Security and Compliance Analyst
Apply NowLocation:
US
Company:
Pomelo Care is a healthcare startup focused on improving care for moms and babies through technology-driven solutions.
Summary:
The Security and Compliance Analyst will support Pomelo Care’s information security and compliance programs while collaborating on various security initiatives. Candidates should have at least three years of experience in GRC, cybersecurity, or related fields and a Bachelor’s degree in a relevant discipline.
Requirements:
Technology: GRC tools and platforms, such as Vanta and MyCSF
Hard Skills: Security risk assessments, Compliance audits, Risk management, Vendor security reviews, Documentation of processes
Credentials: Bachelor’s degree in Computer Science, Information Security, Information Systems, Business, or a related discipline., Professional certification such as CISA, CRISC, Security+, PMP or similar.
Experience: Minimum 3 years of professional experience in GRC, cybersecurity, compliance, risk management, or a related field., Experience coordinating or managing projects, including developing plans, tracking progress, and collaborating with stakeholders.
Job Description:
What you'll do
Pomelo Care is seeking a proactive and detail-oriented Security and Compliance Analyst to support the development and execution of our information security and Governance, Risk, and Compliance (GRC) program. In this role, you will collaborate across departments to help identify and mitigate cybersecurity risks, ensure regulatory compliance, and contribute to security and privacy initiatives. The ideal candidate has a solid foundation in information security or GRC, strong project management skills, and a passion for improving processes in a dynamic healthcare startup environment.
Key responsibilities will include:
- Support the implementation and maintenance of Pomelo Care’s information security and GRC program, including policies, standards, and procedures.
- Assist in performing security risk assessments and control evaluations across the organization.
- Track and coordinate remediation activities for identified risks or compliance gaps.
- Support third-party risk management activities, including vendor security reviews, user access reviews and due diligence assessments.
- Participate in internal and external audits (e.g., SOC 2, HITRUST), including evidence collection and responding to the auditor inquiries.
- Help manage compliance with healthcare-specific regulations (e.g., HIPAA) and security frameworks.
- Support the development and project management of security compliance workflows, including implementation of technical and administrative controls
- Develop and maintain metrics and dashboards to communicate GRC program status to stakeholders.
- Document processes, workflows, and control narratives to support governance and compliance efforts.
- Manage GRC or security-related projects, ensuring timely and quality delivery.
- Provide support for security awareness and training initiatives.
Who you are
- Minimum 3 years of professional experience in GRC, cybersecurity, compliance, risk management, or a related field.
- Experience coordinating or managing projects, including developing plans, tracking progress, and collaborating with stakeholders.
- Excellent organizational skills and attention to detail.
- Strong written and verbal communication skills.
- Ability to work independently and prioritize multiple tasks in a fast-paced startup environment.
We'll be super excited if you have
- Bachelor’s degree in Computer Science, Information Security, Information Systems, Business, or a related discipline.
- Professional certification such as CISA, CRISC, Security+, PMP or similar.
- Experience in healthcare technology startups or familiarity with healthcare regulatory requirements (e.g., HIPAA, HITRUST).
- Experience with GRC tools and platforms, such as Vanta and MyCSF.
Why you should join our team
By joining Pomelo, you will get in on the ground floor of a fast-moving, well-funded, and mission-driven startup that always puts the patient first. You will learn, grow and be challenged -- and have fun with your team while doing it.
We strive to create an environment where employees from all backgrounds are respected. We also offer:
- Competitive healthcare benefits
- Generous equity compensation
- Unlimited vacation
- Membership in the First Round Network (a curated and confidential community with events, guides, thousands of Q&A questions, and opportunities for 1-1 mentorship)
At Pomelo, we are committed to hiring the best team to improve outcomes for all mothers and babies, regardless of their background. We need diverse perspectives to reflect the diversity of problems we face and the population we serve. We look to hire people from a variety of backgrounds, including but not limited to race, age, sexual orientation, gender identity and expression, national origin, religion, disability, and veteran status.