Skip to main content

Security Analyst

Job Details

Fully Remote
Full Time

Description

Curana Health is a provider of value-based primary care services for the senior living industry, including skilled nursing facilities, assisted & independent living communities, Memory Care units, and affordable senior housing sites. Our 1,000+ clinicians serve more than 1,500 senior living community partners across 34 states, and Curana participates in various innovative CMS programs (including owned-and-operated Accountable Care Organizations and Medicare Advantage plans). With rapid year-over-year growth since our founding in 2021, Curana is setting a new standard in innovative care delivery for seniors with high-risk, complex clinical needs, many of whom have been historically underserved by the healthcare system. Our mission: To radically improve the health, happiness and dignity of senior living residents.

Job Summary:

Curana Health is seeking a Security Analyst to join our IT Security Team, focusing on Governance, Risk, and Compliance (GRC) activities related to Mergers and Acquisitions (M&A). This role is crucial in assessing, managing, and mitigating IT security, compliance, and risk challenges that arise during M&A activities. The ideal candidate will have a strong understanding of GRC frameworks, due diligence processes, and post-acquisition integration with emphasis on cybersecurity and regulatory compliance within the Healthcare Industry.

Essential Duties and Responsibilities:

  • Conduct IT security and compliance due diligence for potential acquisitions
  • Identify and evaluate cybersecurity risks, compliance gaps, and technology-related issues
  • Collaborating with cross-functional teams (Legals, Finance, IT, and Business Unites) to assess and report M&A-related risks
  • Ensure acquired entities align with organization GRC policies, regulatory requirements and industry standards
  • Develop and implement risk mitigation plans and compliance roadmaps for newly acquired entities
  • Participate in internal and external IT compliance audits/assessments, providing required documentation and remediation support
  • Support the integration of acquired entities into existing IT security and compliance frameworks
  • Monitor ongoing compliance and risk posture during the integration phase
  • Work with technology teams to address identified security gaps and ensure seamless technology transitions
  • Prepare comprehensive reports outlining risk findings, mitigations strategies, and compliance status
  • Provide regular updates to senior management and M&A project teams regarding security risks and progress on remediation
  • Act as a liaison between technical and non-technical stakeholders to ensure clear communication of risks and compliance obligations

Education and Experience:

  • Bachelor’s degree in Information Security, Computer Science, Information Technology or related field
    • May be substituted with applicable industry experience
  • 3-5 years of experience in IT security, risk management, or GRC with at least 1-2 years focused on M&A activities.
  • Healthcare industry experience is required

Knowledge and Skills:

  • Strong understanding of IT governance, risk management, and compliance frameworks
  • Experience with cybersecurity assessments and regulatory compliance audits
  • Ability to interpret and apply laws, regulations, and industry standards
  • Strong analytical and problem-solving skills with attention to detail
  • Excellent verbal and written communication skills, including executive-level reporting
  • Ability to manage multiple projects and deadlines in a fast-paced M&A environment

Curana Health is dedicated to the principles of Equal Employment Opportunity. We affirm, in policy and practice, our commitment to diversity. We do not discriminate on the basis of actual or perceived race, color, creed, religion, national origin, ancestry, citizenship status, age, sex or gender (including pregnancy, childbirth and related medical conditions), gender identity or gender expression (including transgender status), sexual orientation, marital status, military service and veteran status, physical or mental disability, protected medical condition as defined by applicable or state law, genetic information, or any other characteristic protected by applicable federal, state and local laws and ordinances.

The EEO policy applies to all personnel matters as outlined in our company policy including recruitment, hiring, transfers, and general treatment during employment

Apply