Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Lead Governance, Risk, and Compliance Analyst image - Rise Careers
Job details

Lead Governance, Risk, and Compliance Analyst

At Clover, the Business Enablement team leads our technological advancement while ensuring robust security and compliance. We deliver user-friendly corporate applications, manage complex data ecosystems, and provide efficient tech solutions across the organization. Our goal is simple: we make it easy for the business to do what’s right for Clover.

We are looking for a Lead GRC Analyst to build and maintain a strong Cybersecurity Risk Management Program to include managing and reporting on risks introduced by third-parties. You will work closely with various business partners across the organization and report directly to the GRC Manager. 

  As a Lead GRC Analyst you will:

  • Lead risk assessments to identify and prioritize potential security threats, including risk assessments of third parties.
  • Lead compliance engagements and internal audits to monitor compliance with relevant regulatory and industry standards (e.g., HIPAA, CMS, Sarbanes-Oxley, SEC, NIST) and other applicable federal, state, and local laws.
  • Manage and own the security risk register and risk reporting to security leaders.
  • Manage and lead incident investigations to identify root cause and implement preventive measures.
  • Review security policies and standards to ensure alignment with business objectives and regulatory requirements.
  • Understand and communicate security policies and standards to employees and stakeholders.
  • Collaborate with all departments to educate employees on security policies and procedures, promoting a security-conscious culture.
  • Lead completion of security audits of Clover from third parties.
  • Update and administer GRC tools with relevant assessment and risk data.

You will love this job if:

  • You enjoy conducting security risk assessments and working with cross-functional teams.  
  • You are a problem solver. You enjoy tracking down the answers, analyzing data, and ensuring data is accurate and complete. 
  • You are a meticulous record keeper.
  • You are excited to work in a fast-paced and globally distributed organization.
  • You are self motivated and can work independently.

You should get in touch if:   

  • You have 7+ years of experience working in a security risk management role and have a deep comprehension of ePHI. 
  • You have experience conducting internal risk assessments or internal security audits.
  • You have experience conducting internal security assessments and mastery of best practices for risk management.
  • You have a degree and/or training in technology or relevant Security certifications such as CISSP, CISM, CISA, CRISC is preferred. 
  • You have familiarity with control frameworks / regulatory requirements such as, HIPAA, HITRUST, SOx, NIST CSF, NIST 800-53. Healthcare experience is preferred.
  • You have experience working with auditors and/or regulators. 
  • You have the ability to work within a globally distributed organization and understanding of international information security regulations;
  • You have strong written and verbal communication skills and are able to partner and communicate with a range of business professionals.
  • You have experience using and administering automated GRC platforms (such as Onspring) is preferred. 

Benefits Overview:

  • Financial Well-Being: Our commitment to attracting and retaining top talent begins with a competitive base salary and equity opportunities. Additionally, we offer a performance-based bonus program, 401k matching, and regular compensation reviews to recognize and reward exceptional contributions.
  • Physical Well-Being: We prioritize the health and well-being of our employees and their families by providing comprehensive medical, dental, and vision coverage. Your health matters to us, and we invest in ensuring you have access to quality healthcare.
  • Mental Well-Being: We understand the importance of mental health in fostering productivity and maintaining work-life balance. To support this, we offer initiatives such as No-Meeting Fridays, monthly company holidays, access to mental health resources, and a generous flexible time-off policy. Additionally, we embrace a remote-first culture that supports collaboration and flexibility, allowing our team members to thrive from any location. 
  • Professional Development: Developing internal talent is a priority for Clover. We offer learning programs, mentorship, professional development funding, and regular performance feedback and reviews.

Additional Perks:

  • Employee Stock Purchase Plan (ESPP) offering discounted equity opportunities
  • Reimbursement for office setup expenses
  • Monthly cell phone & internet stipend
  • Remote-first culture, enabling collaboration with global teams
  • Paid parental leave for all new parents
  • And much more!

About Clover: We are reinventing health insurance by combining the power of data with human empathy to keep our members healthier. We believe the healthcare system is broken, so we've created custom software and analytics to empower our clinical staff to intervene and provide personalized care to the people who need it most.

We always put our members first, and our success as a team is measured by the quality of life of the people we serve. Those who work at Clover are passionate and mission-driven individuals with diverse areas of expertise, working together to solve the most complicated problem in the world: healthcare.

From Clover’s inception, Diversity & Inclusion have always been key to our success. We are an Equal Opportunity Employer and our employees are people with different strengths, experiences, perspectives, opinions, and backgrounds, who share a passion for improving people's lives. Diversity not only includes race and gender identity, but also age, disability status, veteran status, sexual orientation, religion and many other parts of one’s identity. All of our employee’s points of view are key to our success, and inclusion is everyone's responsibility.


#LI-REMOTE

Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records. We are an E-Verify company.

A reasonable estimate of the base salary range for this role is $100,000 to $130,000. Final pay is based on several factors including but not limited to internal equity, market data, and the applicant’s education, work experience, certifications, etc.


