Reporting to the Chief Information Security Officer, the Governance, Risk, and Compliance (GRC) Analyst manages the day-to-day operation of CareMetx's governance, risk, and compliance program. This ...
Reporting to the Chief Information Security Officer, the Governance, Risk, and Compliance (GRC) Analyst manages the day-to-day operation of CareMetx's governance, risk, and compliance program. This ...
Information Security Analyst Lead
Fort George G Meade, MD · On-site
$112K - $150K/yr
We are seeking an Information Security Analyst who is responsible for providing security support ... Interpret security risk assessment, review security scan results, assess security vulnerabilities ...
Information Security Analyst Lead
Fort George G Meade, MD · On-site
$112K - $150K/yr
We are seeking an Information Security Analyst who is responsible for providing security support ... Interpret security risk assessment, review security scan results, assess security vulnerabilities ...
Information Security Analyst Lead
Fort George G Meade, MD · On-site
$112K - $150K/yr
We are seeking an Information Security Analyst who is responsible for providing security support ... Interpret security risk assessment, review security scan results, assess security vulnerabilities ...
Information Security Analyst Lead
Fort George G Meade, MD · On-site
$112K - $150K/yr
We are seeking an Information Security Analyst who is responsible for providing security support ... Interpret security risk assessment, review security scan results, assess security vulnerabilities ...
Information Security Analyst Lead
Fort George G Meade, MD · On-site
$112K - $150K/yr
We are seeking an Information Security Analyst who is responsible for providing security support ... Interpret security risk assessment, review security scan results, assess security vulnerabilities ...
Quick apply
Information Security Analyst Lead
Fort George G Meade, MD · On-site
$112K - $150K/yr
We are seeking an Information Security Analyst who is responsible for providing security support ... Interpret security risk assessment, review security scan results, assess security vulnerabilities ...
... Risk Analyst, Cyber Risk Manager, Security Architect, Cybersecurity Engineer, System Security Engineer, etc. DEGREE (Level Desired) Bachelor's Degree DEGREE (Focus) Cybersecurity, Information ...
... Risk Analyst, Cyber Risk Manager, Security Architect, Cybersecurity Engineer, System Security Engineer, etc. DEGREE (Level Desired) Bachelor's Degree DEGREE (Focus) Cybersecurity, Information ...
Tharros is seeking a Senior Information Security Analyst to support the Naval Air Warfare Center ... risk mitigation activities for Navy networks, systems, data, and mission infrastructure. The Senior ...
Tharros is seeking a Senior Information Security Analyst to support the Naval Air Warfare Center ... risk mitigation activities for Navy networks, systems, data, and mission infrastructure. The Senior ...
Description Tharros is seeking a Senior Information Security Analyst to support the Naval Air ... Review vulnerability data, security documentation, risk assessments, and authorization artifacts ...
Description Tharros is seeking a Senior Information Security Analyst to support the Naval Air ... Review vulnerability data, security documentation, risk assessments, and authorization artifacts ...
Introduction As the state's IT leader, DoIT manages information technology and telecommunications ... risk indicators, audit results, audit intake trends, and operational data into actionable analysis ...
Introduction As the state's IT leader, DoIT manages information technology and telecommunications ... risk indicators, audit results, audit intake trends, and operational data into actionable analysis ...
1640 - Information Security Analyst
$85K - $101K/yr
Sigma Defense is currently seeking an Information Security Analyst to work in support of the Army ... Conduct vulnerability assessments, risk analysis, and incident responses. * Actively monitor ...
1640 - Information Security Analyst
$85K - $101K/yr
Sigma Defense is currently seeking an Information Security Analyst to work in support of the Army ... Conduct vulnerability assessments, risk analysis, and incident responses. * Actively monitor ...
1640 - Information Security Analyst
Belcamp, MD · On-site
$85K - $101K/yr
Sigma Defense is currently seeking an Information Security Analyst to work in support of the Army ... Conduct vulnerability assessments, risk analysis, and incident responses. * Actively monitor ...
1640 - Information Security Analyst
Belcamp, MD · On-site
$85K - $101K/yr
Sigma Defense is currently seeking an Information Security Analyst to work in support of the Army ... Conduct vulnerability assessments, risk analysis, and incident responses. * Actively monitor ...
1640 - Information Security Analyst
Belcamp, MD · On-site
$85K - $101K/yr
Sigma Defense is currently seeking an Information Security Analyst to work in support of the Army ... Conduct vulnerability assessments, risk analysis, and incident responses. * Actively monitor ...
