GRAIL
GRAIL is a healthcare company whose mission is to detect cancer early, when it can be cured.
Hybrid

Senior Security Risk Analyst #3496

Sorry, this job was removed at 12:07 p.m. (PST) on Tuesday, May 7, 2024
Find out who's hiring in Peninsula.
See all Data + Analytics jobs in Peninsula
Apply
By clicking Apply Now you agree to share your profile information with the hiring company.
Employer Provided Salary: 130,000-160,000 Annually
Salary data is provided by the employer. Please note this is not a guarantee of compensation.

GRAIL is a healthcare company whose mission is to detect cancer early, when it can be cured. GRAIL is focused on alleviating the global burden of cancer by developing pioneering technology to detect and identify multiple deadly cancer types early. The company is using the power of next-generation sequencing, population-scale clinical studies, and state-of-the-art computer science and data science to enhance the scientific understanding of cancer biology, and to develop its multi-cancer early detection blood test. GRAIL is headquartered in Menlo Park, CA with locations in Washington, D.C., North Carolina, and the United Kingdom. GRAIL, LLC is a wholly-owned subsidiary of Illumina, Inc. (NASDAQ:ILMN). For more information, please visit www.grail.com.


GRAIL is seeking a dynamic Security Risk Analyst to join our Security Governance, Risk and Compliance (GRC)Team. The Security Risk Analyst will be supporting the Security GRC Team to help mature GRAIL’s GRC function by defining security guardrails and countermeasures to protect GRAIL’s assets, customers, and business partners. 


In this role you are pivotal in driving continuous improvement efforts for GRAIL’s Information security risk management process, in addition to the end to end operations of the risk management life cycle.


GRAIL's headquarters are located in Menlo Park, CA and this role is a hybrid role with 2 days onsite.

Responsibilities

  • Lead and drive comprehensive information security risk assessments including identification, assessment and measurement across different systems/processes, assets and third parties
  • Partner with cross-functional teams including (but not limited to) Engineering, IT, People, Finance, Quality to identify appropriate security controls to implement, and define risk mitigation strategies
  • Collaborate with business owners to ensure that onboarded third party solutions are properly assessed for security risks, and that adequate security controls are in place 
  • Document, track and evaluate the effectiveness of risk mitigation efforts performed by cross-functional teams
  • Identify security controls that will be implemented for risk mitigation (this includes controls from ISO 27001, PCI, HIPAA and/or SOC 2)
  • Develop, update and maintain policy and procedure documentations on a specified cadence or as needed
  • Serve as a subject matter expert for the Risk Management program, and support relevant audit requests during external audits
  • Lead efforts in configuring and maintaining a comprehensive Information Security Risk Register using GRAIL’s GRC platform
  • Build and maintain metrics to help cultivate awareness of organizational information security risks 
  • Communicate risk assessment results and risk mitigation status to the leadership team
  • Perform other relevant tasks as assigned

Preferred Qualifications

  • Bachelor’s degree in an Information Systems, Engineering, or related technical discipline
  • Ideal candidate will have 3+ years proven experience in risk assessment, preferably in the healthcare/Biotech domain
  • Demonstrated experience in Information Security reviews, and or risk assessments
  • Deep understanding of risk assessment methodologies and frameworks such as NIST RMF / NIST 800-53
  • Knowledgeable in security frameworks and standards including, but not limited to, ISO 27001, PCI DSS, HIPAA and SOC 2
  • Skilled in analyzing and interpreting security data/architecture for risk evaluation
  • Ability to communicate effectively between technical and non-technical stakeholders, across different levels of the organization
  • Strong analytical, and organizational skills for prioritization and decision-making
  • Ability to learn new tools and technologies quickly
  • Technical understanding of cloud-based security in an AWS environment preferred

The estimated, full-time, annual base pay scale for this position is $ 130,000 - $ 160,000. Actual base pay will consider skills, experience, and location. 


Based on the role, colleagues may be eligible to participate in an annual bonus plan tied to company and individual performance, or an incentive plan. We also offer a long-term incentive plan to align company and colleague success over time.


In addition, GRAIL offers a progressive benefit package, including flexible time-off, a 401k with a company match, and alongside our medical, dental, vision plans, carefully selected mindfulness offerings.


GRAIL is an Equal Employment Employer and does not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability or any other legally protected status. We will reasonably accommodate all individuals with disabilities so that they can participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation. GRAIL maintains a drug-free workplace.

See More
Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.

What are GRAIL Perks + Benefits

GRAIL Benefits Overview

We’re committed to creating the best experience for everyone at GRAIL, ensuring that each member of our team has comprehensive benefits and resources to thrive at all stages of life, both at work and at home.

Culture
Volunteer in local community
We parter with Bay Area local partners such as Life Science Cares to help meet basic needs in the community.
Partners with nonprofits
GRAIL partners with The Honor Foundation to facilitate mock interviews to help military professionals transition to civilian life. Also oSTEM and The National Sales Network to identify diverse talent.
Open door policy
OKR operational model
Team based strategic planning
Open office floor plan
Employee resource groups
Employee-led culture committees
Hybrid work model
In-person all-hands meetings
Employee awards
Flexible work schedule
Remote work program
Diversity
Dedicated diversity and inclusion staff
Mandated unconscious bias training
Unconscious bias training is included as part of our standard interview training. We also have a formal training on the topic of unconscious bias that is facilitated by the People Team.
Diversity manifesto
Mean gender pay gap below 10%
Diversity employee resource groups
GRAIL proudly offers 4 employee resources groups led by team members in tandem with an executive sponsor. They include: ASERG, WERG, PRIDE, and BIPOCC.
Hiring practices that promote diversity
GRAIL's Talent team has partnered with a variety of non-profits, associations and job boards including WITI, oSTEM, THF, DiversityJobs and The National Sales Network to identify diverse talent.
Health Insurance + Wellness
Flexible Spending Account (FSA)
Disability insurance
Dental insurance
Vision insurance
Health insurance
Life insurance
Wellness programs
Team workouts
Mental health benefits
Abortion travel benefits
Financial & Retirement
401(K)
401(K) matching
Company equity
Performance bonus
Pay transparency
Child Care & Parental Leave
Childcare benefits
Generous parental leave
Family medical leave
Company sponsored family events
Fertility benefits
Vacation + Time Off
Unlimited vacation policy
Paid holidays
Paid sick days
Flexible time off
Bereavement leave benefits
Company-wide vacation
Office Perks
Commuter benefits
Company-sponsored outings
Free daily meals
Free snacks and drinks
Some meals provided
Company-sponsored happy hours
Onsite office parking
Recreational clubs
Relocation assistance
Onsite gym
Professional Development
Job training & conferences
Promote from within
Mentorship program
Online course subscriptions available
Paid industry certifications

More Jobs at GRAIL

Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.
Learn more about GRAILFind similar jobs like this