About Avalere Health
United by one powerful purpose: to reach EVERY PATIENT POSSIBLE. At Avalere Health, we make sure every patient is identified, treated, supported, and cared for. Our Advisory, Medical, and Marketing teams come together—intentionally and effectively—to build unconventional connections and shape a future in which healthcare is never a barrier and no patient is left behind.
We begin fulfilling our mission by offering meaningful, purpose-driven careers that enable our team to make a real difference in patients’ lives. We’re committed to fostering a culture where employees can bring their whole selves to work and draw on the strength of diverse experiences and skills to help make a difference for every patient, everywhere.
Our flexible work approach allows our global teams to choose where they work—whether in the office or from home—based on team and client needs. Major hubs in London, Manchester, Washington, D.C., and New York, along with smaller offices worldwide, act as collaboration centers where teams can come together when it matters. Home-based colleagues are supported as well, with dedicated social activities and resources.
Inclusion is at the core of everything we do. We support employees in bringing their full selves to work through six Employee Network Groups: Diverse Ability, Family, Gender, LGBTQ+, Mental Health, and Race/Ethnicity. These groups create opportunities to advance diversity, equity, and inclusion, and to connect, learn, and socialise through regular meetings and activities. We’re a Fertility Friendly accredited employer, with a Fertility Policy, enhanced parental leave, and a flexible culture to ensure every employee feels supported throughout their family planning journey and can work in a way that meets their family’s needs.
We also invest heavily in employees’ professional development through hands-on career experiences, access to thousands of on-demand training sessions, regular career conversations, and the opportunity to make global, cross-capability career moves.
We’re proud to be part of the Disability Confident Scheme, which helps ensure you can be interviewed fairly if you have a disability, a long-term health condition, or are neurodiverse. If you’d like to apply and require adjustments, you can tell us in your application.
About the Role
The Information Security GRC Analyst supports the InfoSec GRC Lead in operating and improving the organisation’s governance, risk, and compliance programme. The role includes reviewing client MSAs and related security requirements, supporting internal and client audits, driving risk and exception management workflows, and supporting supplier/third-party security reviews. The organisation aligns with ISO/IEC 27001 and is implementing ISO/IEC 42001. The role supports compliance activities relevant to HIPAA, GDPR, and APPI. This is a great opportunity for recent graduates or early-career professionals to build a career in information security.
What You’ll Do
– Governance & Management System Support: Maintain documentation and evidence for ISO/IEC 27001 and ISO/IEC 42001; support continual improvement activities.
– Client MSA & Security Requirements Review: Extract and document security requirements from client MSAs; identify gaps and risks; coordinate with Legal and Privacy teams.
– Audit Support: Coordinate internal and client audit requests; gather evidence; ensure traceability between requirements, controls, and evidence.
– Risk Management & Exceptions: Support risk assessments for vendors/projects; maintain risk registers; assist with exception workflows.
– Supplier Reviews: Review third-party security submissions; track supplier risk ratings and remediation actions.
– Compliance Support: Map regulatory requirements (HIPAA, GDPR, APPI) to internal controls; maintain compliance documentation.
– Reporting & Improvement: Produce operational reports on audit status and risk metrics; contribute to process improvements.
About You
– Strong attention to detail
– Excellent written communication skills
– Professional discretion when handling sensitive information
– A foundational understanding of information security concepts (e.g., access control, encryption, incident response)
– Exposure to, or interest in, ISO/IEC 27001 or AI governance frameworks (ISO/IEC 42001)
– Experience supporting audits, vendor risk reviews, or privacy compliance is an advantage
– Familiarity with GRC/ticketing/documentation tools (e.g., ServiceNow/Jira)
– Suitable for junior candidates (1–3 years) in security, IT, risk, compliance, audit, or related areas, or equivalent demonstrated capability
– A bachelor’s degree in information security, IT, risk management, compliance, or a related field is beneficial, but not required if you have relevant experience
– Minimum requirement: You must hold—or be able to achieve within an agreed onboarding period (supported by the company)—the ISC2 Certified in Cybersecurity (CC) certification
What We Can Offer
You’ll receive up to a 7% pension contribution, life insurance, income protection, and private medical insurance. Enjoy flexible working arrangements, including flexible hybrid working, plus the option to work anywhere in the world for two weeks each year. You’ll get 25 days of annual leave plus two personal wellbeing days, along with end-of-year holiday gifts and an early finish on Fridays in June, July, and August.
You’ll also have access to free counselling through our employee assistance programme and personalised health support. Enhanced maternity, paternity, family leave, and fertility policies support you at every stage of your family planning journey, with on-demand support from our partner Peppy. You’ll have ongoing opportunities to develop professionally through on-demand training, support, and global mobility across the business.
We encourage all applicants to read our candidate privacy notice
before applying to Avalere Health.To apply for this job, please visit the application page

