
Senior GRC Manager
Posted Aug 28

Posted Aug 28
This is a fully remote position, open to applicants in Alabama, +44 more states.
• Take full ownership of ClearDATA's GRC program from start to finish
• Oversee the Information Security Management Program, encompassing policies, procedures, and standards
• Assist with audits, assessments, and certification renewals for HIPAA, GDPR, HITRUST, and SOC 2
• Manage the risk register and monitor third-party and vendor risks
• Ensure control mapping and audit evidence are up-to-date and well-organized
• Collaborate with the IT/ITSec Manager and security team on incident response planning
• Work alongside security engineers and DevSecOps to convert control requirements into system operations and verifiable audit evidence
• Revise policies and program documentation as systems, vendors, or shared-responsibility ownership evolve
• Engage directly with auditors to pinpoint and resolve compliance gaps
• Highlight open risks and outstanding matters that need attention
• Act as the primary compliance resource for engineering, DevSecOps, management, and executive leadership
• Deliver a transparent evaluation of the program's status and associated risks
• Minimum of 5 years of experience in GRC, IT compliance, or information security compliance
• Practical experience, preferably within a regulated industry
• Direct involvement in maintaining an Information Security Management Program or a similar compliance program
• Familiarity with HIPAA, SOC 2, HITRUST, or GDPR regulations
• Healthcare experience is highly preferred
• Experience collaborating with external auditors
• Capability to work across a technical organization and engage with executive leadership
• Exceptional writing skills with the ability to articulate technical details into clear policy language
• Highly organized and detail-oriented; proficient in managing multiple compliance workstreams
• A pragmatic, risk-based approach to compliance
• CISA, HITRUST CCSFP, or CRISC certification is beneficial but not mandatory
• Familiarity with AWS, Azure, or GCP and related compliance considerations is a plus
• Experience with GRC tools such as Thoropass or OneTrust is advantageous
• A background that includes both compliance and a technical discipline such as IT, security, or engineering is desirable
• Comprehensive benefits package including medical, dental, vision, STD, and life insurance
• 3 weeks of vacation along with 5 personal days
• Employee stock ownership and RRSP program
• Flexible work arrangements available
• Opportunities for career advancement
• Chance to learn and grow
• Opportunities for community involvement
• Casual work environment
• Award-winning company culture
Local Initiatives Support Corporation (LISC)
Precision For Medicine
Vertex Pharmaceuticals
ABX
Get handpicked remote jobs straight to your inbox weekly.