Sr. Governance Risk & Compliance Analyst

About Providence

Providence, one of the US’s largest not-for-profit healthcare systems, is committed to high quality, compassionate healthcare for all. Driven by the belief that health is a human right and the vision, ‘Health for a better world’, Providence and its 121,000 caregivers strive to provide everyone access to affordable quality care and services.

Providence has a network of 51 hospitals, 1,000+ care clinics, senior services, supportive housing, and other health and educational services in the US.

Providence India is bringing to fruition the transformational shift of the healthcare ecosystem to Health 2.0. The India center will have focused efforts around healthcare technology and innovation, and play a vital role in driving digital transformation of health systems for improved patient outcomes and experiences, caregiver efficiency, and running the business of Providence at scale.


Why Us?

  • Best In-class Benefits
  • Inclusive Leadership
  • Reimagining Healthcare
  • Competitive Pay
  • Supportive Reporting Relation

Position Summary

The Governance, Risk & Compliance (GRC) Analyst is responsible for supporting Providence’s compliance governance, regulatory readiness, risk management, and control assurance activities, with a focus on third-party and enterprise compliance obligations. This role partners closely with Security, Privacy, Legal, Procurement, Internal Audit, business stakeholders, and external vendors to ensure policies, controls, processes, and third-party engagements align with applicable regulatory requirements, internal standards, and industry frameworks.

The position emphasizes compliance program execution, control testing, policy adherence, audit evidence management, regulatory mapping, risk documentation, and continuous monitoring to support a mature and defensible GRC program.

Key Responsibilities

Compliance Governance & Program Support

  • Support day-to-day execution of GRC processes, including compliance assessments, control reviews, risk documentation, and remediation tracking.
  • Evaluate alignment with regulatory, contractual, and policy requirements, including HIPAA, HITECH, PCI-DSS, SOC 2, ISO 27001, NIST, HITRUST, and applicable state and federal regulations.
  • Review compliance artifacts, certifications, audit reports, policies, procedures, and security attestations to validate control effectiveness and compliance posture.
  • Ensure enterprise and third-party activities meet Providence security, privacy, compliance, and governance expectations.

Risk Assessment, Controls & Compliance Validation

  • Perform inherent and residual risk assessments across third-party and compliance-related activities.
  • Assess control gaps, compliance deficiencies, exceptions, and risk findings; recommend practical remediation plans and track closure.
  • Support control validation activities to confirm that processes, evidence, and control execution meet defined compliance requirements.
  • Maintain accurate risk ratings, control documentation, issue records, exceptions, and supporting evidence within designated GRC platforms.

Policy & Regulatory Compliance

  • Support the development, maintenance, and enforcement of GRC policies, standards, procedures, control requirements, and governance frameworks.
  • Interpret regulatory, contractual, and internal policy requirements and translate them into actionable compliance activities.
  • Track regulatory changes, audit expectations, and emerging compliance requirements that may impact security, privacy, third-party risk, or operational governance processes.

Audit & Evidence Management

  • Coordinate audit evidence collection, documentation, quality review, and submission for internal and external compliance reviews.
  • Support compliance assessments related to ISO 27001, SOC audits, NIST-based reviews, HIPAA/HITECH, HITRUST, and other healthcare regulatory obligations.
  • Facilitate audit response activities, management action plans, remediation tracking, and closure validation for compliance findings.

Third-Party & Vendor Compliance Oversight

  • Conduct periodic third-party compliance reviews, lifecycle assessments, and continuous monitoring activities.
  • Review vendor security incidents, breaches, exceptions, corrective action plans, and compliance commitments to assess organizational impact.
  • Escalate significant compliance concerns, unresolved findings, and residual risks through appropriate governance and risk review channels.

Reporting & Metrics

  • Develop GRC dashboards, compliance scorecards, executive reports, and audit-readiness summaries that communicate risk and compliance posture.
  • Track key risk indicators (KRIs), key compliance indicators, overdue assessments, control gaps, remediation status, exceptions, and audit findings.
  • Present compliance insights, risk themes, remediation progress, and recommendations to stakeholders, governance forums, and leadership teams.

Collaboration & Stakeholder Engagement

  • Partner with Security, Privacy, Legal, Procurement, Internal Audit, business owners, and vendors to support compliance reviews, risk decisions, and governance activities.
  • Provide guidance on GRC processes, documentation expectations, evidence requirements, control obligations, and third-party compliance standards.
  • Support risk review boards, governance committees, regulatory examinations, audit discussions, and compliance status reviews.

Required Qualifications

  • Bachelor's degree in Information Security, Cybersecurity, Information Systems, Business Administration, Risk Management, or related field.
  • 6+ years of experience in Governance, Risk & Compliance (GRC), Third-Party Risk Management (TPRM), Information Security, Audit, Compliance, or Risk Management.
  • Working knowledge of regulatory and compliance frameworks including:
    • HIPAA/HITECH
    • NIST Cybersecurity Framework
    • ISO 27001
    • SOC 1 / SOC 2
    • PCI-DSS
    • HITRUST
    • Vendor Risk Management practices
  • Experience conducting compliance reviews, assessments, or audits.
  • Strong analytical, documentation, and communication skills.

Preferred Qualifications

  • Experience in healthcare cybersecurity, healthcare compliance, or healthcare technology environments.
  • Familiarity with ServiceNow GRC, Archer, OneTrust, AuditBoard, or equivalent GRC platforms.
  • Professional certifications such as:
    • CISA
    • CRISC
    • CISSP
    • CISM
    • HCISPP
    • ISO 27001 Lead Auditor
  • Experience supporting regulatory audits and compliance programs.

Knowledge, Skills & Abilities

  • Strong understanding of third-party risk governance principles.
  • Ability to interpret regulatory and contractual requirements.
  • Experience performing compliance gap assessments and control reviews.
  • Strong report-writing, evidence-management, and audit-support skills.
  • Excellent stakeholder management and cross-functional collaboration capabilities.
  • Ability to manage multiple assessments and remediation initiatives simultaneously.

 

Providence’s vision to create ‘Health for a Better World’ aids us to provide a fair and equitable workplace for all in our employment, whether temporary, part-time or full time, and to promote individuality and diversity of thought and background, and acknowledge its role in the organization’s success. This makes us committed towards equal employment opportunities, regardless of race, religion or belief, color, ancestry, disability, marital status, gender, sexual orientation, age, nationality, ethnic origin, pregnancy, or related needs, mental or sensory disability, HIV Status, or any other category protected by applicable law. In furtherance to our mission in building a more inclusive and equitable environment, we shall, from time to time, undertake programs to assist, uplift and empower underrepresented groups including but not limited to Women, PWD (Persons with Disabilities), LGTBQ+ (Lesbian, Gay, Transgender, Bisexual or Queer), Veterans and others. We strive to address all forms of discrimination or harassment and provide a safe and confidential process to report any misconduct.

Contact our Integrity hotline also, read our Code of Conduct.