Назад
Company hidden
2 часа назад

Senior GRC Manager (Cybersecurity)

130 000 - 150 000$
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior GRC Manager (Cybersecurity): Owning and maintaining ClearDATA's information security management and compliance programs with an accent on HIPAA, GDPR, HITRUST, SOC 2, risk registers, control mapping, and audit readiness. Focus on translating security controls into operational practices, managing external audit cycles, maintaining defensible evidence, and closing compliance gaps with engineering and DevSecOps.

Location: North Carolina, United States

Salary: $130,000–$150,000 per year

Company

ClearDATA provides cloud compliance and security solutions for the highly regulated healthcare industry and is part of hirify.global, which develops mission-critical software for public sector, healthcare, utilities, and private sector organizations.

What you will do

  • Own and maintain the Information Security Management Program, including policies, procedures, and security standards.
  • Manage audits, assessments, and certification renewals for HIPAA, GDPR, HITRUST, and SOC 2.
  • Maintain the risk register, third-party and vendor risk processes, control mappings, and audit evidence.
  • Partner with security engineers and DevSecOps to translate control requirements into operational practices and defensible audit evidence.
  • Work directly with external auditors to identify and close compliance gaps before they become findings.
  • Support incident response planning and provide leadership with clear, practical risk assessments.

Requirements

  • 5+ years of hands-on experience in GRC, IT compliance, or information security compliance.
  • Experience maintaining an Information Security Management Program or similar compliance program.
  • Working knowledge of HIPAA, SOC 2, HITRUST, or GDPR; healthcare experience is strongly preferred.
  • Experience working directly with external auditors and across technical and executive stakeholders.
  • Strong writing, organizational, and documentation skills, with the ability to manage multiple compliance workstreams.
  • Pragmatic, risk-based approach to solving compliance issues.

Nice to have

  • CISA, HITRUST CCSFP, or CRISC certification.
  • Experience with AWS, Azure, or GCP compliance considerations.
  • Experience with GRC platforms such as Thoropass or OneTrust.
  • Background spanning compliance and IT, security, or engineering.

Culture & Benefits

  • Full-time role with flexible work arrangements.
  • Medical, dental, vision, short-term disability, and life benefits.
  • Three weeks of vacation plus five personal days.
  • Employee stock ownership and RRSP program.
  • Career growth, learning opportunities, and community involvement programs.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →