Bamboo Health is the leader in Real-Time Care Intelligence™ solutions aimed at improving lives for everyone experiencing physical and behavioral health challenges. We are driven by our mission to empower clients to deliver seamless, high-quality and cost-effective care during pivotal moments to improve health outcomes. From coast to coast, Bamboo Health partners with all major retail pharmacy chains, 52 states and territories, 100% of the top 10 best hospitals and more than half of the country’s largest health plans to improve more than 1 billion patient encounters annually. Join us in improving lives during pivotal care moments!
Summary:
Bamboo Health Security designs forward-thinking security solutions across cloud services, identity and access management, virtualization, and third-party integrations. We focus on innovative, scalable practices that meet complex regulatory requirements and support the company’s growth. Our team is highly collaborative and committed to both business success and individual development.
We are seeking a Senior Governance, Risk and Compliance (GRC) Analyst to help mature our compliance program, contribute to our audit cycles, and serve as the security interface for our customers. You will evaluate risks, conduct internal reviews, respond to customer security questionnaires, review security-relevant contract language, and use AI and automation to improve efficiency and maturity. Through this work, you will demonstrate Bamboo Health's security posture to prospective and existing customers, supporting our deals and ongoing customer relationships.
What You’ll Do:
- Evaluate organizational policies and standards, ensuring that external and internal compliance requirements are met.
- Develop improvements to the compliance program, including the use of AI, automation, and process optimization.
- Review security-relevant language in customer contracts (MSAs, DPAs, BAAs) and RFP/RFI security sections, providing recommendations to Legal and the broader GRC team.
- Respond to customer security questionnaires using AI-assisted tools and trust content, exercising professional judgment to ensure responses are accurate and complete.
- Work with external auditors and customers as necessary, providing them with required information and assistance.
- Maintain and update trust center content and customer-facing security documentation.
- Perform vendor security risk assessments and contribute to the third-party risk management program.
- Assist in policy documentation upkeep and development, ensuring clarity and applicability.
- Monitor and assist with the internal training programs on compliance requirements and best practices.
- Ensure Bamboo Health’s security operations remain aligned with both internal and external compliance requirements, contributing to ongoing internal and external audit reviews.
- Effectively communicate Bamboo Health’s compliance posture to both internal and external stakeholders, offering tangible proof of adherence to policy requirements.
- Partner with the larger Information Security team to identify areas for continuous improvement within the compliance framework.
- Stay curious about emerging AI tools and how they can streamline or enhance work within your function.
What Success Looks Like…
In 3 months…
- Understand and be able to describe Bamboo Health's products, organizational structure, customer base, and compliance landscape (SOC 2, HITRUST, FedRAMP, etc.).
- Develop familiarity with policies, risk register, and trust center content.
- Independently respond to customer security questionnaires using established trust content and AI-assisted tools.
- Independently perform vendor security reviews.
- Build partnership with InfoSec team, Legal, Sales, and key cross-functional partners.
- Incorporate AI-supported tools into your day-to-day work—whether through analysis, documentation, or task management.
In 6 months…
- Actively contribute to audit cycles, including evidence collection and control mapping.
- Own recurring compliance tasks (e.g., periodic access reviews, policy reviews, evidence collection cycles).
- Review security-relevant contract language and RFP security sections, providing actionable recommendations.
- Identify compliance gaps and recommend remediation approaches.
- Produce routine metrics and reporting on assigned work streams.
- Support the team's efforts with educational security initiatives and objectives.
In 12 months…
- Independently lead customer security trust activities — questionnaires, trust content, and customer security review calls.
- Own specific compliance frameworks or domains with minimal oversight.
- Drive improvements to the GRC program, including expanded use of AI and automation.
- Contribute meaningfully to audit cycle outcomes, including evidence quality and finding remediation.
- Serve as a trusted subject matter expert and mentor within the Information Security team.
What You Need:
- Bachelor’s degree in information security, computer science, or related field, or equivalent experience in a related field. Security compliance-related certifications such as CISSP, CISA, or CRISC are preferred.
- 5+ years of experience in information security, with substantial focus on compliance, audit, or risk management work.
- Direct experience with security frameworks and certifications like NIST SP 800-53, HITRUST, HIPAA, and/or FedRAMP.
- Experience responding to customer security questionnaires and supporting customer security due diligence activities.
- Experience reviewing security-relevant language in customer or vendor contracts.
- Familiarity with healthcare data protection requirements (HIPAA) and the compliance obligations they create.
- Demonstrated experience with security auditing and evidence gathering for compliance purposes.
- Experience evaluating security controls for compliance purposes.
- Familiarity with cloud security concepts and practices.
- Excellent written and verbal communication skills, with ability to build and communicate business rationale.
- Strong ability to learn quickly and work independently while being part of a team.
- Ability to build effective, sustainable working relationships internally, with customers, and external stakeholders.
- Comfort using or learning AI-supported tools (e.g., ChatGPT, CoPilot, or role-specific tools) to improve daily workflows.
- A forward-thinking, curious mindset with an openness to experimenting with new technologies.
- Strong analytical and problem-solving skills, with sound judgment and creativity in designing solutions.
- Proven ability to thrive in fast-paced, high-growth, and rapidly evolving environments.
- Ability to work effectively in a remote-first environment, ensuring high-quality virtual interactions with minimal distractions.
What You Get:
- Join one of the most innovative healthcare technology companies in the country.
- Have the autonomy to build something with an enthusiastically supportive team.
- Learn from working at the highest levels and on the most strategic priorities of the company, including from world class investors and advisors.
- Receive competitive compensation, including health, dental, vision and other benefits.
Belonging at Bamboo
We Care. #BambooHealthValuesCare
Every human being has the right to the best possible healthcare. Our Real-Time Care Intelligence™ solutions enable healthcare professionals to see and treat every individual as a whole person by providing the right information, at the right time – regardless of physical, behavioral or social barriers.
We’re a great place to work because we care. We continually seek to learn about our differences and ensure the unique perspectives and contributions of all employees are welcome, valued and celebrated.
Our commitment to making a positive impact starts by recognizing and leveraging our differences, building inclusive teams and cultivating a sense of belonging.
Bamboo Health is proud to provide equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.
This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.
Bamboo Health GDPR/RODO
To protect our applicants from fraudulent recruitment activity, we recommend that all applicants verify the validity of an interview and hiring process by visiting our website www.bamboohealth.com. All valid job postings will be listed on our careers page. Bamboo Health does not conduct interviews via text and will not request sensitive information such as banking details during the application process.
#LI-Remote
Similar Jobs
What you need to know about the NYC Tech Scene
Key Facts About NYC Tech
- Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
- Key Industries: Artificial intelligence, Fintech
- Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
- Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory



