GoodRx Logo

GoodRx

Lead, Third Party Risk Analyst

Posted Yesterday
Be an Early Applicant
Remote or Hybrid
3 Locations
113K-242K Annually
Senior level
Remote or Hybrid
3 Locations
113K-242K Annually
Senior level
Conduct third party risk assessments, analyze vendor security controls, interpret compliance frameworks, and manage GRC tools for risk management.
The summary above was generated by AI

GoodRx is the leading prescription savings platform in the U.S. Trusted by more than 25 million consumers and 750,000 healthcare professionals annually, GoodRx provides access to savings and affordability options for generic and brand-name medications at more than 70,000 pharmacies nationwide, as well as comprehensive healthcare research and information. Since 2011, GoodRx has helped consumers save nearly $75 billion on the cost of their prescriptions.

Our goal is to help Americans find convenient and affordable healthcare. We offer solutions for consumers, employers, health plans, and anyone else who shares our desire to provide affordable prescriptions to all Americans.

Key Responsibilities:Vendor Security Assessments & Third Party Risk Management
  • Conduct thorough third party risk assessments, evaluating their security controls, compliance with industry standards and risks.
  • Utilize a GRC platform or similar tools to manage and automate third party risk assessments.
    • Evaluate the current third party risk management program, recommend, and implement enhancements in alignment with industry standards. 
  • Analyze third party assessments, security and compliance reports, identifying gaps and potential risks to the organization.
    • Assess data handling, encryption, access controls, incident response and secure software development maturity capabilities as well as other areas of their governance programs in alignment with their specific use cases.
  • Issue, track, and review GoodRx third party security questionnaires and their findings, and follow up on remediation efforts to mitigate identified risks.
Security Framework & Compliance Analysis
  • Interpret and apply security compliance frameworks such as SOC 2, ISO (27001, 22301, 42001, etc.), NIST 800-53, HiTrust, etc.
  • Provide insights and recommendations based on security audits, penetration test reports, and compliance documentation.
  • Ensure vendors maintain security controls that align with the organization's policies and regulatory obligations.
  • Support security audits by providing vendor risk assessment reports and remediation tracking.
Security Tools & Automation
  • Manage and enhance the GRC Platform’s vendor risk management workflows to streamline security assessments.
  • Leverage security tools for risk scoring, threat intelligence, and compliance monitoring.
  • Continuously improve vendor risk assessment methodologies and security controls.
Required Qualifications:
  • +5 years of experience in security risk assessments, vendor security evaluations, or similar compliance roles.
  • Strong experience working with OneTrust or similar GRC (Governance, Risk, and Compliance) tools.
  • Knowledge of SOC 2 Type II, ISO 27001, NIST 800-53, CIS, and other security frameworks.
  • Familiarity with security best practices for cloud services (AWS, Azure, GCP).
  • Understanding of third-party risk management (TPRM) processes.
  • Experience with reviewing security policies, audit reports, and vendor due diligence documentation.
  • Experience with security questionnaires (SIG, CAIQ) and vendor risk scoring methodologies.
Preferred Qualifications:
  • Certifications such as CISA, CISSP, CCSP, ISO 27001 Lead Auditor, CTPRP or CRISC.
  • Experience with automating vendor risk processes in OneTrust, Drata, Archer, or ServiceNow.
  • Knowledge of third-party cybersecurity risk scoring tools (BitSight, SecurityScorecard, RiskRecon).
  • Understanding of supply chain risk management (SCRM) and emerging vendor threats.
Soft Skills:
  • Strong communication skills to collaborate with vendors, security teams, and stakeholders.
  • Detail-oriented mindset to analyze compliance documentation and identify security gaps.

Engineering teams are responsible for supporting appropriate security controls, including management, operational, and technical controls in addition to general GoodRx best practices, such as reading and adhering to the security policies and procedures, being vigilant and observant of potential security threats, etc.

