Governance, Risk & Compliance Analyst at Sword Health

Sword Health logo
Sword Health

Governance, Risk & Compliance Analyst

pt flag
Portugal

Remote

Full Time

#Information Security

#Healthcare Technology

#Compliance

#ISO 27001

#SOC 2

#GDPR

#HIPAA

#Risk Management

#Leadership

#AI

Sword Health is looking for a Governance, Risk & Compliance Analyst

Sign up to unlock quick summaries and profile fit assessments

Sword Health is shifting healthcare from human-first to AI-first through its AI Care platform, making world-class healthcare available anytime, anywhere, while significantly reducing costs for payers, self-insured employers, national health systems, and other healthcare organizations. Sword began by reinventing pain care with AI at its core, and has since expanded into women’s health, movement health, and more recently mental health. Since 2020, more than 700,000 members across three continents have completed 10 million AI sessions, helping Sword's 1,000+ enterprise clients avoid over $1 billion in unnecessary healthcare costs. Backed by 42 clinical studies and over 44 patents, Sword Health has raised more than $500 million from leading investors, including Khosla Ventures, General Catalyst, Transformation Capital, and Founders Fund. Learn more at www.swordhealth.com.

As a GRC Analyst, you will be a key driver of trust and regulatory excellence at Sword Health. You will act as the primary interface for our partners and clients, translating our security posture into clear, authoritative responses that enable business growth. Beyond external trust, you will take ownership of certification lifecycles and bridge the gap between technical security controls and medical device quality standards.
 
We are looking for an agile problem-solver who can pivot quickly to support new products and initiatives in a way that aligns with our fast-paced innovation.

What you’ll be doing:
  • Acting as the primary subject matter expert for all security and compliance inquiries, including security questionnaires, RFPs, and M&A due diligence; building and maintaining a robust knowledge base to ensure accurate and efficient responses to partners and clients.
  • Taking end-to-end ownership of certification lifecycles, such as ISO 27001 and Cyber Essentials; ensuring year-round audit readiness, managing the certification process from start to finish, and independently leading external audits.
  • Working closely with the GRC team to improve existing programs, ensuring that our mapping of controls to processes and documentation remains robust and scalable as we grow.
  • Partnering with the Quality Assurance & Regulatory Affairs (QARA) team to bridge the gap between security-focused frameworks and Medical Device Compliance initiatives, ensuring a unified approach to the AI Act and other healthcare-specific regulations.
  • Collaborating with product teams on existing and upcoming initiatives to ensure security-by-design; quickly learning new product architectures and partnering with stakeholders to ensure all necessary compliance and security controls are integrated smoothly into the development lifecycle.
  • Collaborating with Security, Product, Engineering, and IT teams to ensure that security controls are naturally integrated into their existing workflows without creating operational friction.
  • Providing subject matter expertise and support for security and compliance training, as well as other general GRC initiatives as they arise.


  • What you need to have:
  • 5+ years of hands-on experience in GRC, with a proven track record of leading audits and maintaining certifications for internationally recognized security standards.
  • Hands-on experience with at least three of the following frameworks: ISO 27001, SOC 2, HITRUST, NIS2, Cyber Resilience Act, FedRAMP, CMMC, NIST SP 800-171, NIST SP 800-53, GDPR, HIPAA or PCI DSS.
  • Exceptional command of the English language, both written and spoken. You must be able to communicate complex security concepts clearly and authoritatively to both technical teams and external stakeholders.
  • A strong understanding of how security controls apply to Infrastructure and Product environments to effectively map requirements to technical work instructions.
  • A "wildcard" mindset—the ability to be dropped into a new project or product initiative, learn the context quickly, and define the necessary compliance path forward.
  • Familiarity with the intersection of cybersecurity (ISO, NIS2) and privacy/regulatory frameworks (GDPR, AI Act, or Medical Device regulations).
  • Familiarity with Medical Device certifications and regulations, such as ISO 13485 and FDA’s Good Manufacturing Practices (GMP).
  • Proven experience using LLMs to accelerate personal workflows, including drafting, summarizing, and analyzing GRC-related tasks to achieve significant individual productivity gains.
  • Demonstrated ability to design and implement AI-driven automations or integrated workflows that replace manual processes and enhance productivity at a team level is a strong plus.
  • Experience working across diverse teams such as Legal, Quality, and IT to align on shared compliance goals.
  • Leverage AI to streamline the creation and maintenance of compliance artifacts (e.g., policies, control descriptions, risk assessments), ensuring accuracy, consistency, and proper review processes.
  • Design and implement AI-assisted workflows for risk tracking and governance, improving visibility, follow-ups, and accountability across risk owners.
  • Support the automation of evidence collection and control monitoring processes, using AI to reduce manual effort while maintaining auditability.
  • Ensure that the use of AI in GRC processes preserves traceability, version control, and regulatory compliance requirements.
  • Define and enforce guardrails for the responsible use of AI in compliance and risk management activities.
  • Continuously evaluate the reliability and integrity of AI-generated outputs used in governance and reporting processes.


