Responsibilities
- Act as a hybrid risk specialist and automation developer with a focus on automating compliance and security processes
- Manage and operate the compliance automation platform, including control mapping, evidence gathering, monitoring, and audit coordination
- Conduct risk evaluations, assess third-party security, identify control deficiencies, and oversee remediation efforts
- Maintain comprehensive documentation for controls, policies, procedures, and compliance artifacts across various regulatory standards
- Collaborate with Security, IT, Infrastructure, and Engineering teams to ensure controls meet policy and compliance expectations
- Assist in preparing for and responding to internal and external audits, including SOC 2, HIPAA, and HITRUST
- Lead the maintenance of the organization's cyber risk register and work with stakeholders to assess and mitigate risks
- Create and manage risk dashboards, performance metrics, and executive-level reports using business intelligence tools