freehire launches on Product Hunt on 26 August.

Follow →

GRC Security Analyst

At Curana Health, we're on a mission to radically improve the health, happiness, and dignity of older adults—and we're looking for passionate people to help us do it.

As a national leader in value-based care, we offer senior living communities and skilled nursing facilities a wide range of solutions (including on-site primary care services, Accountable Care Organizations, and Medicare Advantage Special Needs Plans) proven to enhance health outcomes, streamline operations, and create new financial opportunities.

Founded in 2021, we've grown quickly—now serving 200,000+ seniors in 1,500+ communities across 32 states. Our team includes more than 1,000 clinicians alongside care coordinators, analysts, operators, and professionals from all backgrounds, all working together to deliver high-quality, proactive solutions for senior living operators and those they care for.

Ranked #147 on the Inc. 5000 list of America's fastest-growing private companies, we're just getting started. If you're looking to make a meaningful impact on the senior healthcare landscape, you're in the right place—and we look forward to working with you.

For more information about our company, visit CuranaHealth.com.

Summary

Curana Health is seeking an IT Governance, Risk, and Compliance Analyst to join our IT Security and Governance team. In this role, you will help strengthen our security and compliance programs by supporting risk management, audit readiness, policy administration, control monitoring, and regulatory compliance activities. You will work closely with IT, Security, Privacy, Compliance, Legal, and business teams to identify risks, support practical solutions, and help ensure Curana Health continues to meet security and regulatory expectations as we grow.

Who You Are:

You are an IT Governance, Risk, and Compliance professional who enjoys connecting the dots between security requirements, business needs, and practical solutions. With approximately 2–5 years of experience in information security, compliance, risk management, audit, cybersecurity governance, or a related area, you bring a strong interest in identifying risks, improving processes, and helping teams stay audit-ready. You are analytical, detail-oriented, and collaborative, with the ability to communicate clearly with both technical and non-technical stakeholders. You have hands-on experience with activities such as evidence collection, remediation tracking, risk registers, control validation, and compliance documentation. Healthcare experience is highly valued, though candidates from other regulated industries such as financial services, banking, similar highly regulated environments are encouraged to apply. You will thrive in this role if you enjoy working in a fast-moving, growing environment where thoughtful problem-solving, responsible innovation, and continuous improvement are valued.

Essential Duties & Responsibilities

  • Conduct security risk assessments and help document risks, control gaps, and recommended next steps.
  • Support ongoing improvements to Curana Health’s Governance, Risk, and Compliance program.
  • Help maintain security policies, standards, procedures, and guidelines.
  • Coordinate audit and assessment activities, including evidence collection, control validation, documentation, and remediation tracking.
  • Map security controls to frameworks including HIPAA, SOC 2, NIST, CIS, CMS, and URAC.
  • Support compliance monitoring activities and assist with regulatory readiness initiatives.
  • Maintain risk registers, issue logs, corrective action plans, compliance metrics, and governance documentation.
  • Partner with technology teams to address security vulnerabilities, control deficiencies, and compliance gaps.
  • Participate in risk intake, assessment, prioritization, escalation, and ongoing monitoring activities.
  • Support third-party risk management and vendor security review processes.

Qualifications

Required Qualifications

  • Bachelor’s degree in Information Security, Cybersecurity, Information Technology, Computer Science, Healthcare Informatics, or a related field; equivalent experience will also be considered.
  • 2–5 years of experience in GRC, information security, risk management, audit, compliance, cybersecurity, or a related function.
  • Experience supporting risk assessments, compliance reviews, audits, control testing, or governance activities.
  • Experience working in a regulated industry or compliance-driven environment.
  • Knowledge of the HIPAA Security Rule.
  • Understanding of information security governance, risk management, and compliance concepts.
  • Strong analytical, organizational, and problem-solving skills.
  • Excellent written and verbal communication skills.
  • Ability to manage multiple priorities and deadlines in a fast-paced environment.

Preferred Qualifications

  • Healthcare industry experience.
  • Knowledge of the HIPAA Privacy Rule.
  • Experience with frameworks such as HIPAA, SOC 2, NIST Cybersecurity Framework, CIS Controls, CMS, URAC, HITRUST, or ISO 27001.
  • Experience with third-party risk management programs.
  • Experience with GRC platforms such as ServiceNow GRC, Archer, OneTrust, AuditBoard, LogicGate, or similar solutions.
  • Experience supporting AI governance, emerging technology risk reviews, or security governance initiatives.

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available