Senior Manager, Governance, Risk, and Compliance
virtahealthRemoteFull Time3d ago
AWSOpenAIGeminiAISecuritySOCComplianceJiraSaaSSalesCustomer SuccessRecruiting
Job description
Senior Manager, Governance, Risk, and Compliance
About the role
This position offers a significant opportunity to shape and lead Virta Health's Governance, Risk, and Compliance (GRC) program within a technology-driven environment. You will be instrumental in fostering a strong security and compliance culture across the organization, supporting commercial growth, overseeing audits, and strengthening key security frameworks.
Key facts
What you'll do
- Manage and advance the company's information security compliance program, including policies, procedures, and controls, adapting to organizational growth and evolving risks.
- Oversee the GRC platform, Vanta, to automate evidence gathering, ensure readiness for audits, and maintain certifications like HIPAA, HITRUST CSF, and SOC 2.
- Collaborate with Sales and Customer Success teams to address enterprise customer security evaluations and questionnaires, effectively communicating the company's security posture.
- Define and manage the security policy lifecycle, exception processes, vendor risk assessments, and executive risk reporting, conducting regular risk assessments to identify and mitigate vulnerabilities.
- Streamline workflows for employee requests, such as SaaS tool evaluations and policy exceptions, using ticketing systems like Zendesk or Jira.
- Ensure alignment between GRC policies and technical architectures, including AI governance frameworks like ISO 42001 and NIST AI RMF, by working with IT, Enterprise Security Engineering, and Product Development.
- Promote a culture of security awareness through training programs for all employees, emphasizing their role in compliance and data privacy.
Requirements
- A minimum of 7 years of experience in Cybersecurity GRC, IT Auditing, or Information Security Compliance.
- At least 2 years of experience leading programs or managing teams in regulated industries, such as healthcare or digital health.
- Hands-on experience with at least one of the following frameworks: HITRUST CSF, HIPAA, or SOC 2.
- Demonstrated success using GRC automation platforms like Vanta or Drata to scale compliance initiatives.
- Proven ability to communicate effectively with external clients and collaborate with Sales and Customer Success on security reviews and RFPs.
- Experience designing and implementing efficient, AI-assisted workflows to improve team productivity.
- Capacity to navigate complex situations, balancing corporate risk tolerance, operational efficiency, and regulatory mandates.
- Strong leadership skills to influence both technical and non-technical stakeholders towards achieving security compliance goals.
Skills & tools
- Vanta
- Zendesk
- Jira
- HIPAA
- HITRUST CSF
- SOC 2
- ISO 42001
- NIST AI RMF
Practical notes
- This role is fully remote.
- Corporate roles are not available in AK, AR, DE, HI, ME, MS, NM, OK, SD, VT, WI.
- Applicants may encounter sensitive patient information governed by HIPAA and are expected to adhere to strict security and privacy procedures.
- Virta Health utilizes Ashby as its applicant tracking system, which incorporates AI tools for application review and candidate screening. Candidate data is not used to train AI models, and all final hiring decisions are made by Virta Health personnel.