Senior Manager, Governance, Risk, and Compliance
New
V
Virta HealthDigital Health
As a remote-first company, our team is spread across various locations with office hubs in Denver and San Francisco.Full-TimeManager
Salary$161.5K - $209K; $161.5K – $209K • Offers Equity; Salary Range: $161.5K – $209K • Offers Equity
Apply NowOpens the employer's application page
Job Details
- Experience
- 7+ years of dedicated experience in Cybersecurity GRC, IT Auditing, or Information Security Compliance, with at least 2+ years leading programs or managing teams in regulated environments.
- Required Skills
- CybersecurityZendeskHIPAA
Requirements
- 7+ years of dedicated experience in Cybersecurity GRC, IT Auditing, or Information Security Compliance.
- 2+ years leading programs or managing teams in regulated environments such as Healthcare or Digital Health.
- Direct, hands-on experience managing and maintaining HITRUST CSF, HIPAA, and SOC 2 frameworks.
- Proven track record of using SaaS GRC automation platforms like Vanta or Drata.
- Strong communication skills for partnering with Sales and CS teams on enterprise security evaluations and RFPs.
- Experience designing and implementing AI-enabled workflows to improve team efficiency.
- Ability to balance corporate risk tolerance with operational efficiency and regulatory requirements.
- Cross-functional leadership skills to influence technical and non-technical partners.
- Commitment to evidence-based decision making and security awareness.
Responsibilities
- Maintain and mature information security compliance programs, policies, and controls to address scaling organizational risks.
- Oversee GRC function and scale platforms like Vanta to automate evidence collection and defend certifications.
- Partner with Sales and Customer Success teams to manage enterprise security evaluations, vendor questionnaires, and RFP responses.
- Define and own security policy lifecycles, vendor risk assessments, exception management, and executive reporting.
- Design and optimize ticketing workflows using tools like Zendesk or Jira to improve compliance request SLAs.
- Collaborate with IT and Security Engineering to map policies to technical architectures and AI governance frameworks.
- Champion security awareness and design training programs to maintain compliance and data privacy culture.
View Full Description & ApplyYou'll be redirected to the employer's site