Employerdirecthealthcare

Employerdirecthealthcare

Senior GRC Engineer

Dallas, TX - Hybrid (3x in office/week) · Senior · Contract

Sponsorship not specifiedDetected 8 days ago
PythonSQLAWSAzureCloud PlatformsCI/CDMachine LearningLLMsCybersecurityComplianceVendor ManagementRecruitingHIPAALeadershipCollaborationCISSP

About the role

  • Lantern also pairs members with a dedicated care team, including Care Advocates and nurses, for the entirety of their care journey, helping them get back to good health, back to their families and back to work.
  • With convenient access to specialists nationwide, Lantern means quality care is within driving distance for most.
  • About You: - You use LOGIC in your decision making and understand that progress is critical to making change.

Responsibilities

  • Build and maintain continuous control monitoring workflows integrated into engineering pipelines, not just GRC platforms
  • Design compliance-as-code and policy-as-code approaches; own the technical architecture of how controls are tested automatically
  • Operate and extend the GRC platform (ServiceNow GRC, Drata, OneTrust, or equivalent) as an engineer, not just a user, including building integrations and automating evidence routing
  • Implement AI governance controls aligned to the NIST AI RMF, covering model risk, bias, transparency, and accountability, with a bias toward automated monitoring over manual review
  • Own the HIPAA Privacy and Security compliance program: risk assessments, remediation tracking, workforce training coordination, and ongoing monitoring
  • Support HITRUST CSF certification and SOC 2 Type II audit cycles as a technical contributor, building automated evidence pipelines rather than collecting evidence manually
  • Map the control environment against NIST CSF; identify gaps and build a prioritized, automatable remediation roadmap
  • Build and maintain the enterprise risk register with automated KRI tracking and outcome-based reporting for leadership
  • Build systems, not checklists. Manual processes are temporary; automation is the goal
  • By curating a Network of Excellence comprised of the nation's top specialists for surgery, cancer care, infusions and more, Lantern delivers excellent care with significant cost savings to employers and their workforces.

Requirements

  • Demonstrated ability to write code that extracts evidence directly from systems (Azure, IAM, endpoints, APIs), not just configure workflow tools

Skills

  • Experience with continuous control monitoring, integrating compliance checks into CI/CD or cloud infrastructure
  • Working knowledge of Python, SQL, or equivalent for data extraction, risk scoring, and compliance automation
  • Experience with cloud security controls in Azure
  • CISA, CRISC, CISM, or CISSP
  • HITRUST CCSFP a strong plus
  • Certifications (Preferred)
  • Strong Candidates Will:
  • Move with urgency and precision, flagging risk before it becomes an issue
  • Balance rigor with pragmatism, enabling the organization to move fast while staying protected
  • Communicate clearly to both technical and non-technical audiences without losing nuance
  • Bring genuine curiosity about AI. Follow the space and have formed opinions
  • Embody Lantern's LIGHT pillars (Logic, Inclusion, Grit, Humanity, Truth) in every interaction

Benefits

  • Medical Insurance
  • Dental Insurance
  • Vision Insurance
  • Short & Long Term Disability
  • Life Insurance
  • Flexible Time Off
  • Paid Parental Leave
  • Build and maintain Lantern's AI risk register and AI systems inventory, including pre-deployment risk assessments for new AI use cases across our benefits platform in partnership with Engineering and Product
  • Healthcare Compliance

This listing is sourced directly from Employerdirecthealthcare's careers page and normalized into a canonical job model.