Governance, Risk & Compliance (GRC) Manager
Core
Lead and mature the security compliance program for a health technology platform serving practitioners and patients, ensuring audit readiness and operationalizing controls across the business.
Role type
Senior GRC Manager (hands-on leadership)
Builds
Enterprise security compliance program, audit readiness, and scalable control frameworks
Domain
Health technology / SaaS / Regulatory Compliance
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Governance, Risk & Compliance program ownership, SOC 2 Type II, PCI DSS, HITRUST, GDPR, HIPAA, NIST CSF, CIS Controls, ISO 27001, risk register management, third-party risk management, audit leadership, team management, policy development, cross-functional partnership
Preferred skills
Healthcare or health technology experience, GRC platform experience (Vanta, Drata, OneTrust), professional certifications (CISSP, CISA, CRISC, CISM, HITRUST CCSFP, PCI ISA/QSA, ISO 27001 Lead Auditor), customer security review support
Technologies
SOC 2 Type II, PCI DSS, HITRUST, GDPR, HIPAA, NIST CSF, CIS Controls, ISO 27001, Vanta, Drata, OneTrust
Responsibilities
Own and evolve the GRC program; maintain compliance across SOC 2, PCI DSS, HITRUST, GDPR, and HIPAA; lead external audits and coordinate remediation; manage risk registers and third-party risk; partner with Privacy, Legal, Security, and Engineering; lead and develop a team of two GRC professionals; develop reporting dashboards for compliance posture.
Seniority
Senior, hands-on IC with people management