Clover Health Glassdoor Company Review
3.6 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
Clover Health DE&I Review
4.3 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
CEO of Clover Health
Clover Health CEO photo
Andrew Toy
Approve of CEO

Average salary estimate

$115000 / YEARLY (est.)
min
max
$100000K
$130000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Lead Governance, Risk, and Compliance Analyst, Clover Health

At Clover, we're on a mission to transform health insurance by leveraging the power of data and empathetic care. We are seeking a Lead Governance, Risk, and Compliance Analyst to join our dynamic Business Enablement team. This role will be essential in building and maintaining a robust Cybersecurity Risk Management Program, essential for protecting our company and clients. As a Lead GRC Analyst at Clover, you'll spearhead in-depth risk assessments, proactively identifying potential threats—including those from third parties. You’ll also lead compliance efforts, guide internal audits, and ensure alignment with key regulations like HIPAA and NIST standards. Your keen eye for detail will be invaluable as you manage the security risk register and respond to incidents with a focus on preventive measures. This role is not just about compliance; it’s about fostering a security-conscious culture among our diverse teams. Collaborating across departments, you'll have the chance to communicate security policies clearly, ensuring everyone understands their role in safeguarding sensitive information. If you thrive in fast-paced environments and have a knack for problem-solving, this position offers a unique opportunity to make a significant impact on Clover's mission while advancing your career in a supportive, remote-first culture. Join us in delivering better health outcomes and help us keep our members healthier by applying today!

Frequently Asked Questions (FAQs) for Lead Governance, Risk, and Compliance Analyst Role at Clover Health
What are the responsibilities of a Lead Governance, Risk, and Compliance Analyst at Clover?

As a Lead Governance, Risk, and Compliance Analyst at Clover, your core responsibilities will include leading risk assessments to identify and evaluate security threats, managing compliance engagements and internal audits, overseeing the security risk register, and conducting incident investigations. Additionally, you will be responsible for updating GRC tools with relevant assessments and data, ensuring a strong cybersecurity posture for the organization.

Join Rise to see the full answer
What skills and qualifications are required for the Lead GRC Analyst role at Clover?

To be successful as the Lead GRC Analyst at Clover, candidates should possess a minimum of 7 years of experience in a security risk management role. Preferred qualifications include relevant certifications such as CISSP, CISM, or CISA, experience with regulatory frameworks like HIPAA and NIST, and strong communication skills. Familiarity with automated GRC platforms and healthcare experience can also set candidates apart in this role.

Join Rise to see the full answer
How does the Lead Governance, Risk, and Compliance Analyst collaborate with other teams at Clover?

Collaboration is key for the Lead Governance, Risk, and Compliance Analyst at Clover. You will work closely with various business partners across all departments to promote security awareness and adherence to policies. Your role will involve educating employees on security protocols and supporting them in implementing best practices for data protection, which contributes to a security-conscious culture within the organization.

Join Rise to see the full answer
What is the importance of risk assessments in the Lead GRC Analyst position at Clover?

Risk assessments are vital for the Lead GRC Analyst at Clover as they help identify and prioritize potential security threats to the organization. These assessments allow Clover to proactively manage vulnerabilities, especially those arising from third parties, and ensure compliance with regulatory standards which ultimately safeguard the integrity and confidentiality of health data.

Join Rise to see the full answer
What benefits can one expect in the Lead Governance, Risk, and Compliance Analyst role at Clover?

In the Lead Governance, Risk, and Compliance Analyst role at Clover, employees enjoy a competitive salary, equity opportunities, and a robust benefits package that includes comprehensive health coverage, a 401k matching program, mental health support, flexible work options, and ongoing professional development. Employees also appreciate the emphasis on work-life balance and the opportunity to work in a remote-first environment.

Join Rise to see the full answer
Common Interview Questions for Lead Governance, Risk, and Compliance Analyst
Can you describe your experience with risk assessments?

In my previous roles, I have conducted comprehensive risk assessments that involved evaluating threats from both internal and external sources. I utilized a variety of frameworks such as NIST SP 800-30 to guide my assessments, ensuring a thorough review of controls and potential vulnerabilities.

Join Rise to see the full answer
How do you stay updated on compliance regulations relevant to healthcare?

I regularly engage with industry publications, attend relevant webinars, and participate in professional organizations. Following regulatory updates from bodies like HIPAA and NIST helps me keep my knowledge current and applicable to my role as a GRC Analyst.

Join Rise to see the full answer
What methodologies do you prefer for incident investigations?

I typically employ a root cause analysis methodology, where I focus on gathering data from all phases of an incident. Utilizing tools like the 5 Whys allows me to identify underlying issues effectively, ensuring that preventive measures are implemented.

Join Rise to see the full answer
Describe your experience working with GRC tools.

I have extensive experience using automated GRC platforms, such as Onspring, for managing compliance tasks and monitoring security risks. I find these tools particularly useful for streamlining data collection and reporting, enhancing visibility into our risk management processes.

Join Rise to see the full answer
How do you communicate security policies to non-technical staff?

