Senior Manager, GRC
Core
Lead governance, risk, and compliance for a B2B health benefits platform, managing audits, policies, and customer security due diligence.
Role type
Senior Manager, GRC (Team Lead)
Builds
SOC 2, HITRUST, and ISO 27001/42001 certifications; internal control monitoring programs.
Domain
Healthcare technology / B2B SaaS
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
GRC/IT audit ownership, SOC 2/HITRUST/ISO framework expertise, RFI/RFP response, cross-functional collaboration, project management, technical writing
Preferred skills
New certification program setup, GRC automation tooling, regulated vertical background, security certifications, vulnerability management exposure
Technologies
Vanta, Drata, Secureframe, Hyperproof
Responsibilities
Own SOC 2 and HITRUST certification cycles; establish ISO 27001 and ISO 42001 programs; manage audit calendars and regulatory updates; handle security questionnaires and customer due diligence; run internal control monitoring; partner with Sales on security posture.
Seniority
Senior Manager, hands-on IC with team leadership
