A person sitting in a relaxed position in front of a tablet, on a video call with two other people.
Alma Logo

Alma

Senior Security Governance Risk & Compliance (GRC) Analyst

Job Posted 13 Days Ago Posted 13 Days Ago
Remote
Hiring Remotely in United States
145K-174K
Senior level
Remote
Hiring Remotely in United States
145K-174K
Senior level
The Senior Security GRC Analyst will manage risk assessments, security policies, audits, and compliance certifications while promoting a culture of security within Alma.
The summary above was generated by AI

Alma is on a mission to simplify access to high-quality, affordable mental health care. We do this by making it easy and financially rewarding for therapists to accept insurance and offer in-network care. When a provider joins Alma, they gain access to a suite of tools that not only help them better run their business, but also grow it sustainably and develop as a provider. Alma is available in all 50 states, with over 20,000 therapists in our growing network. Anyone looking for a therapist can browse Alma’s free directory. Alma has raised $220.5M in funding from Insight Partners, Optum Ventures, Tusk Venture Partners, Primary Venture Partners, First Round Capital, Sound Ventures, BoxGroup, Cigna Ventures, and Rainfall Ventures. Alma was also named one of Inc’s Best Workplaces in 2022 and 2023.

Website

Job Board

Values

Candidate Interview Guide

Senior Security Governance Risk & Compliance (GRC) Analyst

Alma is seeking a mission-driven Senior Security Governance Risk and Compliance (GRC) Analyst to join our team.  We are dedicated to building secure and compliant tools and services that help providers more easily manage and grow their practice.

Acting as a principal aide to the VP of Security and IT, this role will play a critical role in enabling a culture of security at Alma, making security a product differentiator that builds confidence and trust with our providers, and preparing Alma for annual audits and certifications (such as SOC 2 and HITRUST). In this role you will perform risk assessments, create and maintain our security policies, educate our staff by developing a security awareness program, respond to security assessments, and review our vendor’s security. 

What you’ll do:

  • Perform risk assessments and reports on Alma’s risk management program
  • Collaborate with stakeholders to identify and facilitate the implementation of mitigating controls
  • Streamline and maintain Alma’s security policies and standards
  • Prepare the organization and facilitate annual audits and certifications (SOC 2, PCI)
  • Educate Alma’s staff by creating and managing an effective security awareness program
  • Develop our vendor risk program, ensuring our vendors meet Alma security standards
  • Develop Alma’s Trust program, preparing materials and responses to security assessments, and making security a product differentiator that builds confidence and instills trust in our providers 
  • Develop and measure key metrics, and coordinate activities in support of cybersecurity priorities

Who you are:

  • You have 5+ years of work experience in Information Security, especially in a GRC analysis role
  • You have experience working in health tech or other highly regulated industries (banking, insurance, etc)
  • You have experience leading SOC 2 audits and/or HITRUST certifications with minimal findings
  • You have experience deploying GRC solutions (Drata or equivalent), putting in place a unified control framework enabling evidence collection automation and  continuous compliance  
  • You strongly understand security best practices and controls frameworks (NIST CSF, NIST 800-53, AICPA Trust Services Criteria, HITRUST CSF,  PCI DSS, HIPAA Security Rule, and Breach Notification)
  • You have experience implementing security controls and policies that align with AWS security best practices
  • You have experience driving security awareness programs, including phishing simulation tools (KnowBe4 or equivalent)
  • You have experience performing risk assessments, with an understanding of quantitative risk analysis frameworks (FAIR)
  • You have experience writing customer-facing materials in partnership with with product and marketing teams
  • You have strong written and verbal communication skills and can convey complex technical topics to non-technical stakeholders clearly and concisely
  • You feel a passion for Alma's mission – to improve the experience of therapy for providers and their clients and simplify access to care

Benefits:

  • We’re a remote-first company
  • Health insurance plans through Aetna (medical and dental) and MetLife (vision), including FSA and HSA plans
  • 401K plan (ADP)
  • Monthly therapy and wellness stipends
  • Monthly co-working space membership stipend
  • Monthly work-from-home stipend
  • Financial wellness benefits through Northstar
  • Pet discount program through United Pet Care
  • Financial perks and rewards through BenefitHub
  • EAP access through Aetna
  • One-time home office stipend to set up your home office
  • Comprehensive parental leave plans
  • 11 paid holidays, 1 Alma Mental Health Day, and 1 Alma Volunteering Day
  • Flexible PTO 

Salary Band: $145,000 - $174,000 

Alma’s compensation philosophy is driven by our company value of building equity. To best ensure pay equity, we typically bring in new hires near the middle of our listed salary bands and we do not negotiate our compensation (i.e. all people hired at the same level & role are brought in at the same salary, equity, and benefits). The recruiter you work with can provide more details on our philosophy.

All Alma jobs are listed on our careers page. We do not use outside applications or automated text messaging in our recruiting process. We will not ask for any sensitive financial or identification information throughout the recruiting process. Any communication during the recruitment process, including interview requests or job offers, will come directly from a recruiting team member with a helloalma.com email address.

Learn more about how Alma handles applicant data by reading Alma's Applicant Privacy Notice.

Top Skills

Aicpa Trust Services Criteria
AWS
Hipaa Security Rule
Hitrust Csf
Nist 800-53
Nist Csf
Pci Dss

Similar Jobs at Alma

2 Days Ago
Remote
United States
115K-145K
Mid level
115K-145K
Mid level
Healthtech
The Product Marketing Manager will develop go-to-market strategies, create valuable messaging, and analyze market trends for insurance and billing tools.
Top Skills: B2B2CFintechHealthcareSaaS
2 Days Ago
Remote
United States
85K-110K
Junior
85K-110K
Junior
Healthtech
The FP&A Analyst at Alma will prepare financial reports, participate in budgeting, collaborate across teams, and deliver insights to support decision-making.
Top Skills: Business Intelligence ToolsExcelLightdashSQL
3 Days Ago
Remote
United States
160K-190K
Mid level
160K-190K
Mid level
Healthtech
The Senior Data Scientist will utilize machine learning and analytics to enhance provider-client matching and other business solutions while collaborating cross-functionally.
Top Skills: A/B TestingMachine LearningPythonRSQL

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine
By clicking Apply you agree to share your profile information with the hiring company.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account