compliance, security, privacy, and risk-related questions in RFPs, due diligence requests, contracts, and customer meetings.
Collaborate with Security, IT, Engineering, Finance, Legal, Privacy, Internal Audit, and business stakeholders to resolve control and compliance issues.
Translate risk and compliance requirements into clear, business-relevant guidance that enables teams to take action.
Lead working sessions, walkthroughs, and process discussions with control owners and subject-matter experts.
Identify emerging risks, process dependencies, and long-term improvement opportunities within the GRC domain.
Guide and support junior analysts and teammates through collaboration, knowledge sharing, and example.
Review work products for accuracy, completeness, and alignment with established quality standards.
Document process improvements, design decisions, procedures, and lessons learned.
Required Qualifications:
4+ years of experience in Governance, Risk, and Compliance, Information Security, IT Audit, or a related discipline.
Hands-on experience operating or configuring GRC tools such as ServiceNow GRC / IRM, Drata, Vanta, or Hyperproof to automate and manage compliance workflows.
Demonstrated experience owning GRC projects, compliance deliverables, or process-improvement initiatives from planning through completion.
Strong working knowledge of SOC 2 or ISO/IEC 27001:2022. Familiarity with HIPAA and other healthcare-related compliance requirements is preferred.
Experience with control design, evidence evaluation, risk assessments, audit support, remediation tracking, or compliance testing.
Experience improving manual compliance processes through automation, workflow design, or system-based reporting.
Strong written and verbal communication skills, with the ability to explain risk and compliance concepts to both technical and non-technical audiences.
Demonstrated ability to work independently, manage competing priorities, anticipate next steps, and escalate risks early.
Experience collaborating across Information Security, IT, Engineering, Legal, Privacy, Finance, Audit, and business teams.
Bachelor’s degree in IT / CS is preferred.
CISA, CISSP (or CISSP Associate), CCSP, ISO 27001 credential, o
More Remote jobs
Remote jobs · Browse all locations