Risk and Compliance Analyst
what we observed
- first seen by us
- Sep 2, 2026
- times checked
- 3, last Sep 4, 2026
we re-check this board on a schedule and log every sighting. report an error
Inovalon was founded in 1998 on the belief that technology, and data specifically, would empower the transformation of the entire healthcare ecosystem for the better, improving both outcomes and economics. At Inovalon, we believe that when our customers are successful in their missions, healthcare improves. Therefore, we focus on empowering them with data-driven solutions. And the momentum is building.
Together, as ONE Inovalon, we are a united force delivering solutions that address healthcare’s greatest needs. Through our mission-based culture of inclusion and innovation, our organization brings value not just to our customers, but to the millions of patients and members they serve.
Overview:
The Risk and Compliance Analyst is internal to Inovalon, a part of the Security Governance, Risk and Compliance department that partners with Technology, business groups, and project teams to perform risk and compliance activities for applications, infrastructure, and vendor third parties. In addition, this position supports enterprise security, risk, and compliance initiatives that improve Inovalon’s security posture, management control systems, liaises with the company's external audit firm, and helps foster an appreciation for a strong control environment across the organization. The candidate must be able to build working relationships and drive change with various levels of management on an enterprise scale and be able to articulate how assessment results translate to business risk for the organization.
Description:
A skilled professional, responsible for providing documentation and team support. Manage multiple tasks and dependencies effectively to deliver high-quality written responses and documentation in a fast-paced environment. Interface with Inovalon teams to understand business needs, functionality and operations for developing thorough accurate information to questionnaires, assisting in audit activities for certifications, like SOC, HITRUST, EHNAC, PCI DSS, etc.
Duties and Responsibilities:
- Participate in cross-functional teams to support enterprise IT Risk and Compliance initiatives and projects;
- Identify, assess, document, test, and support remediation of IT risks across applications, business processes, and information systems;
- Plan, manage, and execute risk-based IT assessments and audit activities for industry certifications and regulatory compliance programs, including information security risk assessments, data integrity reviews, technical compliance reviews, third-party vendor assessments, HIPAA, SOC 1/SOC 2, HITRUST, EHNAC, PCI DSS, and other applicable frameworks, while supporting evidence collection, auditor inquiries, and remediation tracking;
- Lead and support responses to prospective client RFPs, client inquiries, control assessments, security and compliance questionnaires, and other third-party requests by developing thorough, accurate, and well-supported responses in collaboration with cross-functional stakeholders and ensuring alignment with organizational policies and control frameworks;
- Prepare and present risk and compliance reports, highlighting issues, trends, root causes, and recommendations for management and senior leadership;
- Develop, draft, edit, and manage the review and approval of policies, procedures, standards, technical documentation, and other compliance artifacts;
- Collaborate with cross-functional stakeholders and Subject Matter Experts (SMEs) to gather technical information and create accurate, high-quality, and user-friendly documentation;
- Capture, organize, and maintain compliance-related documentation, policies, procedures, and project artifacts;
- Estimate, plan, prioritize, and independently manage multiple documentation and compliance projects to ensure timely delivery;
- Conduct research, analyze findings, document observations, and identify root causes of risk, security, and compliance issues, escalating as appropriate;
- Build and maintain collaborative relationships with internal teams, external partners, auditors, and key stakeholders;
- Ensure adherence to organizational policies, confidentiality requirements, and HIPAA regulations while supporting operational and compliance objectives;
- Perform additional responsibilities as assigned to support the organization's operational and financial success.
Job Requirements:
- Security / Audit-related certifications preferred, such as CISA, CCSFP, CISSP, CRISC;
- 2+ years of experience collaborating in teams and working within the areas of Internal Audit, Technology Governance, Risk Assurance, and/or Internal Controls. Healthcare industry experience is a plus;
- Familiarity with COSO/COBIT internal control framework a plus; and
- An in-depth understanding of core information technology processes and controls, current trends in corporate information technology and emerging themes in the marketplace.
Education & Skills:
- Bachelor’s degree in Business, Technology, and/ or equivalent work experience;
- Articulate communicator, demonstrating mastery of both spoken and written English, with the ability to tailor deliverables appropriately for audiences ranging from technical to senior executives;
- Excellent written and verbal communication skills;
- Proven ability to manage multiple projects and work-streams concurrently and successfully;
- Excellent skills using Excel/Word/PowerPoint and flowcharting tools are required;
- Ability to handle complex projects in a multi-tasking environment, meeting deadlines and interacting with individuals at all levels within the organization;
- High degree of adaptability and flexibility;
- Self-motivated, detail-oriented professional with strong organizational skills;
- Strong analytical skills, previous experience with Cybersecurity documentation;
- Ability to multitask with multiple documents and deadlines.
This position is not eligible for immigration sponsorship (e.g. H-1B, TN, or E-3). Applicants must be authorized to work in the United States as a condition of employment. (This is only applicable for US-based positions)
If you don’t meet every qualification listed but are excited about our mission and the work described, we encourage you to apply. Inovalon is most interested in finding the best candidate for the job, and you may be just the right person for this or other roles.
By embracing inclusion, we enhance our work environment and drive business success. Inovalon strives to provide equal opportunities to the communities where we operate and to our clients and everyone whom we serve. We endeavor to create a culture of inclusion in which our associates feel empowered to bring their full, authentic selves to work and pursue their professional goals in an equitable setting. We understand that by fostering this type of culture, and welcoming different perspectives, we generate innovation and growth.
Inovalon is proud to be an equal opportunity workplace. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or veteran status. We also consider qualified applicants regardless of criminal histories, consistent with legal requirement.
To review the legal requirements, including all labor law posters, please visit this link
To review the California Consumer Privacy Statement: Disclosures for California Residents, please visit this link