Sr Information Security GRC Analyst
Listed on 2026-07-13
-
IT/Tech
Cybersecurity, Information Security, Data Security, IT Consultant
Job Summary
The Senior Information Security GRC Analyst supports and advances Masimo’s enterprise information security governance, risk, and compliance (GRC) program through leadership of security compliance initiatives, third‑party risk management, policy governance, audit readiness, and risk assessment activities. This role partners closely with Information Security, IT, Engineering, Quality, Legal, and business stakeholders to strengthen security governance processes, support regulatory and customer requirements, and maintain alignment with industry frameworks and healthcare security expectations.
The Senior Information Security GRC Analyst contributes to the continuous improvement of governance processes, compliance monitoring, and enterprise risk management activities within a regulated healthcare and medical device environment. This position requires strong knowledge of information security principles, compliance frameworks, and risk management practices, along with the ability to communicate effectively across both technical and non-technical audiences.
- Support the strategic execution and continuous improvement of the enterprise information security governance, risk, and compliance (GRC) program
- Lead coordination of external security audits and certification activities, including HITRUST, ISO 27001, SOC 2, and related compliance initiatives
- Partner with internal stakeholders to gather documentation, evidence, remediation updates, and corrective action plans for audits and assessments
- Conduct third‑party and supply chain cybersecurity risk assessments, including evaluation of vendor security posture, due diligence questionnaires, and supporting security documentation
- Collaborate with business and technical teams to respond to customer security assessments, compliance inquiries, and due diligence requests
- Lead information security risk assessments and track remediation activities through resolution
- Manage the review and tracking of security exceptions and risk acceptance requests, ensuring appropriate compensating controls and approvals are documented
- Assist in the development, maintenance, and communication of information security policies, standards, procedures, and guidelines
- Collaborate with technical teams to evaluate, document, and validate security controls and compliance requirements
- Maintain audit findings, remediation plans, compliance documentation, risk registers, and governance tracking records
- Develop and maintain compliance monitoring processes, governance reporting metrics, dashboards, and ongoing reporting activities
- Conduct internal security assessments, readiness reviews, and governance maturity initiatives
- Support governance and risk management activities related to cloud platforms, SaaS environments, emerging technologies, and evolving cybersecurity threats
- Partner with leadership and cross‑functional stakeholders to promote a risk‑aware security culture and support enterprise governance initiatives
- Stay informed of evolving cybersecurity threats, regulatory requirements, and industry best practices relevant to healthcare and medical device environments
- Support cross‑functional initiatives related to information security awareness, governance, operational maturity, and compliance readiness
- 7+ years of experience in information security governance, risk, and compliance (GRC), cybersecurity risk management, IT audit, compliance, or related areas
- Experience leading or managing security audits or compliance initiatives related to HITRUST, ISO 27001, SOC 2, NIST, or similar frameworks
- Experience conducting third‑party security assessments and vendor risk reviews
- Strong understanding of information security principles, risk management concepts, and security control frameworks
- Ability to understand and discuss technical security concepts including identity and access management (IAM), encryption, vulnerability management, endpoint security, logging/monitoring, cloud security, and network security
- Strong analytical, organizational, documentation, communication, and stakeholder management skills
- Ability to manage multiple priorities and work collaboratively…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).