GRC Analyst at AP MAX INC
, , Portugal -
Full Time


Start Date

Immediate

Expiry Date

19 Jun, 26

Salary

0.0

Posted On

21 Mar, 26

Experience

2 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

GRC, Compliance, Information Security, SOC 2, HIPAA Compliance, Policy Writing, Risk Assessment, Vendor Security Reviews, Audit Readiness, Control Evidence Collection, Drata, CISA, CISM, CRISC, ISO 27001, NIST

Industry

Retail Pharmacies

Description
Company Overview At Allia Health Group, the umbrella organization for Southend Pharmacy, Brello Health, and Woven, we don’t just follow industry trends—we redefine them. Our mission is to commoditize anti-aging solutions, making them affordable and accessible to the average consumer—not just the wealthy. By offering customized and cost-effective wellness products that follow cost-containment models, we aim to improve people’s quality of life and meet them wherever they are on their health journey. Job Summary The GRC Analyst will lead and operationalize the organization’s SOC 2 compliance program while supporting broader governance, risk, and compliance initiatives. This role is responsible for building policies, managing compliance frameworks, and ensuring audit readiness across the organization.The ideal candidate is hands-on, detail-oriented, and capable of driving cross-functional alignment across technical and business teams. Key Responsibilities * Lead SOC 2 Type 1 gap assessment and readiness initiatives * Develop and maintain information security policies and procedures * Manage compliance platform and control evidence collection * Execute HIPAA compliance initiatives and maintain documentation * Maintain risk register and conduct regular risk assessments * Manage vendor security reviews and assessments * Partner with engineering teams to align technical controls with compliance requirements * Serve as primary point of contact for external auditors What We Require * Minimum 4+ years of experience in GRC, compliance, or information security * Hands-on experience with SOC 2 frameworks * Knowledge of HIPAA security requirements * Experience with compliance platforms such as Drata or similar * Strong policy writing and documentation skills * Ability to manage cross-functional stakeholders Preferred Requirement * CISA, CISM, or CRISC certification * Experience in regulated or healthcare environments * Exposure to ISO 27001 or NIST frameworks * Experience managing external audits What We Offer * Full benefits package including medical, vision, dental, 401(k) with company match, PTO, Flex days, holidays, and more * Working in Madeira in a shared office space, remote in Portugal, or remote in a Portuguese timezone-friendly location. * Opportunity to build and own compliance programs from the ground up * High-impact role supporting company-wide security and regulatory initiatives * Benefits package designed to meet local market standards and legal requirements. This may include health coverage, paid time off, holidays, and retirement contributions, depending on your location. Allia Health Group does not provide employment visa sponsorship now or in the future. Applicants must be legally authorized to work in the United States without the need for current or future sponsorship. Equal Opportunity Employer Statement Allia Health Group is proud to be an Equal Opportunity Employer where we are committed to fostering a diverse and inclusive workplace. We are committed to cultivating a culture where all team members feel valued & respected. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender identity or expression, sexual orientation, national origin, genetic information, disability, age, veteran status, or any other characteristics protected by applicable law. If you have any questions or require immediate assistance or accommodations during the application or interview process, please contact us at recruiting@alliahealth.co.
Responsibilities
The GRC Analyst will lead and operationalize the organization’s SOC 2 compliance program while supporting broader governance, risk, and compliance initiatives. This role is responsible for building policies, managing compliance frameworks, and ensuring audit readiness across the organization.
Loading...