Truemed Logo

Truemed

GRC Analyst

Posted 5 Days Ago
Remote
Hiring Remotely in USA
Senior level
Remote
Hiring Remotely in USA
Senior level
The role involves leading SOC2 Type II compliance, managing security governance and risk, implementing security tools, and responding to incidents while collaborating with cross-functional teams.
The summary above was generated by AI
About Truemed

We’re a payments processing company partnering with health and wellness enterprises that rely on us to handle sensitive payment and health data. Security is at the core of everything we do. We require, and customers expect, SOC2 Type II compliance and rigorous security programs —this role formalizes the security programs we’ve started and will help build a best-in-class security foundation.

This is your chance to shape security at a fast-growing startup from the ground up. If you thrive in autonomous environments, love building programs from scratch, and want to own security initiatives directly impacting revenue, this role is for you.

What You’ll Do
  • Lead SOC2 Type II Compliance – Own the end-to-end process, including risk assessments, audits, and evidence collection.

  • Governance, Risk, and Compliance (GRC) – Respond to customer security questionnaires and build scalable processes to streamline responses.

  • Security Tooling & Implementation – Drive adoption of MDMs, virus scanners, and vulnerability management across our full stack.

  • Incident Response & Risk Mitigation – Develop security monitoring, respond to incidents, and proactively harden our systems before issues arise.

  • Cross-Team Collaboration – Work directly with engineering, sales, and customer success teams

  • Support Security in IT - Manage and enforce that company owned devices are provisioned and secure. Ensure permissions and access are granted when appropriate

What We’re Looking For
  • 5+ years of experience in security engineering, compliance, or security operations.

  • Hands-on experience with SOC2 Type II audits—either leading them or playing a significant role.

  • Strong background in vulnerability management, endpoint security, and secure software development practices.

  • Familiarity with MDMs, antivirus tools, SIEMs, and web security best practices.

  • Experience working with GRC teams and responding to enterprise security questionnaires.

  • Ability to work autonomously and drive initiatives without excessive oversight.

  • Scrappy attitude and a willingness to do the dirty work to make a successful startup

  • Bonus: Experience in payments, fintech, or healthcare security.

Why Join Us?

🚀 Get in on the ground floor – Build security at a company that prioritizes it from day one.

🔑 High autonomy – Own security initiatives and define how security is done at scale.

📈 Growth opportunities – Be the first dedicated security hire with the potential to grow into a leadership role.

💡 Work on impactful problems – Protect sensitive payment and health data while helping close high-value enterprise deals.

🌎 Remote-friendly – Work from anywhere in the US while collaborating with top-tier engineers.

If you're passionate about security and want to shape the future of security at a growing startup, we’d love to hear from you!

Top Skills

Endpoint Security
Mdms
Secure Software Development Practices
Siems
Soc2 Type Ii
Virus Scanners
Vulnerability Management
Web Security Best Practices

Similar Jobs

2 Days Ago
Remote
USA
Mid level
Mid level
Appliances • Industrial
Responsible for governance, risk, and compliance processes, cybersecurity risk assessments, compliance audits, and collaboration with technical teams to ensure adherence to regulatory standards.
Top Skills: CmmcCobitDfarsIso 27001Nist 800-171
2 Days Ago
Remote
United States
Junior
Junior
eCommerce
The GRC & Privacy Analyst will manage compliance tools, support SOC 2 audits, handle vendor risk, and conduct compliance research.
Top Skills: Data Privacy Management Platforms (Osano)ExcelGoogle SheetsGrc Platforms (Drata)
5 Days Ago
Remote
United States
135K-190K
Senior level
135K-190K
Senior level
Fintech • Real Estate • Software
The Senior GRC Analyst will support governance, risk management, and compliance processes, developing policies, managing risks, and ensuring compliance with frameworks like SOC2 and ISO 27001.
Top Skills: Grc FrameworksIso 27001Soc2

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account