Назад
Company hidden
6 дней назад

Senior Manager, GRC (Healthcare)

170 000 - 201 000$
Формат работы
remote (только USA)/hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Manager, GRC (Healthcare): Owning governance, risk, and compliance for a B2B virtual healthcare benefits platform with an accent on SOC 2, HITRUST, ISO 27001, and ISO 42001 certification programs. Focus on establishing audit frameworks, monitoring controls, responding to customer security questionnaires, and coordinating remediation across Engineering, IT, HR, Legal, and Sales.

Location: United States; hybrid work with New York City onsite three days per week and monthly Work Together Days in Boston, Washington, DC, Chicago, Seattle, and San Francisco for employees based in those cities; remote work is available through US hub cities.

Salary: $170,000–$201,000 per year, plus equity and benefits.

Company

hirify.global provides virtual healthcare and women's and family health programs to employers, health plans, and consumers through its digital health platform.

What you will do

  • Own SOC 2 Type II and HITRUST certification renewals, including scoping, evidence collection, auditor coordination, and remediation tracking.
  • Establish ISO 27001 and ISO 42001 certification programs through gap assessments, control mapping, policy development, and audit preparation.
  • Manage the audit calendar and coordinate evidence collection and control remediation across Engineering, IT, HR, Legal, and other stakeholders.
  • Own security questionnaires, RFIs, and RFP responses, and represent the security and compliance posture in customer discussions.
  • Build an internal audit and control-monitoring program to identify control gaps and process drift before external audits.
  • Track regulatory and framework changes, including HIPAA, state privacy laws, and ISO updates, and translate them into control updates.

Requirements

  • 6+ years of experience in GRC, information security compliance, or IT audit, including ownership of at least one SOC 2 or similar audit cycle.
  • Hands-on knowledge of SOC 2, HITRUST, and ISO 27001 frameworks.
  • Experience responding to customer security questionnaires and RFIs, preferably in B2B SaaS or healthcare.
  • Strong cross-functional collaboration, written communication, and project management skills.
  • Ability to coordinate overlapping audits, certification projects, dependencies, and remediation deadlines independently.
  • Employment is for US-based, full-time employees; hybrid attendance requirements apply in designated US hub cities.

Nice to have

  • Experience establishing a new SOC 2, HITRUST, ISO 27001, or ISO 42001 certification program.
  • Experience with Vanta, Drata, Secureframe, Hyperproof, or similar GRC automation tools.
  • Background in health tech, digital health, fintech, insurtech, or another regulated B2B industry.
  • Certifications such as CISA, CRISC, CISSP, PMP, CAPM, CISM, or CTRC/CAP.
  • Experience with vulnerability management, IT operations audits, or Sales Engineering support during deal cycles.

Culture & Benefits

  • Flexible hybrid work model with remote work through US hub cities.
  • Employer-covered health, dental, and insurance plan options.
  • Access to Maven healthcare specialists and wellness partnerships.
  • 16 weeks of fully paid parental leave and a new parent stipend after one year of employment.
  • Annual professional development stipend, career coaching, and 401(k) matching with immediate vesting for US-based employees.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →