Talent.com
Senior Security Compliance Analyst
Senior Security Compliance AnalystOneStudyTeam • Boston, MA, US
Senior Security Compliance Analyst

Senior Security Compliance Analyst

OneStudyTeam • Boston, MA, US
11 days ago
Job type
  • Full-time
Job description

Job Description

Job Description

At OneStudyTeam (a Reify Health company), we specialize in speeding up clinical trials and increasing the chance of new therapies being approved with the ultimate goal of improving patient outcomes. Our cloud-based platform, StudyTeam, brings research site workflows online and enables sites, sponsors, and other key stakeholders to work together more effectively. StudyTeam is trusted by the largest global biopharmaceutical companies, used in over 6,000 research sites, and is available in over 100 countries. Join us in our mission to advance clinical research and improve patient care.

One mission. One team. That's OneStudyTeam.

We are seeking a Senior Security Compliance Analyst with expertise in Governance, Risk, and Compliance (GRC) to support and enhance our security and compliance programs within the healthcare industry. This role is critical in ensuring adherence to industry regulations, responding to customer audits, and maintaining compliance with ISO 27001, HIPAA, and other security frameworks.

The ideal candidate will be a detail-oriented compliance expert who can navigate complex regulatory environments, assist with internal/external audits, and drive continuous improvement in security governance. The ideal candidate must be able to operate independently while delivering on the following duties.

What You'll Be Working On:
  • Lead and support customer security audits, responding to security questionnaires and demonstrating compliance with security frameworks.
  • Prepare, coordinate, and manage ISO 27001 audits, including evidence collection, control implementation, and auditor engagement.
  • Ensure ongoing compliance with HIPAA, NIST CSF, and other regulatory requirements applicable to healthcare data security.
  • Develop and maintain policies, procedures, and security documentation to meet regulatory and contractual obligations.
  • Perform gap analyses and risk assessments to identify and remediate compliance risks.
  • Manage and improve security governance frameworks, ensuring alignment with industry best practices and business objectives.
  • Conduct third-party vendor risk assessments, ensuring compliance with security policies and contractual obligations.
  • Monitor security controls, ensuring effectiveness and continuous improvement in alignment with security frameworks.
  • Support security awareness training initiatives, ensuring employees understand compliance responsibilities.
  • Stay current on ISO 27001, HIPAA, NIST 800-53, and other relevant standards, translating them into actionable security controls.
  • Assist in defining security metrics and reporting on compliance status and risk posture to leadership.
  • Work closely with legal, security, IT, and business teams to align compliance requirements with security operations.
What You'll Bring to OneStudyTeam:
  • Bachelor's degree in Information Security, Computer Science, Risk Management, or related field (or equivalent experience).
  • 8+ years of progressive experience in GRC, compliance, or security audit roles.
  • Experience in healthcare or regulated industries strongly preferred.
  • Certifications strongly preferred: ISO 27001 Lead Auditor/Implementer, CISSP, CISM, CISA, HITRUST CCSFP, CRISC.
  • Experience leading ISO 27001, SOC2, or HITRUST audits, including ISMS implementation and external audit coordination.
  • Strong understanding of NIST CSF, SOC 2, GDPR, and other security frameworks.
  • Hands-on experience with customer security audits, including responding to security questionnaires and managing security assessments.
  • Ability to perform risk assessments, policy reviews, and compliance gap analyses.
  • Strong written and verbal communication skills, with the ability to explain technical concepts to non-technical stakeholders.
  • Detail-oriented with excellent organizational and project management skills.
  • Ability to work independently and collaboratively in a remote environment.
  • Familiarity with GRC tools (e.g., OneTrust, LogicGate, Archer, Vanta, Drata) is a plus.

The expected salary range for this role is $125,000 - $175,000 USD per year for full time team members.

We value diversity and believe the unique contributions each of us brings drives our success. We do not discriminate on the basis of race, sex, religion, color, national origin, gender identity, age, marital status, veteran status, or disability status.

Note: OneStudyTeam is unable to sponsor work visas at this time. If you are a non-U.S. resident applicant, please note that OneStudyTeam works with a Professional Employer Organization.

As a condition of employment, you will abide by all organizational security and privacy policies.

This organization participates in E-Verify (E-Verify's Right to Work guidance can be found here).

Mandatory Employer Disclosures:
Notice to Illinois applicants: Applicants are not obligated to disclose expunged juvenile records or adjudication, arrest, or conviction.
Notice to Connecticut applicants: OneStudyTeam may require applicants to submit to a urinalysis drug test in connection with an application for employment.
Notice to Arizona, Georgia, Indiana, and North Dakota applicants: OneStudyTeam complies with applicable laws prohibiting smoking in and around places of employment.
Notice to Massachusetts applicants: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Notice to Rhode Island applicants: OneStudyTeam complies with Rhode Island law prohibiting smoking in enclosed areas within places of employment. OneStudyTeam is also subject to is subject to Chapters 29–38 of Title 28 of the Rhode Island General Laws.
Notice to Maryland applicants: UNDER MARYLAND LAW, AN EMPLOYER MAY NOT REQUIRE OR DEMAND, AS A CONDITION OF EMPLOYMENT, PROSPECTIVE EMPLOYMENT, OR CONTINUED EMPLOYMENT, THAT AN INDIVIDUAL SUBMIT TO OR TAKE A LIE DETECTOR OR SIMILAR TEST. AN EMPLOYER WHO VIOLATES THIS LAW IS GUILTY OF A MISDEMEANOR AND SUBJECT TO A FINE NOT EXCEEDING $100.

Create a job alert for this search

Senior Security Compliance Analyst • Boston, MA, US

Similar jobs

Senior Analyst, Security Compliance (SOX IT)

CoinbaseBoston, MA, United States
Full-time

Ready to be pushed beyond what you think you’re capable of?.At Coinbase, our mission is to increase economic freedom in the world.It’s a massive, ambitious opportunity that demands the best of us, ...Show more

 • Promoted

Security Compliance Analyst-Intern

EnsonoBoston, MA, United States
Full-time

Security Compliance Analyst-InternRemote - United StatesJR012847.Purpose is to be a relentless ally, disrupting the status quo and unleashing our clients to Do Great Things.We enable our clients to...Show more

 • Promoted

Compliance Senior Associate Anti-Financial Crime (AML/KYC) | Alternative Investment Platform

Origin StaffingCambridge, MA, United States
Full-time

Compliance Senior Associate Anti-Financial Crime (AML/KYC).A leading global private investment firm is seeking a Compliance Senior Associate to support its Anti-Financial Crime (AFC) / KYC program ...Show more

 • Promoted

Cyber Security Analyst

Damco SolutionsWoburn, MA, United States
Full-time

The primary work location for this role will be 400 Presidential Way Woburn MA.The work schedule for this position is 5 DAYS onsite Monday through Friday.ASAP - December 2025 with opportunity for e...Show more

 • Promoted

Senior Security Program Analyst

WHOOPBoston, MA, United States
Full-time

At WHOOP, we are on a mission to unlock human performance and extend healthspan.The security organization supports this mission by protecting the systems, data, and infrastructure that power the pl...Show more

 • Promoted

INFOSEC COMPLIANCE ANALYST III, IS&T Information Security

InsideHigherEdBoston, Massachusetts, United States
Full-time +1

INFOSEC COMPLIANCE ANALYST III, IS&T Information Security.INFOSEC COMPLIANCE ANALYST III, IS&T Information Security.The salary of the finalist selected for this role will be set based on a variety ...Show more

 • Promoted

Senior Compliance Analyst

DraftKingsBoston, MA, United States
Full-time

As a Senior Compliance Analyst, you'll play a key role in strengthening and scaling compliance programs across the Global Compliance & Risk Team.You'll work at the intersection of governance, opera...Show more

 • Promoted

Senior Security Analyst

TeradataBoston, MA, United States
Permanent

At Teradata, we believe that people thrive when empowered with better information.That's why we built the most complete cloud analytics and data platform for AI.By delivering harmonized data, trust...Show more

 • Promoted

Sr. Compensation Analyst

AxonBoston, MA, United States
Full-time

Join Axon and be a Force for Good.At Axon, we're on a mission to Protect Life.We're explorers, pursuing society's most critical safety and justice issues with our ecosystem of devices and cloud sof...Show more

 • Promoted

Senior Risk Analyst

AIGBoston, MA, United States
Full-time

American International Group, Inc.AIG) is a leading global insurance organization.Building on 100 years of experience, today AIG member companies provide a wide range of property casualty insurance...Show more

 • Promoted

Senior Compliance Analyst

Wellington ManagementBoston, MA, United States
Full-time

Wellington Management offers comprehensive investment management capabilities that span nearly all segments of the global capital markets.Our investment solutions, tailored to the unique return and...Show more

 • Promoted

Security Analyst - Tier 2

SevenAIBoston, MA, United States
Full-time

AI is on a mission to put swarming AI agents in the hands of defenders to offload non-human work, shift people up, and finally focus on achieving the security outcomes that teams have been searchin...Show more

 • Promoted

Senior Security Installation Specialist

SiemensCanton, MA, United States
Full-time +1

Here at Siemens, we take pride in enabling sustainable progress through technology.We do this through empowering customers by combining the real and digital worlds.Improving how we live, work, and ...Show more

 • Promoted

Associate Compliance Analyst

The Boston Beer Company, Inc.Boston, MA, United States
Full-time

We are currently hiring a FT Associate Compliance Analyst hybrid in Boston, MA.The Associate Compliance Analyst provides support to obtain commercial approval of alcoholic beverages worldwide with ...Show more

 • Promoted

Senior Compliance Analyst/Compliance Counsel

Audax GroupBoston, MA, United States
Full-time

Founded in 1999, Audax Group is a leading alternative investment manager with offices in Boston, New York, San Francisco, London and Hong Kong.With approximately $42 billion of assets under managem...Show more

 • Promoted

Senior Analyst, Risk and Compliance

PerpetualDorchester, MA, United States
Full-time

A hands-on role, working across core risk and compliance activities in a leading diversified financial services asset management business.Join a highly regarded Chief Risk Office and broaden your i...Show more

 • Promoted

Senior Business Systems Analyst - Workday Security

Northeastern UniversityBoston, MA, United States
Full-time

This job description is intended to describe the general nature and level of work being performed by people assigned to this classification.It is not intended to be construed as an exhaustive list ...Show more

 • Promoted

Senior Risk & Compliance Analyst

Metro Credit UnionChelsea, MA, United States
Full-time

At Metro Credit Union, we're more than a financial institution we're a mission-driven organization committed to empowering our members, supporting our communities, and doing the right thing every d...Show more