Full-Time

GRC Senior Analyst

Risk Management

Confirmed live in the last 24 hours

Flatiron Health

Flatiron Health

1,001-5,000 employees

Cancer-specific EHR system for healthcare providers

Data & Analytics
Healthcare

Senior

Durham, NC, USA

Hybrid role requiring 3 office days per week.

Category
Risk & Compliance
Legal & Compliance
Requirements
  • 6+ years relevant experience working in Security Risk Management, Security Metrics & Reporting, Third party risk assessment, SOC2/ISO/NIST 800-53 audit oversight, and Interpretation & Maintenance of Security Policies / Standards
  • Experience with reporting on key risk indicators and metrics to stakeholders
  • Experience working with security frameworks (HIPAA, PCI, NIST, ISO etc)
  • Proven ability to manage risk and projects in a face paced environment
  • Ability to communicate risk effectively to stakeholders within the organization.
  • Superior organizational skills and attention to detail
  • Excellent interpersonal, writing and communication skills
  • Ability to constantly prioritize and change or adapt to ambiguous situations
  • Passionate about healthcare and the fight against cancer
  • You have HIPAA experience
Responsibilities
  • Provide oversight to the Security Risk Management function and help create / drive its strategic roadmap
  • Create and deliver security metrics and risk indicators to our external stakeholders to help inform the business areas of their risk posture and enable the business to make informed risk decisions
  • Assist in maturing the security risk management strategy throughout the enterprise.
  • Maintain processes and playbooks related to security metrics reporting
  • Provide oversight for Security’s Plan of Action (POAM) and Exception process.
  • Perform risk based analysis on proposed projects, vendors, and issue resolution implementations
  • Lead Security related implementations and projects by coordinating with technical and non-technical teams to ensure success
  • Proactively identify and develop solutions to data security issues by working with multiple teams including Privacy, Legal, HR, Procurement and vendors
  • Effectively communicate security needs and business requirements to stakeholders
  • Serve as an advisor and internal consultant on identified issues, project plans or any other initiative that may have security implications
  • Test implemented controls and perform risk assessments based on established frameworks and Flatiron internal policies
  • Respond to client security risk assessment questionnaires by gathering information from across the organization as necessary
  • Promote security education and awareness across Flatiron

Flatiron Health focuses on improving cancer care and research through its specialized platform. The main product is a cancer-specific Electronic Health Record (EHR) system that helps healthcare providers manage patient information efficiently while enhancing patient experiences. This system integrates real-world data in real-time, allowing for smarter research and better patient outcomes. Flatiron connects various stakeholders in the cancer care ecosystem, such as community oncologists and academic researchers, facilitating collaboration and data sharing to accelerate cancer research and improve care quality. Unlike competitors, Flatiron emphasizes data quality and patient care, partnering with regulatory bodies to meet high standards. The goal is to leverage real-world data to transform oncology and support the development of new cancer treatments.

Company Stage

Acquired

Total Funding

$304.6M

Headquarters

New York City, New York

Founded

2012

Growth & Insights
Headcount

6 month growth

-5%

1 year growth

-7%

2 year growth

-6%
Simplify Jobs

Simplify's Take

What believers are saying

  • Flatiron's significant presence at the ASCO Annual Meeting and multiple accepted research abstracts highlight its leadership in oncology research.
  • Collaborations with organizations like ACCC and NCCN expand access to clinical trials and improve cancer care quality, offering employees opportunities to work on impactful projects.
  • The company's innovative tools like Flatiron Clinical Pipe™ and Flatiron Assist™ streamline data capture and clinical decision support, enhancing efficiency and patient outcomes.

What critics are saying

  • The highly specialized focus on oncology may limit Flatiron's market expansion opportunities beyond cancer care.
  • Dependence on partnerships and collaborations for data and research initiatives could pose risks if these relationships falter.

What makes Flatiron Health unique

  • Flatiron Health's cancer-specific EHR system integrates real-world data in real-time, setting it apart from generic EHR solutions.
  • The company's platform connects various stakeholders in the oncology ecosystem, facilitating collaboration and data sharing, which accelerates cancer research and improves care quality.
  • Flatiron's partnerships with regulatory bodies and life sciences companies ensure high data quality and compliance, enhancing its credibility and market position.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Work/life autonomy via flexible work hours and flexible paid time off

Generous parental leave (16 weeks for either parent)

Transition back to work program following parental leave

Child and caregiver travel benefits for new parents

Backup child care

Weekly meditation sessions

Flatiron-sponsored fitness classes

Weekly massages and manicures available onsite (employee funded)