Senior Compliance Analyst
EarnestFull Time
Junior (1 to 2 years)
Candidates should have 6+ years of experience leading GRC, IT compliance, security, and risk management projects, along with a strong understanding of various frameworks such as SOC 2, HIPAA, HITRUST, NIST 800-171, ISO27001, ISO27799, CMMC, and FedRAMP. Familiarity with IT environments, cloud environments, security controls, and compliance tooling (e.g., AWS, GCP, GitHub) is required, as well as hands-on experience conducting and leading risk assessments, managing audits, and supporting compliance reporting. Preferred certifications include CGRC, CISA, CRISC, CISSP, or equivalent.
The Senior GRC Analyst will plan and lead strategic GRC initiatives such as attaining industry certification (e.g. SOC 2, HITRUST), as well as tactical initiatives for efficiency and automation. They will also analyze, draft, update, and maintain security and compliance policies, collaborate with Product, Engineering, and Privacy teams to assess security risks in new product features and infrastructure changes, monitor and analyze regulatory changes and industry trends, and perform risk assessments, track remediation efforts, and collaborate with stakeholders to mitigate security and compliance risks.
Wearable health monitoring smart ring
Oura offers a smart ring that tracks various health metrics, including sleep patterns, heart rate variability, and physical activity. The ring uses advanced sensors to collect data, which is then analyzed and displayed through a mobile app, providing users with insights to improve their health and lifestyle. Unlike many competitors, Oura focuses on a direct-to-consumer model, selling its rings through its website and collaborating with sports teams and health institutions for additional partnerships. The goal of Oura is to help users, including athletes and those with health conditions, optimize their health through data-driven insights.