TherapyNotes, LLC Logo

TherapyNotes, LLC

Senior GRC Analyst

Posted 2 Days Ago
Remote
Hiring Remotely in United States
95K-135K Annually
Senior level
Remote
Hiring Remotely in United States
95K-135K Annually
Senior level
The Senior GRC Analyst will develop GRC strategies, manage risks, ensure compliance, mentor team members, and support cybersecurity audit activities.
The summary above was generated by AI
Description

About Us

TherapyNotes is the go-to superhero for behavioral health Practice Management and EHR software! Our top-notch SaaS solution handles scheduling, billing, documenting, telehealth, and more so clinicians can focus on awesome patient care.

We're a dynamic team of pros who love to innovate and push the envelope, keeping our software cutting-edge. Join us, and let's revolutionize behavioral health software together while making a real difference!

Description

TherapyNotes is seeking an experienced cyber security professional to join our team of technology enthusiasts.  The right candidate should have a focus on cybersecurity compliance, security control implementation, risk/vulnerability management, continuous monitoring, and security awareness training. The role will serve as the liaison for external audits, oversee an internal cybersecurity audit program. This role requires a strong understanding of regulatory requirements, risk management frameworks, and industry best practices.

Responsibilities

  • Develop and implement GRC strategies, policies, and procedures to ensure compliance with regulatory standards and industry best practices.
  • Lead the assessment and management of risks across the organization, including conducting risk assessments, identifying gaps, and developing mitigation plans.
  • Collaborate with cross-functional teams to integrate GRC principles into business processes and systems.
  • Monitor regulatory changes and industry trends to ensure the organization remains compliant and proactive in addressing emerging risks.
  • Provide guidance and training to employees on GRC policies, procedures, and best practices.
  • Support the execution of audits, assessments, and compliance activities through validation of adherence to compliance standards.
  • Mentor and coach GRC analysts, fostering their professional development and growth within the organization.
  • Support the execution and continual improvement of the company’s information security program, with an emphasis on meeting HIPAA-HITECH, state, and GDPR compliance requirements
  • Identify and document cyber risks and manage mitigation, follow up on open security risks, and report issues to leadership
  • Assist with ad-hoc compliance reporting and follow up with customers and/or support partners to ensure all identified vulnerabilities are being addressed
  • Provide support to Information Security Incident Response team during cyber/privacy incidents
  • Validate that information security requirements are built into architectures and new technology projects
  • Ensures the running application and developing codebase protects the confidentiality, integrity, and availability of our customer's data
  • Evaluate the technical security posture of newly proposed third-party solutions.
  • Identify areas of improvement related to third party risk management to drive maturity.

Requirements

  • BS degree in Information Security, Risk Management, Business Administration, or related field
  • 8+ years of experience in GRC, risk management, or related fields.
  • Experience supporting and/or leading audit discussions
  • Certified Information Systems Security Professional (CISSP), Certified Information Security Auditor (CISA), Certified Information Security Manager (CISM) or Certified in Risk and Information Systems Control (CRISC) strongly preferred
  • Strong knowledge of regulatory requirements (e.g., GDPR, HIPAA, PCI-DSS, CPRA) and industry standards (e.g., ISO 27001, NIST).
  • Expert in designing, implementing, and maintaining security solutions
  • Experience developing and implementing GRC frameworks, policies, and procedures
  • Excellent analytical skills with the ability to assess complex risks and develop effective mitigation strategies
  • Exceptional communication and interpersonal skills, with the ability to effectively collaborate with stakeholders at all levels of the organization
  • Proven ability to lead and manage projects, including coordinating cross-functional teams and delivering results on time
  • Ability to adapt to a fast-paced and dynamic environment, with a focus on continuous improvement and innovation
  • Expert in OWASP, CIS and/or other security standards and secure configuration baselines
  • Proficiency with cloud-based solutions and web related technologies

Benefits

  • Competitive salary - $95,000-$135,000
  • Employer sponsored health, dental, vision, life, and disability insurance
  • Retirement plan with company contribution
  • Annual company profit sharing
  • Personal development/training budget
  • Open, collaborative work environment
  • Extensive 2-week onboarding plan
  • Comprehensive mentorship program

Equal Opportunity Employer Statement & Applicant Rights
TherapyNotes LLC is an Equal Opportunity Employer and does not discriminate based on race, color, religion, sex, national origin, age, disability, genetic information, or any other protected status under federal, state, or local law. We are committed to providing a workplace free of discrimination and harassment. For more information about your rights under federal employment laws, please review the following:

If you require a reasonable accommodation during the application process, please contact .

#LI-Remote
#LI-RH1
7/1/2025

Top Skills

Cisa
Cism
Cissp
Cpra
Crisc
Gdpr
Hipaa
Iso 27001
Nist
Owasp
Pci-Dss

Similar Jobs

3 Days Ago
Easy Apply
Remote
United States
Easy Apply
109K-169K
Senior level
109K-169K
Senior level
Security • Software • Cybersecurity • Automation
As a Senior GRC Analyst, you'll enhance Drata's GRC program, manage compliance frameworks, conduct risk assessments, and collaborate on product improvements.
Top Skills: AWSAzureFedrampGCPGdprGrc PlatformsHipaaIso 27001Iso 27017Iso 27018Soc 1Soc 2Soc 3
8 Days Ago
Easy Apply
In-Office or Remote
4 Locations
Easy Apply
163K-192K
Senior level
163K-192K
Senior level
Consumer Web • Healthtech • Professional Services • Social Impact • Software
As a Senior Governance Risk and Compliance Analyst, you'll build and maintain compliance frameworks, coordinate audits, identify risks, and assist in security operations to ensure best practices in security and privacy for Headway.
Top Skills: AWSCeleryCloudflareDatadogFastapiGitKafkaPagerdutyPostgresPython 3ReactRemixSemgrepSnowflakeSqlalchemyTypescript
6 Days Ago
Remote
United States
155K-165K Annually
Senior level
155K-165K Annually
Senior level
Other
The Senior GRC Analyst develops and maintains cybersecurity policies, evaluates compliance, coordinates with teams, and manages risk management processes.
Top Skills: Active DirectoryCcpaGdprMicrosoft EntraNistOffice 365PamPci-DssRapid7Soc 2Sox

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account