
Senior GRC Manager
Posted Aug 28

Posted Aug 28
This is a fully remote position, open to applicants in Alabama, +44 more states.
• Take full ownership of ClearDATA's Governance, Risk, and Compliance (GRC) program from start to finish.
• Oversee the Information Security Management Program, encompassing policies, procedures, and standards.
• Assist with audits, assessments, and certification renewals for HIPAA, GDPR, HITRUST, and SOC 2.
• Manage the risk register, which includes third-party and vendor risks.
• Ensure control mapping and audit evidence are consistently updated and well-organized.
• Collaborate with the IT/ITSec Manager and security team to enhance incident response planning.
• Work alongside security engineers and DevSecOps to convert control requirements into operational practices and defensible audit evidence.
• Revise policies and program documentation in response to changes in systems, vendors, or shared-responsibility ownership.
• Engage directly with auditors to identify and mitigate compliance gaps before they are reported.
• Highlight open risks and outstanding issues that require attention.
• Act as a compliance resource across the company for engineering, DevSecOps, management, and executive leadership.
• Deliver a clear evaluation of program status and associated risks to leadership.
• Minimum of 5 years of experience in GRC, IT compliance, or information security compliance.
• Practical experience, preferably within a regulated industry.
• Proven track record in maintaining an Information Security Management Program or a similar compliance initiative.
• Familiarity with HIPAA, SOC 2, HITRUST, or GDPR regulations.
• Experience in the healthcare sector is strongly preferred.
• Direct experience interacting with external auditors.
• Capability to navigate through a technical organization and communicate effectively with executive leadership.
• Excellent writing skills, with the ability to translate technical details into clear policy language.
• Highly organized and detail-oriented, with the ability to manage multiple compliance initiatives simultaneously.
• A pragmatic, risk-based perspective on compliance matters.
• Certifications such as CISA, HITRUST CCSFP, or CRISC are advantageous but not mandatory.
• Familiarity with AWS, Azure, or GCP and their compliance implications is a plus.
• Experience with GRC tools like Thoropass, OneTrust, or similar platforms is beneficial.
• A background that combines compliance and a technical discipline such as IT, security, or engineering is a plus.
• Relaxed work atmosphere.
• Comprehensive benefits package including medical, dental, vision, short-term disability, and life insurance.
• 3 weeks of vacation along with 5 personal days.
• Employee stock ownership and RRSP program.
• Opportunities for community engagement.
• Flexible work arrangement options.
• Career advancement opportunities.
• Continuous learning opportunities.
• An award-winning organizational culture.
Local Initiatives Support Corporation (LISC)
Precision For Medicine
Vertex Pharmaceuticals
ABX
Get handpicked remote jobs straight to your inbox weekly.