Experience using Governance, Risk, and Compliance (GRC) platforms or audit management tools. * Familiarity with cloud environments, information security controls, and third-party risk management.
Experience using Governance, Risk, and Compliance (GRC) platforms or audit management tools. * Familiarity with cloud environments, information security controls, and third-party risk management.
Experience using Governance, Risk, and Compliance (GRC) platforms or audit management tools. * Familiarity with cloud environments, information security controls, and third-party risk management.
Experience using Governance, Risk, and Compliance (GRC) platforms or audit management tools. * Familiarity with cloud environments, information security controls, and third-party risk management.
Compliance Analyst II
Louisville, KY · On-site
Experience using Governance, Risk, and Compliance (GRC) platforms or audit management tools. * Familiarity with cloud environments, information security controls, and third-party risk management.
Compliance Analyst II
Louisville, KY · On-site
Experience using Governance, Risk, and Compliance (GRC) platforms or audit management tools. * Familiarity with cloud environments, information security controls, and third-party risk management.
... * Entry-level experience in compliance or a related field * Willingness to learn new technical ... Knowledge of Risk Models and risk fundamentals Other Requirements * Ability to work extended hours ...
... * Entry-level experience in compliance or a related field * Willingness to learn new technical ... Knowledge of Risk Models and risk fundamentals Other Requirements * Ability to work extended hours ...
Privacy Senior Associate
Lexington, KY · On-site
Demonstrate familiarity with Governance, Risk, and Compliance (GRC) software-preferably ServiceNow ... Acts as a trusted subject-matter contributor rather than an entry-level support role. Privacy by ...
Privacy Senior Associate
Lexington, KY · On-site
Demonstrate familiarity with Governance, Risk, and Compliance (GRC) software-preferably ServiceNow ... Acts as a trusted subject-matter contributor rather than an entry-level support role. Privacy by ...
Privacy Senior Associate
Louisville, KY · On-site
Demonstrate familiarity with Governance, Risk, and Compliance (GRC) software-preferably ServiceNow ... Acts as a trusted subject-matter contributor rather than an entry-level support role. Privacy by ...
Privacy Senior Associate
Louisville, KY · On-site
Demonstrate familiarity with Governance, Risk, and Compliance (GRC) software-preferably ServiceNow ... Acts as a trusted subject-matter contributor rather than an entry-level support role. Privacy by ...
Business Risk Specialist
Owensboro, KY · On-site
$20 - $24.38/hr
The organization's risk management framework is designed to promote strong governance and effective ... compliance, reputational, and strategic risks. Under general supervision, the Business Risk ...
Business Risk Specialist
Owensboro, KY · On-site
$20 - $24.38/hr
The organization's risk management framework is designed to promote strong governance and effective ... compliance, reputational, and strategic risks. Under general supervision, the Business Risk ...
Business Risk Specialist
Owensboro, KY · On-site
$20 - $24.38/hr
The organization's risk management framework is designed to promote strong governance and effective ... compliance, reputational, and strategic risks. Under general supervision, the Business Risk ...
Business Risk Specialist
Owensboro, KY · On-site
$20 - $24.38/hr
The organization's risk management framework is designed to promote strong governance and effective ... compliance, reputational, and strategic risks. Under general supervision, the Business Risk ...
Includes design of the cyber organization, governance, and risk assessments. Qualifications ... including CIS-Risk and Compliance (CIS-RC), CIS-Security Incident Response (CIS-SIR), CIS ...
Includes design of the cyber organization, governance, and risk assessments. Qualifications ... including CIS-Risk and Compliance (CIS-RC), CIS-Security Incident Response (CIS-SIR), CIS ...
Intern - Policy and Procedure
Douglas, KY · On-site
$14 - $18.50/hr
... Risk Management (IRM) system, RSA Archer. The intern will help manage document workflows, track approvals, maintain version control, and ensure compliance with established formatting and governance ...
Intern - Policy and Procedure
Douglas, KY · On-site
$14 - $18.50/hr
... Risk Management (IRM) system, RSA Archer. The intern will help manage document workflows, track approvals, maintain version control, and ensure compliance with established formatting and governance ...
Includes design of the cyber organization, governance, and risk assessments. Qualifications ... including CIS-Risk and Compliance (CIS-RC), CIS-Security Incident Response (CIS-SIR), CIS ...
Includes design of the cyber organization, governance, and risk assessments. Qualifications ... including CIS-Risk and Compliance (CIS-RC), CIS-Security Incident Response (CIS-SIR), CIS ...
... and compliance controls. * Support migration and upgrade tasks alongside senior engineers and ... MRSH) is a global leader in risk, reinsurance and capital, people and investments, and management ...
