Employerdirecthealthcare
Senior GRC Engineer
Dallas, TX - Hybrid (3x in office/week) · Senior · Contract
Sponsorship not specifiedDetected 8 days ago
PythonSQLAWSAzureCloud PlatformsCI/CDMachine LearningLLMsCybersecurityComplianceVendor ManagementRecruitingHIPAALeadershipCollaborationCISSP
About the role
- Lantern also pairs members with a dedicated care team, including Care Advocates and nurses, for the entirety of their care journey, helping them get back to good health, back to their families and back to work.
- With convenient access to specialists nationwide, Lantern means quality care is within driving distance for most.
- About You: - You use LOGIC in your decision making and understand that progress is critical to making change.
Responsibilities
- Build and maintain continuous control monitoring workflows integrated into engineering pipelines, not just GRC platforms
- Design compliance-as-code and policy-as-code approaches; own the technical architecture of how controls are tested automatically
- Operate and extend the GRC platform (ServiceNow GRC, Drata, OneTrust, or equivalent) as an engineer, not just a user, including building integrations and automating evidence routing
- Implement AI governance controls aligned to the NIST AI RMF, covering model risk, bias, transparency, and accountability, with a bias toward automated monitoring over manual review
- Own the HIPAA Privacy and Security compliance program: risk assessments, remediation tracking, workforce training coordination, and ongoing monitoring
- Support HITRUST CSF certification and SOC 2 Type II audit cycles as a technical contributor, building automated evidence pipelines rather than collecting evidence manually
- Map the control environment against NIST CSF; identify gaps and build a prioritized, automatable remediation roadmap
- Build and maintain the enterprise risk register with automated KRI tracking and outcome-based reporting for leadership
- Build systems, not checklists. Manual processes are temporary; automation is the goal
- By curating a Network of Excellence comprised of the nation's top specialists for surgery, cancer care, infusions and more, Lantern delivers excellent care with significant cost savings to employers and their workforces.
Requirements
- Demonstrated ability to write code that extracts evidence directly from systems (Azure, IAM, endpoints, APIs), not just configure workflow tools
Skills
- Experience with continuous control monitoring, integrating compliance checks into CI/CD or cloud infrastructure
- Working knowledge of Python, SQL, or equivalent for data extraction, risk scoring, and compliance automation
- Experience with cloud security controls in Azure
- CISA, CRISC, CISM, or CISSP
- HITRUST CCSFP a strong plus
- Certifications (Preferred)
- Strong Candidates Will:
- Move with urgency and precision, flagging risk before it becomes an issue
- Balance rigor with pragmatism, enabling the organization to move fast while staying protected
- Communicate clearly to both technical and non-technical audiences without losing nuance
- Bring genuine curiosity about AI. Follow the space and have formed opinions
- Embody Lantern's LIGHT pillars (Logic, Inclusion, Grit, Humanity, Truth) in every interaction
Benefits
- Medical Insurance
- Dental Insurance
- Vision Insurance
- Short & Long Term Disability
- Life Insurance
- Flexible Time Off
- Paid Parental Leave
- Build and maintain Lantern's AI risk register and AI systems inventory, including pre-deployment risk assessments for new AI use cases across our benefits platform in partnership with Engineering and Product
- Healthcare Compliance
Apply directly at Employerdirecthealthcare →Create a free account for alerts like thisView Employerdirecthealthcare immigration profile
This listing is sourced directly from Employerdirecthealthcare's careers page and normalized into a canonical job model.