Quick apply
1640 - Information Security Analyst
Belcamp, MD · On-site
$85K - $101K/yr
Sigma Defense is currently seeking an Information Security Analyst to work in support of the Army ... Conduct vulnerability assessments, risk analysis, and incident responses. * Actively monitor ...
Role Description * Assist with the collection, analysis, and reporting of security-related data to ... Conduct research and gather information to support policy development, program evaluation, and ...
Role Description * Assist with the collection, analysis, and reporting of security-related data to ... Conduct research and gather information to support policy development, program evaluation, and ...
Role Description * Assist with the collection, analysis, and reporting of security-related data to ... Conduct research and gather information to support policy development, program evaluation, and ...
Role Description * Assist with the collection, analysis, and reporting of security-related data to ... Conduct research and gather information to support policy development, program evaluation, and ...
The ideal candidate is a seasoned analyst with deep expertise in both corporate risk and financial ... Information Security Protect the data and systems of Crisis24 and its stakeholders by adhering to ...
The ideal candidate is a seasoned analyst with deep expertise in both corporate risk and financial ... Information Security Protect the data and systems of Crisis24 and its stakeholders by adhering to ...
Information Security Systems Officer
Annapolis Junction, MD · On-site
$150K - $210K/yr
1 Accord Consulting, LLC is a growing information and technology business founded on the basic ... Support security planning, assessment, risk analysis, and risk management * Identify overall ...
Quick apply
Information Security Systems Officer
Annapolis Junction, MD · On-site
$150K - $210K/yr
1 Accord Consulting, LLC is a growing information and technology business founded on the basic ... Support security planning, assessment, risk analysis, and risk management * Identify overall ...
Information Security Analyst
Bethesda, MD · Hybrid
$83K - $112K/yr
Cyber and IT Risk Management Job Qualifications: Skills: Operating Systems (OS), Security ... No GDIT is looking for a Information Security Analyst to join our National Institutes of Health ...
New
Information Security Analyst
Bethesda, MD · Hybrid
$83K - $112K/yr
Cyber and IT Risk Management Job Qualifications: Skills: Operating Systems (OS), Security ... No GDIT is looking for a Information Security Analyst to join our National Institutes of Health ...
New
Gather and analyze information from multiple Navy and Contractor entities to prepare reports ... Maintain the Program Risk Plan and ISEE Risk Issue, and Opportunity (RIO) register. * Facilitate ...
Gather and analyze information from multiple Navy and Contractor entities to prepare reports ... Maintain the Program Risk Plan and ISEE Risk Issue, and Opportunity (RIO) register. * Facilitate ...
Senior Cybersecurity Analyst / Information Security Manager - To with Security Clearance
Rockville, MD · On-site
$150K - $190K/yr
We are seeking a highly skilled Senior Cybersecurity Analyst / Information Security Manager with expertise in IT security, risk management, and policy development. The ideal candidate will have a ...
Senior Cybersecurity Analyst / Information Security Manager - To with Security Clearance
Rockville, MD · On-site
$150K - $190K/yr
We are seeking a highly skilled Senior Cybersecurity Analyst / Information Security Manager with expertise in IT security, risk management, and policy development. The ideal candidate will have a ...
Delegated Authorizing Official 3 with Security Clearance
Annapolis Junction, MD · On-site
$17.25 - $20.50/hr
... information security controls, and perform and analyze the security risk assessment, risk analysis, risk management process, security control assessments, and awareness activities for systems and ...
Delegated Authorizing Official 3 with Security Clearance
Annapolis Junction, MD · On-site
$17.25 - $20.50/hr
... information security controls, and perform and analyze the security risk assessment, risk analysis, risk management process, security control assessments, and awareness activities for systems and ...
Senior Cybersecurity Analyst / Information Security Manager - Top Secret Clearance
Rockville, MD · On-site
$150K - $190K/yr
We are seeking a highly skilled Senior Cybersecurity Analyst / Information Security Manager with expertise in IT security, risk management, and policy development. The ideal candidate will have a ...
Senior Cybersecurity Analyst / Information Security Manager - Top Secret Clearance
Rockville, MD · On-site
$150K - $190K/yr
We are seeking a highly skilled Senior Cybersecurity Analyst / Information Security Manager with expertise in IT security, risk management, and policy development. The ideal candidate will have a ...
Information Security Risk Analyst information
See Maryland salary details
$31.03 - $34.87
6% of jobs
$34.87 - $38.71
5% of jobs
$38.71 - $42.55
8% of jobs
$44.37 is the 25th percentile. Wages below this are outliers.