When communicating security policies, I focus on using clear, straightforward language and examples relevant to the employees' roles. I also offer training sessions and create engaging materials that outline best practices and the importance of compliance in a way that's easily digestible.

Join Rise to see the full answer
What steps would you take if you identified a significant security risk?

Upon identifying a significant security risk, my first step would be to assess the potential impact and determine the appropriate stakeholders to involve. I would then lead a thorough investigation to understand the root cause, develop an actionable mitigation plan, and communicate effectively with relevant parties to enact those measures.

Join Rise to see the full answer
In your opinion, what is the biggest challenge facing GRC professionals today?

One of the biggest challenges facing GRC professionals today is the ever-evolving threat landscape, particularly with the rise of sophisticated cyber attacks. Adapting compliance protocols and risk management strategies in real-time while ensuring the organization remains compliant can be incredibly complex.

Join Rise to see the full answer
How do you prioritize compliance tasks?

I prioritize compliance tasks based on risk assessment results, focusing first on high-impact areas. Additionally, I keep track of regulatory deadlines and audit schedules to ensure timely completions, while also considering the resources available to my team.

Join Rise to see the full answer
What experience do you have in managing third-party risks?

I have significant experience in managing third-party risks, including evaluating vendor security protocols and compliance standing. By conducting regular assessments and audits, I help ensure that third-party partners align with our organizational security posture and regulatory requirements.

Join Rise to see the full answer
Can you give an example of a successful compliance audit you've led?

In a previous role, I successfully led a compliance audit that resulted in identifying several areas for improvement in our security policies. By addressing these areas, we enhanced our compliance posture and avoided potential fines, reinforcing our commitment to data protection.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 5 days ago

Clover Health is on the lookout for a Talent Development Associate to drive impactful learning experiences across the organization.

Photo of the Rise User
Posted 14 days ago

We're looking for a Lead Cybersecurity Engineer to drive privileged and password management initiatives at a top-tier cybersecurity firm.

Photo of the Rise User

Lead NXP's Blue Team as a Security Operations Analyst, driving defensive strategies in a pivotal cybersecurity role.

Photo of the Rise User

Join Desjardins as an ElasticSearch Programmer Analyst and advance your career in a collaborative environment focused on delivering exceptional technology solutions.

Photo of the Rise User

Join Finanzen.net Group as a DevSecOps Engineer, driving secure software development practices across all development teams.

Photo of the Rise User
Codvo.ai Hybrid Plano, Texas, United States
Posted 14 days ago

Join Codvo as a DevOps Lead to lead the implementation of innovative DevOps practices and strategies.

Photo of the Rise User
Posted 11 days ago

Become a part of the NYC Public Engagement Unit as an IT Mobile Support Technician, specializing in mobile device support and technical service.

At Clover, we’re working to solve the country’s most complex and expensive problem: improving healthcare. Clover Health is a Medicare Advantage insurer that combines technology and preventive care to lower costs and increase the quality of life fo...

25 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
April 11, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
62 people applied to Cyber Crime Analyst at TEKsystems
H
Someone from OH, Rocky River just viewed Training Manager at Hotel Bardo Savannah
F
Someone from OH, Columbus just viewed VP of Communications at Freedom Together Foundation
Photo of the Rise User
Someone from OH, Columbus just viewed Chief Organizational Communication Officer at Providence
Photo of the Rise User
54 people applied to Security Analyst Jr at DEUNA
Photo of the Rise User
Someone from OH, Cuyahoga Falls just viewed SEASONER at Shearer's Foods
Photo of the Rise User
Someone from OH, Columbus just viewed Bilingual Care Manager, Telephonic RN at Humana
Photo of the Rise User
Someone from OH, Columbus just viewed Talent Business Partner at Red Bull
Photo of the Rise User
8 people applied to GRC Analyst at Mercury
Photo of the Rise User
Someone from OH, Brunswick just viewed Sanitation Team Member at Shearer's Foods
Photo of the Rise User
Someone from OH, Columbus just viewed Talent Acquisition Specialist at Beghou Consulting
C
Someone from OH, Middletown just viewed Operations Analyst at Core Specialty Insurance
A
Someone from OH, Strongsville just viewed Graphic Design Intern at Anvil NorthWest
W
Someone from OH, Uhrichsville just viewed Director Operations at WVUMedicine
Photo of the Rise User
Someone from OH, Cincinnati just viewed Game Director, Scripps Sports at The E.W. Scripps Company
Photo of the Rise User
Someone from OH, Lorain just viewed 3D Modeler / Graphic Designer - Freelance at Twine
o
Someone from OH, Oxford just viewed Digital Media & Marketing Student Intern at osu
Photo of the Rise User
Someone from OH, Beachwood just viewed Dispensary Tech at Ayr Wellness
Photo of the Rise User
Someone from OH, Springfield just viewed Front Desk Clerk at Marriott International
Photo of the Rise User
Someone from OH, Columbus just viewed Licensing and Regulatory Compliance Analyst at Sportradar
Photo of the Rise User
Someone from OH, Mansfield just viewed US_EN_Operations_Warehouse Loader (Part Time) at Red Bull