Manager and Senior Manager: Governance, Risk, & Compliance (GRC)
Core
Lead the design and hands-on execution of Governance, Risk, and Compliance (GRC) initiatives to maintain alignment with regulatory frameworks, reduce enterprise risk, and strengthen operational resilience.
Role type
Manager/Senior Manager GRC Program Lead
Builds
Scalable security control frameworks, policies, standards, and risk management programs
Domain
Health Tech / SaaS / Regulated Environments
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
GRC program management, regulatory framework implementation (ISO 27001, SOC 2, GDPR, HIPAA), enterprise risk register management, third-party risk assessment, incident response coordination, team mentorship, operational metrics reporting, process improvement
Preferred skills
CISA, CISSP, CRISC, CIPP/E, ISO Lead Auditor, HITRUST CCSFP certifications, experience in health tech or SaaS
Technologies
ISO 27001, SOC 2, GDPR, PCI, NIST CSF, HIPAA
Responsibilities
Drive development and implementation of governance programs aligned with regulatory frameworks; Partner in managing security control frameworks and third-party risk assessments; Support incident response and post-incident reviews; Manage enterprise risk register and drive risk prioritization; Coach and mentor GRC analysts; Lead third-party risk management lifecycle; Own operational intake and triage for GRC requests; Develop and report operational metrics and KPIs; Evaluate and improve GRC tools and processes
Seniority
Senior, hands-on IC with leadership scope
