
Senior Manager, Governance, Risk, Compliance
Posted Jul 31

Posted Jul 31
This is a fully remote position, open to applicants in Alaska, +9 more states.
• Maintain and enhance Virta Health's information security compliance program, policies, procedures, and controls to address emerging risks as the organization grows.
• Oversee the Governance, Risk, and Compliance (GRC) function at Virta, scaling our platform (Vanta) to automate continuous evidence gathering, ensuring audit preparedness while upholding our HIPAA, HITRUST CSF, and SOC 2 certifications.
• Collaborate directly with Sales and Customer Success teams to manage enterprise customer evaluations and security reviews, effectively communicating Virta's robust security compliance posture to external stakeholders.
• Define and manage Virta's security policy lifecycle, exception management processes, vendor risk assessments, and executive risk reporting.
• Conduct regular risk assessments to identify vulnerabilities, evaluate potential impacts, and advise business owners on mitigation strategies.
• Oversee the administrative security queue for Virta employees. Design and refine seamless ticketing workflows (such as Zendesk or Jira) and Service Level Agreements (SLAs) for access governance reviews, SaaS tool compliance assessments, and policy exception requests.
• Work closely with IT, Enterprise Security Engineering, and Product Development teams to ensure operational GRC policies are well-integrated into our technical architectures and evolving AI governance frameworks (e.g., ISO 42001, NIST AI RMF).
• Promote a culture of security awareness throughout the organization. Develop and deliver targeted training programs so that employees comprehend their roles in maintaining compliance and data privacy.
• 7+ years of focused experience in Cybersecurity GRC, IT Auditing, or Information Security Compliance, including at least 2+ years in leadership roles or managing teams in regulated environments (such as Healthcare or Digital Health).
• Direct, hands-on experience with managing and maintaining at least one of the primary security and healthcare frameworks, specifically HITRUST CSF, HIPAA, and SOC 2.
• Demonstrated history of utilizing modern SaaS GRC automation platforms (such as Vanta or Drata) to scale continuous compliance initiatives.
• Exceptional client-facing communication abilities with a proven track record of collaborating with Sales and Customer Success teams to navigate complex enterprise security evaluations, vendor questionnaires, and RFP processes.
• Successfully designed and implemented repeatable AI-enabled workflows that resolve team bottlenecks and enhance efficiency.
• Capability to operate in ambiguous situations, striking the right balance between corporate risk tolerance, operational efficiency, and regulatory requirements.
• Strong cross-functional leadership skills with the capacity to influence both technical and non-technical business partners to align on security compliance goals.
• Offers Equity
Finalsite
EXALTA Group
Auto Approve
Cushman & Wakefield
Get handpicked remote jobs straight to your inbox weekly.