... and compliance controls. * Support migration and upgrade tasks alongside senior engineers and ... MRSH) is a global leader in risk, reinsurance and capital, people and investments, and management ...
Microsoft 365 Engineer
Louisville, KY · Hybrid
... labeling, compliance policy configuration, data governance, monitoring, and incident response ... Work with security, legal, risk, records management, and business stakeholders to help translate ...
Microsoft 365 Engineer
Louisville, KY · Hybrid
... labeling, compliance policy configuration, data governance, monitoring, and incident response ... Work with security, legal, risk, records management, and business stakeholders to help translate ...
... or entrylevel professional roles. * Basic understanding of data concepts such as data governance ... risk exposure while maximizing the impact of our programs for children and families. Our shared ...
... or entrylevel professional roles. * Basic understanding of data concepts such as data governance ... risk exposure while maximizing the impact of our programs for children and families. Our shared ...
Data Engineer Staff
Lexington, KY · On-site
Standards & Governance • Define and enforce best practice standards, certification processes, and ... Risk & Design Support • Assist early stage risk identification and mitigation for task order ...
Data Engineer Staff
Lexington, KY · On-site
Standards & Governance • Define and enforce best practice standards, certification processes, and ... Risk & Design Support • Assist early stage risk identification and mitigation for task order ...
... governance activities across the Credit Union. Under close supervision, the intern will gain ... Must have a strong interest in information security, risk management or compliance. * Must have ...
... governance activities across the Credit Union. Under close supervision, the intern will gain ... Must have a strong interest in information security, risk management or compliance. * Must have ...
... in compliance with HIPAA. • Documents patient interactions in contact center systems. • Meets entry-level productivity and quality standards for contact center operations. • Performs other ...
... in compliance with HIPAA. • Documents patient interactions in contact center systems. • Meets entry-level productivity and quality standards for contact center operations. • Performs other ...
... in compliance with HIPAA. • Documents patient interactions in contact center systems. • Meets entry-level productivity and quality standards for contact center operations. • Performs other ...
... in compliance with HIPAA. • Documents patient interactions in contact center systems. • Meets entry-level productivity and quality standards for contact center operations. • Performs other ...
... in compliance with HIPAA. • Documents patient interactions in contact center systems. • Meets entry-level productivity and quality standards for contact center operations. • Performs other ...
... in compliance with HIPAA. • Documents patient interactions in contact center systems. • Meets entry-level productivity and quality standards for contact center operations. • Performs other ...
... Governance framework. The Nurse Manager ensures that the Swanson Theory of Caring and patient ... Ensures compliance with regulatory agency standards and policies; supports patient safety and a non ...
... Governance framework. The Nurse Manager ensures that the Swanson Theory of Caring and patient ... Ensures compliance with regulatory agency standards and policies; supports patient safety and a non ...
Entrylevel Governance Risk Compliance information
What is the difference between Entrylevel Governance Risk Compliance vs Entrylevel Internal Auditor?
| Aspect | Entrylevel Governance Risk Compliance | Entrylevel Internal Auditor |
|---|---|---|
| Certifications | ISO 31000, CCPA, GDPR awareness | CPA, CIA, CISA |
| Work Environment | Corporate compliance departments, risk management teams | Internal audit departments, consulting firms |
| Employer & Industry Usage | Financial, healthcare, manufacturing | Financial services, government, consulting |
While both roles focus on organizational integrity, Entrylevel Governance Risk Compliance professionals primarily ensure adherence to regulations and manage risks, whereas Entrylevel Internal Auditors evaluate internal controls and financial accuracy. The GRC role emphasizes compliance frameworks and risk mitigation, while Internal Auditors focus on audit processes and financial integrity.

Full-time
Medical, Retirement, PTO
Posted 13 days ago
Job description
ABOUT THIS POSITION
The Compliance Analyst II plays a key role in supporting and coordinating Waystar's information technology compliance and assurance programs. This position is responsible for managing day-to-day activities related to regulatory and industry assessments, including HITRUST, PCI DSS, SOC 2 / 3 + HIPAA, and TX-RAMP. The Compliance Analyst II serves as a primary liaison between internal stakeholders and external auditors, helping ensure successful completion of assessments and maintaining audit readiness throughout the year.This role requires strong organizational skills, attention to detail, project management capabilities, and the ability to work effectively with technical and non-technical teams across the organization. The Compliance Analyst II is expected to independently manage assigned assessments from planning through completion while supporting broader compliance initiatives as directed by the Manager, IT Compliance.
WHAT YOU'LL DO
Compliance Assessment Management
- Coordinate and manage assigned compliance assessments and audits, including HITRUST, PCI DSS, SOC 2 / 3 + HIPAA, and TX-RAMP.