  • To ensure you feel good solving a big Human problem, we offer:
  • A stimulating, fast-paced environment with lots of room for creativity.
  • A bright future at a promising high-tech startup company.
  • Career development and growth, with a competitive salary.
  • The opportunity to work with a talented team and to add real value to an innovative solution with the potential to change the future of healthcare.
  • A flexible environment where you can control your hours (remotely) with unlimited vacation.
  • Access to our health and well-being program (digital therapist sessions).
  • Remote or Hybrid work policy.
  • To get to know more about our Tech Stack, check here.


  • Portugal - Sword Benefits & Perks:
    • Health, dental and vision insurance
    • Meal allowance
    • Equity shares
    • Remote work allowance
    • Flexible working hours
    • Work from home
    • Discretionary vacation
    • Snacks and beverages
    • English class
    Note: Please note that this position does not offer relocation assistance. Candidates must possess a valid EU visa and be based in Portugal.
    Sword Health complies with applicable Federal and State civil rights laws and does not discriminate on the basis of Age, Ancestry, Color, Citizenship, Gender, Gender expression, Gender identity, Gender information, Marital status, Medical condition, National origin, Physical or mental disability, Pregnancy, Race, Religion, Caste, Sexual orientation, and Veteran status.
    Sword Health logo

    Sword Health

    5 views

    0 applied

    Company Size

    501-1000

    Markets

    Medical

    Social Media

    Visit Sword Health
    Share this job
    Copy Permalink
    Open roles at Sword Health
    Sword Health logo
    Sword Health

