Truemed Logo

Truemed

GRC Analyst

Reposted 5 Days Ago
Remote
Hiring Remotely in USA
Senior level
Remote
Hiring Remotely in USA
Senior level
The role involves leading SOC2 Type II compliance, managing security governance and risk, implementing security tools, and responding to incidents while collaborating with cross-functional teams.
The summary above was generated by AI
About Truemed

We’re a payments processing company partnering with health and wellness enterprises that rely on us to handle sensitive payment and health data. Security is at the core of everything we do. We require, and customers expect, SOC2 Type II compliance and rigorous security programs —this role formalizes the security programs we’ve started and will help build a best-in-class security foundation.

This is your chance to shape security at a fast-growing startup from the ground up. If you thrive in autonomous environments, love building programs from scratch, and want to own security initiatives directly impacting revenue, this role is for you.

What You’ll Do
  • Lead SOC2 Type II Compliance – Own the end-to-end process, including risk assessments, audits, and evidence collection.

  • Governance, Risk, and Compliance (GRC) – Respond to customer security questionnaires and build scalable processes to streamline responses.

  • Security Tooling & Implementation – Drive adoption of MDMs, virus scanners, and vulnerability management across our full stack.

  • Incident Response & Risk Mitigation – Develop security monitoring, respond to incidents, and proactively harden our systems before issues arise.

  • Cross-Team Collaboration – Work directly with engineering, sales, and customer success teams

  • Support Security in IT - Manage and enforce that company owned devices are provisioned and secure. Ensure permissions and access are granted when appropriate

What We’re Looking For
  • 5+ years of experience in security engineering, compliance, or security operations.

  • Hands-on experience with SOC2 Type II audits—either leading them or playing a significant role.

  • Strong background in vulnerability management, endpoint security, and secure software development practices.

  • Familiarity with MDMs, antivirus tools, SIEMs, and web security best practices.

  • Experience working with GRC teams and responding to enterprise security questionnaires.

  • Ability to work autonomously and drive initiatives without excessive oversight.

  • Scrappy attitude and a willingness to do the dirty work to make a successful startup

  • Bonus: Experience in payments, fintech, or healthcare security.

Why Join Us?

🚀 Get in on the ground floor – Build security at a company that prioritizes it from day one.

🔑 High autonomy – Own security initiatives and define how security is done at scale.

📈 Growth opportunities – Be the first dedicated security hire with the potential to grow into a leadership role.

💡 Work on impactful problems – Protect sensitive payment and health data while helping close high-value enterprise deals.

🌎 Remote-friendly – Work from anywhere in the US while collaborating with top-tier engineers.

If you're passionate about security and want to shape the future of security at a growing startup, we’d love to hear from you!

Top Skills

Endpoint Security
Mdms
Secure Software Development Practices
Siems
Soc2 Type Ii
Virus Scanners
Vulnerability Management
Web Security Best Practices

Similar Jobs

8 Days Ago
Remote or Hybrid
United States
125K-135K Annually
Mid level
125K-135K Annually
Mid level
Big Data • Marketing Tech • Software
The GRC Analyst will manage risk management, regulatory compliance, audit processes, and IT asset management while collaborating across teams.
Top Skills: IsoMicrosoft Cloud CertificationsNistScfSoc
9 Days Ago
Remote
United States
Mid level
Mid level
Cloud
The Cybersecurity Analyst II - SOC & GRC ensures security and compliance by managing controls, investigating incidents, and performing risk assessments.
Top Skills: Iso 27001Microsoft SentinelNessusNistQualysSplunk
15 Days Ago
Remote
USA
95K-115K Annually
Senior level
95K-115K Annually
Senior level
Artificial Intelligence • Machine Learning • Software • Analytics
The Analyst, GRC - Public Sector will manage compliance operations, oversee vulnerability remediation, and streamline processes for FedRAMP and GovRAMP standards.
Top Skills: Artificial IntelligenceAWSBurp SuiteFedrampGovrampNist Sp 800-53OscalWiz

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account