$42.55 - $46.38
11% of jobs
$46.38 - $50.22
12% of jobs
The median wage is $53.82 / hr.
$50.22 - $54.06
8% of jobs
$54.06 - $57.90
7% of jobs
$57.90 - $61.74
9% of jobs
$63.48 is the 75th percentile. Wages above this are outliers.
$61.74 - $65.58
17% of jobs
$65.58 - $69.42
8% of jobs
$69.42 - $73.26
7% of jobs
$31
$56
$73
How much do information security risk analyst jobs pay per hour?
What is the difference between Information Security Risk Analyst vs Cybersecurity Analyst?
| Aspect | Information Security Risk Analyst | Cybersecurity Analyst |
|---|---|---|
| Certifications | ISO 27001, CISSP, CISA | CompTIA Security+, CEH, CISSP |
| Work Environment | Risk assessment teams, compliance departments | Security operations centers, incident response teams |
| Employer & Industry Usage | Financial, healthcare, government sectors | Tech companies, cybersecurity firms, enterprises |
While both roles focus on protecting information assets, the Information Security Risk Analyst primarily assesses and manages risks related to information security policies and compliance. In contrast, the Cybersecurity Analyst actively monitors security systems, responds to threats, and handles incidents. Understanding these differences helps organizations assign the right responsibilities and professionals to safeguard their digital assets.
What are the key skills and qualifications needed to thrive as an information security risk analyst, and why are they important?
What is an information security risk analyst?
What does an information security risk analyst do?
As an information security risk analyst, your job is to help assess each potential threat and determine whether or not your current network system suffers from vulnerability to that threat. In this IT role, you may monitor network activity, help implement and manage safety protocols, and research emerging threats to help determine the best response to them. Information security risk analysts often work with many other IT personnel at the same company to manage security needs and, somewhat unusually for an IT role, may also collaborate with outside experts and volunteers to find the best way to counter a particular threat. This is an extremely collaborative position, so the ability to work well with other people, including those you may be meeting for the first time, is essential to your success.
How does an information security risk analyst typically collaborate with other departments to address security risks?

Full-time
Posted 15 days ago
CareMetx rating
5.6
Based on 9 frontline employees who took The Breakroom Quiz
195th of 223 rated it services
Job description
From intake to outcomes, CareMetx is dedicated to delivering industry-leading patient access solutions and support services that help patients quickly start and stay on specialty therapy treatments. We provide scalable, efficient digital hub services for pharmaceutical companies and healthcare providers, streamlining workflows with seamless integration for patient enrollment, consent, and prior authorization. Our best-in-class patient support services enhance every step of care, connecting patients, providers, and brands to drive better outcomes and accelerate time-to-therapy.
Job Title: Governance, Risk, and Compliance (GRC) Analyst
POSITION SUMMARY:
Reporting to the Chief Information Security Officer, the Governance, Risk, and Compliance (GRC) Analyst manages the day-to-day operation of CareMetx’s governance, risk, and compliance program. This role ensures that all HIPAA, SOC 2, and NIST CSF 2.0 controls in the GRC platform maintain current evidence, runs the IT Risk Management process, manages external audits and customer security reviews, and supports the policy and continuity-testing programs. The Governance, Risk, and Compliance Analyst is responsible for the unmonitored (manually collected) controls and the program and process layer of compliance, while the Senior Security Engineer is responsible for the monitored (automated, technical) controls. The role works closely with the CISO, business leaders, and the Executive Leadership Team, and is the organizing force that keeps CareMetx continuously audit-ready in a HIPAA-regulated, PHI-handling environment.
PRIMARY DUTIES AND RESPONSIBILITIES:
Control & Evidence Management (GRC Platform)
- Ensure every HIPAA, SOC 2, and NIST CSF 2.0 control in the GRC platform has current, valid evidence, refreshed at least annually.
- Manage all unmonitored controls — the manually collected items such as policies, procedures, standards, and records — including gathering, uploading, and renewing their evidence on schedule.
- Maintain an evidence calendar so manual controls are refreshed before they expire.
- Maintain a control-ownership matrix recording who is accountable for every compliance item in the GRC platform, and keep it current as people and systems change.
IT Risk Management
- Manage the IT Risk Management process end to end.
- Collect risks from business and functional leaders on a recurring basis and document each in a maintained risk register.
- Work with the CISO to score and prioritize risks using a consistent methodology.
- Track remediation and treatment activity to closure and follow up with risk owners.
- Alert business leaders when risks are untreated, overdue, or trending the wrong way.
