Haystack
← Back to Jobs
Administrative
AA

Information Security Governance, Risk & Compliance Analyst

ARCCA Analytics And IT Solutions LLCLos Angeles, CA🇺🇸United StatesPosted Sep 21, 2026

Why This Role Stands Out

This hybrid role offers a fantastic opportunity to shape information security governance and risk management, with a focus on policy, assessments, and vendor management. If you are a CISSP-certified professional with a knack for translating technical risks into business insights, you will thrive in this position and contribute significantly to ARCCA Analytics And IT Solutions LLC's esteemed program. Apply today to leverage your expertise and grow your career in a dynamic environment!

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Los Angeles, CA, United States
Posted
3 days ago

Job Description

ROLE: Information Security Governance, Risk & Compliance Analyst
TYPE: Contract / Contract-to-Hire
SCHEDULE: Hybrid — 3 days onsite, 2 days remote (local candidates only)
MUST-HAVE: Active CISSP
ROLE OVERVIEW
Supports the governance and risk management side of the information security program:
    ∙    Policy administration, risk assessments, and security program documentation
    ∙    Coordinating responses to audit requests and external inquiries from health plans, regulators, and insurers
    ∙    Vendor and third-party risk management
    ∙    Disaster recovery planning and documentation alongside IT
    ∙    Building and delivering security awareness and training material, including new hire orientation
    ∙    Translating technical security risk into business-relevant insight for leadership and cross-functional teams
Works closely with IT, Compliance, Legal, HR, Procurement, and Patient Financial Services, plus other operational groups as needed.
MINIMUM QUALIFICATIONS
    ∙    Bachelor’s degree in Business, Information Systems, Management, or a related field
    ∙    5+ years in IT audit, information security, or IT risk management
    ∙    Hands-on experience with security assessments, vendor risk assessments, and information security control management
    ∙    Working knowledge of HIPAA, PCI, and other federal/state data protection requirements
    ∙    Active CISSP is the primary certification benchmark. Strong candidates with related certifications (CISA, etc.) can be considered if they can obtain CISSP within a defined timeframe

Similar jobs