- Develop and maintain assessment project plans, timelines, request trackers, and status reporting.
- Facilitate audit planning activities, kick-off meetings, stakeholder interviews, walkthroughs, and evidence collection efforts.
- Assign audit requests to appropriate control owners and monitor progress through completion.
- Serve as a primary point of contact for internal teams and external auditors during assessments.
- Maintain ongoing communication with stakeholders regarding audit requirements, deadlines, risks, and remediation efforts.
- Monitor assessment status and escalate issues or delays when necessary.
Audit Readiness & Documentation
- Maintain an audit-ready compliance posture by collecting, organizing, and maintaining evidence throughout the year.
- Develop, review, and update compliance documentation, procedures, narratives, inventories, and process flows.
- Assist with the development and maintenance of policies, standards, and supporting compliance documentation.
- Support continuous monitoring activities designed to maintain compliance with organizational and regulatory requirements.
Cross-Functional Collaboration
- Partner with Information Security, Infrastructure, Engineering, Product Development, Legal, Privacy, Human Resources, Procurement, and other business units to support compliance initiatives.
- Facilitate meetings and communications between internal stakeholders and external assessors.
- Assist process owners in understanding audit requirements and evidence expectations.
- Support remediation efforts by tracking corrective actions and validating completion of assigned tasks.
\Compliance Operations
- Manage and respond to requests submitted through the Compliance team inbox.
- Track and maintain compliance metrics, assessment schedules, documentation inventories, and ongoing compliance activities.
- Support responses to customer and regulatory inquiries related to compliance certifications and attestations.
- Participate in internal process improvement initiatives that increase efficiency and strengthen compliance programs.
WHAT YOU'LL NEED
- Stay current on emerging regulatory requirements, industry frameworks, and compliance best practices.
- Contribute to special projects and strategic initiatives assigned by the Manager, IT Compliance.
- Perform other duties as assigned.
Minimum Qualifications
- Bachelor's degree in Information Systems, Cybersecurity, Business, Risk Management, Compliance, Accounting, or a related field; or equivalent combination of education and experience.
- 2+ years of experience in information technology compliance, audit, risk management, cybersecurity, or a related discipline.
- Experience supporting one or more compliance frameworks including HITRUST, PCI DSS, SOC 2 / 3, HIPAA, TX-RAMP, NIST, or similar regulatory frameworks.
- Experience coordinating audits and working directly with external assessors or auditors.
- Experience managing multiple concurrent projects and competing priorities.
Preferred Qualifications
- Experience managing compliance assessments from planning through final reporting.
- Knowledge of healthcare regulatory requirements and HIPAA security and privacy requirements.
- Experience using Governance, Risk, and Compliance (GRC) platforms or audit management tools.
- Familiarity with cloud environments, information security controls, and third-party risk management.
- Relevant certifications such as:
- HITRUST CCSFP
- CISA
- CRISC
- CISSP
- CIPP/US
- PCI ISA
ABOUT WAYSTAR
Through a smart platform and better experience, Waystar helps providers simplify healthcare payments and yield powerful results throughout the complete revenue cycle.
Waystar's healthcare payments platform combines innovative, cloud-based technology, robust data, and unparalleled client support to streamline workflows and improve financials so providers can focus on what matters most: their patients and communities. Waystar is trusted by 1M+ providers, 1K+ hospitals and health systems, and is connected to over 5K commercial and Medicaid/Medicare payers. We are deeply committed to living out our organizational values: honesty; kindness; passion; curiosity; fanatical focus; best work, always; making it happen; and joyful,optimistic & fun.
Waystar products have won multiple Best in KLAS or Category Leader awards since 2010 and earned multiple #1 rankings from Black Book surveys since 2012. The Waystar platform supports more than 500,000 providers, 1,000 health systems and hospitals, and 5,000 payers and health plans. For more information, visit waystar.comor follow @Waystaron Twitter.
WAYSTAR PERKS
- Competitive total rewards (base salary + bonus, if applicable)
- Customizable benefits package (3 medical plans with Health Saving Account company match)
- We offer generous paid time off for our non-exempt team members, starting with 3 weeks +13 paid holidays, including 2 personal floating holidays. We also offer flexible time off for our exempt team members + 13 paid holidays
- Paid parental leave (including maternity + paternity leave)
- Education assistance opportunities and free LinkedIn Learning access
- Free mental health and family planning programs, including adoption assistance and fertility support
- 401(K) program with company match
- Pet insurance
- Employee resource groups
Waystar is proud to be an equal opportunity workplace. We celebrate, value, and support diversity and inclusion. Qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, national origin, disability status, genetics, marital status, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws.
This applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.