- Build and deliver risk reporting and presentations for the Executive Leadership Team.
Audit & Assessment Support
- Coordinate the annual SOC 2 audit and HIPAA assessments: assemble and organize requested evidence.
- Serve as the primary point of contact and manage day-to-day communications with external auditors.
- Maintain year-round audit readiness so audits are a checkpoint, not a fire drill.
Customer Security Reviews
- Complete customer security questionnaires and audit / due-diligence requests accurately and on time.
- Maintain a reusable answer library and keep the customer trust portal content current to reduce one-off effort.
Vendor Risk Management
- Support the vendor management process — confirm that vendors hold SOC 2 or other certifications appropriate to their criticality.
- Report issues, such as a vendor breach or missing certification, to the Vendor Management team.
Policy & Documentation
- Support the CISO and IT in writing, reviewing, and maintaining policies, procedures, and standards.
- Manage the document lifecycle — version control, review cadence, approvals, and publication — and keep policy evidence aligned in the GRC platform.
Continuity & Resilience Testing
- Schedule and coordinate required tests and exercises, including Disaster Recovery (DR), Business Continuity (BCP), and Incident Response (IR) tabletops.
- Track completion, capture results, and file the test evidence against the relevant controls.
Compliance Oversight & Escalation
- Monitor overall compliance posture across the three frameworks and flag gaps early.
- Alert the CISO and management promptly whenever the organization is out of compliance — a control failing, evidence missing or expired, or an owner unresponsive.
Scope & Authority
- Reports to the CISO, with a dotted-line relationship to the Vice President, Compliance & Risk Management; partners with the corporate Compliance and Risk Management teams to support enterprise-wide programs.
- Manages the unmonitored / manually collected control set and the day-to-day operation of the GRC program.
- Authority to require evidence, status updates, and risk submissions from control and risk owners across the business.
- Escalates non-compliance and untreated risk to the CISO and management.
- Other duties as assigned by the CISO.
Qualifications
EXPERIENCE AND EDUCATIONAL REQUIREMENTS:
Required Qualifications
- 5+ years in governance/risk/compliance, IT audit, or security compliance, ideally in a regulated industry.
- Hands-on experience with SOC 2 and the HIPAA Security Rule; working familiarity with NIST CSF 2.0.
- Experience operating a GRC / compliance-automation platform and maintaining control evidence.
- Experience running or supporting a risk management program — risk register, risk scoring, and treatment tracking.
- Experience supporting external audits and completing customer security questionnaires.
Preferred Qualifications
- Healthcare or other PHI / regulated-data environment experience.
- Familiarity with NIST CSF 2.0, NIST 800-53, or HITRUST mappings.
- Experience with a customer trust portal and security-questionnaire automation.
Certifications Preferred (any of the following)
- CISA (Certified Information Systems Auditor).
- CRISC (Certified in Risk and Information Systems Control).
- CGRC (Certified in Governance, Risk and Compliance).
- ISO 27001 Lead Auditor.
- HCISPP (HealthCare Information Security and Privacy Practitioner).
- CompTIA Security+ (foundational security knowledge).
MINIMUM SKILLS, KNOWLEDGE AND ABILITY REQUIREMENTS:
- Strong writing skills for policies and procedures, and clear executive-level reporting and presentation skills.
- Excellent organization, follow-through, and cross-functional communication; able to chase evidence and hold owners accountable diplomatically.
Physical Demands:
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
- While performing the duties of this job, the employee is regularly required to sit.
- The employee must occasionally lift and/or move up to 10 pounds.
Work Environment:
The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions. The noise level in the work environment is usually moderate.
Schedule:
- Must be flexible on schedule and hours.
- Some Travel may be required.
CareMetx considers equivalent combinations of experience and education for most jobs. All candidates who believe they possess equivalent experience and education are encouraged to apply.
At CareMetx we work hard, we believe in what we do, and we want to be a company that does right by our employees. Our niche industry is an integral player in getting specialty products and devices to the patients who need them by managing reimbursements for those products, identifying alternative funding when insurers do not pay, and providing clinical services.
CareMetx is an equal employment opportunity employer. All qualified applicants will receive consideration for employment and will not be discriminated against based on race, color, sex, sexual orientation, gender identity, religion, disability, age, genetic information, veteran status, ancestry, or national or ethnic origin.
Requirements:About CareMetx
Sourced by ZipRecruiter
Industry
It services
Company size
11 - 50 Employees
Headquarters location
Bethesda, MD, US
Year founded
2011