At GoodRx, pay ranges are determined based on work locations and may vary based on where the successful candidate is hired. The pay ranges below are shown as a guideline, and the successful candidate’s starting pay will be determined based on job-related skills, experience, qualifications, and other relevant business and organizational factors. These pay zones may be modified in the future. Please contact your recruiter for additional information.

San Francisco and Seattle Offices:

$151,000.00 - $242,000.00

New York Office:

$139,000.00 - $222,000.00

Santa Monica Office:

$126,000.00 - $202,000.00

Other Office Locations:

$113,000.00 - $182,000.00

GoodRx also offers additional compensation programs such as annual cash bonuses or commission, and annual equity grants for most positions as well as generous benefits. Our great benefits offerings include medical, dental, and vision insurance, 401(k) with a company match, an ESPP, unlimited vacation, 13 paid holidays, and 72 hours of sick leave. GoodRx also offers additional benefits like mental wellness and financial wellness programs, fertility benefits, generous parental leave, pet insurance, supplemental life insurance for you and your dependents, company-paid short-term and long-term disability, and more!

We’re committed to growing and empowering a more inclusive community within our company and industry. That’s why we hire and cultivate diverse teams of the best and brightest from all backgrounds, experiences, and perspectives. We believe that true innovation happens when everyone has a seat at the table and the tools, resources, and opportunities to excel.

With that said, research shows that women and other underrepresented groups apply only if they meet 100% of the criteria. GoodRx is committed to leveling the playing field, and we encourage women, people of color, those in the LGBTQ+ communities, individuals with disabilities, and Veterans to apply for positions even if they don’t necessarily check every box outlined in the job description. Please still get in touch - we’d love to connect and see if you could be good for the role!

GoodRx is committed to providing reasonable accommodations for candidates with disabilities during our recruiting process. If you need any assistance or accommodations due to a disability, please reach out to us at [email protected].

We prioritize candidate safety. Please be aware that all official communication will only be sent from @goodrx.com or [email protected] addresses.

GoodRx is America's healthcare marketplace. The company offers the most comprehensive and accurate resource for affordable prescription medications in the U.S., gathering pricing information from thousands of pharmacies coast to coast, as well as a tele-health marketplace for online doctor visits and lab tests. Since 2011, Americans with and without health insurance have saved $60 billion using GoodRx and million consumers visit goodrx.com each month to find discounts and information related to their healthcare. GoodRx is the #1 most downloaded medical app on the iOS and Android app stores. For more information, visit www.goodrx.com.

Top Skills

AWS
Azure
GCP
Grc
Onetrust

Similar Jobs at GoodRx

Yesterday
Remote or Hybrid
USA
127K-271K Annually
Senior level
127K-271K Annually
Senior level
Consumer Web • Coupons • Healthtech • Social Impact • Pharmaceutical
Lead partnerships with regional and national retail pharmacy chains, driving growth through collaborative planning and execution of initiatives. Manage strategic relationships, negotiate with senior stakeholders, and track KPIs for performance improvement.
Top Skills: Collaboration PlatformsExcelGoogle WorkspacePowerPoint
4 Days Ago
Remote or Hybrid
USA
113K-242K Annually
Senior level
113K-242K Annually
Senior level
Consumer Web • Coupons • Healthtech • Social Impact • Pharmaceutical
Lead the People Analytics function, implementing data-driven strategies and insights to support HR and organizational goals, and enable informed decision-making through analytics.
Top Skills: ExcelSQLTableauVisierWorkday
4 Days Ago
Remote or Hybrid
4 Locations
96K-205K Annually
Senior level
96K-205K Annually
Senior level
Consumer Web • Coupons • Healthtech • Social Impact • Pharmaceutical
The role involves analyzing subscription data, defining performance metrics, collaborating across teams, and presenting actionable insights to drive strategy for subscriptions.
Top Skills: AmplitudeCustomer Data PlatformDatabricksDbtGoogle AnalyticsGoogle Tag ManagerLookerPower BIPythonSQLTableau

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account