    Chief Information Security Officer

    Remote

    Full Time

    #Technology

    #Information Security

    #Cybersecurity

    #Identity Management

    #Software Security

    #GRC

    #Security Operations

    #SOC 2

    #HITRUST

    #FedRAMP

    #ISO 27001

    #NIST CSF

    Sword Health logo
    Sword Health

    Governance, Risk, and Compliance Analyst

    Remote

    Full Time

    #Technology

    #Information Security

    #Risk Management

    #Compliance

    #Audit Management

    #Communication

    Sword Health logo
    Sword Health

    Expert Brand Designer - B2B Marketing

    Remote

    Full Time

    #Design

    #Marketing

    #Figma

    #Adobe CC

    #Google Suite

    #Layout

    #Web Design

    Sword Health logo
    Sword Health

    Expert Brand Designer

    Remote

    Full Time

    #Design

    #Marketing

    #Figma

    #Adobe CC

    #Google Suite

    #Layout

    #Web Design

    Sword Health logo
    Sword Health

    Head of Product Platform

    Remote

    Full Time

    #Technology

    #Product

    #Product Management

    #AI

    #Strategic Thinking

    Sword Health logo
    Sword Health

    Brand Designer

    Remote

    Full Time

    #Design

    #Graphic Design

    #Brand Strategy

    #Adobe CC

    #Figma

    #Print Design

    #Typography

    #Layout

    Sword Health logo
    Sword Health

    Application Security Engineer

    pt flag
    Portugal

    Hybrid

    Full Time

    #Technology

    #Information Security

    #Snyk

    #Burp suite

    #Python

    #Penetration Testing

    Sword Health logo
    Sword Health

    Contract Technical Recruiter

    Remote

    Contractor

    #Talent Acquisition

    #Recruiting

    #Talent Sourcing

    #Hiring

    #Documentation

    #English

    Sword Health logo
    Sword Health

    Contract Technical Recruiter

    Remote

    Contractor

    #Talent Acquisition

    #Recruiting

    #Talent Sourcing

    #Hiring

    #Technical Recruitment

    #Documentation

    #English

    Sword Health logo
    Sword Health

    Contract Technical Recruiter

    Remote

    Contractor

    #Talent Acquisition

    #Recruiting

    #Talent Sourcing

    #Hiring

    #Documentation

    #English

    Discover similar jobs
    M
    Maximus

    Marketing Creative Director

    Remote

    Full Time

    #Performance

    #Leadership

    #Operations

    #Brand Development

    #Team Management

    #AI Tools

    #Digital

    #Brand Strategy

    #Content Creation

    Sana logo
    Sana

    Customer Success Associate

    Remote

    Full Time

    #Customer Support

    #Health Insurance

    #Time Management

    #Communication Skills

    #Compliance

    #Issue Tracking

    #Navigation

    Allata logo
    Allata

    Ascend Program - Data

    Remote

    Full Time

    #Data

    #Data Engineering

    #Software Development

    #Data Analysis

    #AI

    #Agile

    #Jira

    #Git

    #Cloud Platforms

    Quest Resource LLC logo
    Quest Resource LLC

    Project Manager

    Remote

    Full Time

    #Project Management

    #Scheduling

    #Budget Management

    #Design

    #Risk Management

    #Procurement

    #Coordination

    #Quality Control

    #Client Communication

    OpenVPN logo
    OpenVPN

    AI Platform Engineer

    140k - 150k USD

    Remote

    Full Time

    #AI

    #DevOps

    #Cloud Infrastructure

    #Vertex AI

    #Terraform

    #GCP

    #Compliance

    #ISO 27001

    #Pipelines

    #Kubernetes

    U
    Union

    Sales Engineer

    Remote

    Full Time

    #AI

    #Sales

    #Machine Learning

    #MLOps

    #PyTorch

    #TensorFlow

    #Spark

    #Kubernetes

    #Docker

    #AWS

    #Terraform

    #MEDDIC

    D
    Deepgram

    Pre-Sales Solutions Engineer

    Remote

    Full Time

    #AI

    #Solutions Engineering

    #Python

    #JavaScript

    #API Integration

    #Speech Recognition

    #NLP

    #Cloud Platforms

    #Docker

    #Kubernetes

    #Sales Methodologies

    L
    Lightdash

    Head of Engineering

    Remote

    Full Time

    #Engineering Leadership

    #AI

    #Developer Experience

    #TypeScript

    #React

    #Node.Js

    #SQL

    #Docker

    #Kubernetes

    #GCP

    #Architecture

    #Security

    saas.group logo
    saas.group

    Applied Research Scientist

    Remote

    Full Time

    #AI

    #Research

    #SQL

    #Python

    #Data Analysis

    #Experiment Design

    #Data Pipelines

    #Validation

    #AI Tools

    #Research Methodology

    P
    Pinecone

    Staff/Principal Product Manager, Database

    Remote

    Full Time

    #Product Management

    #AI

    #Database

    #SaaS Products

    #Cloud Infrastructure

    #Data Analysis

    #User Research

    #Roadmap Planning

    #Collaboration

    #Technical Products

    Dataiku logo
    Dataiku

    Fullstack Software Engineer

    Remote

    Full Time

    #Engineering

    #AI

    #Solutions

    #Vue.Js

    #React

    #Angular

    #Python

    #fastAPI

    #Flask

    #RESTful API

    #Data

    ETGroup logo
    ETGroup

    Audio Visual Project Manager

    Remote

    Full Time

    #Technology

    #Audio

    #Project Management

    #Risk Management

    #Management

    #Financial Management

    #Solutions

    #Change Management

    #Communication

    #Project Planning

    #Documentation

    C
    Clyro

    Technical Product Marketer Content Growth

    Remote

    Full Time

    #AI

    #Content Marketing

    #Growth

    #SEO Optimization

    #Content Editing

    #Editorial

    #Keyword Research

    #Management

    #Social Media

    #LinkedIn

    #Twitter

    #Ahrefs

    Doxel logo
    Doxel

    Director, Product Engineering

    Remote

    Full Time

    #Product Engineering

    #Construction

    #AI

    #Architecture

    #Web

    #Data Pipelines

    #3D Rendering

    #Engineering Leadership

    #Team Management

    B
    Boxxe Group

    Project Manager

    Remote

    Full Time

    #Project Management

    #IT

    #Professional Services

    #Waterfall

    #PRINCE2

    #Project Planning

    #Stakeholder Management

    #Risk Management

    #Jira

    #Trello

    #ITIL

    #MS Office

    McFadyen Digital logo
    McFadyen Digital

    Sales Director

    Remote

    Full Time

    #Digital

    #Sales

    #Technology

    #Sales Cycle Management

    #Pipeline Building

    #Cold Calling

    #Channel Partnerships

    #CRM

    #Digital Marketing

    #AI

    A
    Axelera AI

    Field Application Engineering Manager

    Remote

    Full Time

    #AI

    #Field Engineering

    #Customer Success

    #PyTorch

    #TensorFlow

    #Embedded Systems

    #Python

    #CUDA

    #Computer Vision

    #Deployment

    Digital Forge Cyber Assurance Group logo
    Digital Forge Cyber Assurance Group

    Senior Microsoft 365 and Support Services Engineer

    Remote

    Full Time

    #Technology

    #Cybersecurity

    #Microsoft

    #Azure AD

    #Support Engineering

    #Compliance

    #Active Directory

    #Monitoring

    #Management

    #IT

    #Support

    Nestora logo
    Nestora

    Mobile Developer

    in flag
    India

    Remote

    Full Time

    #Technology

    #Mobile Development

    #AI

    #AI Tools

    #Claude

    #Clean Code

    E
    eduki

    Senior AI Engineer

    es flag
    Spain

    39.8k - 57.3k USD

    Remote

    Full Time

    #AI Engineering

    #Automation

    #Data Analytics

    #Systems

    #Databases

    #Engineering

    #AI

    #Orchestration

    #Python

    #SQL

    Your dream job awaits.

    Explore exciting opportunities, connect with top employers, and ignite your career.