Senior Manager, Governance, Risk, and Compliance
Virta Health - United States
Hiring: Senior Manager, Governance, Risk, and Compliance Company: Virta Health Location: United States Job Posted Time: 2026-09-11 13:28:00 Employment Type: Remote Target Skills & Keywords : AWS, HIPAA, Jira, Program Management, SOC 2, SaaS, Zendesk About the job Experience: •7+ years of dedicated experience in Cybersecurity GRC, IT Auditing, or Information Security Compliance, with at least 2+ years leading programs or managing teams in regulated environments (such as Healthcare or Digital Health). Required Skills: •Enable Commercial Velocity (RFPs & Security Questionnaires): Partner directly with Sales and Customer Success to navigate enterprise customer evaluations and security reviews, communicating Virta's strong security compliance posture to external stakeholders. •Own Policy, Risk & Compliance Governance: Define and own Virta's security policy lifecycle, exception management processes, vendor risk assessments, and executive risk reporting. Conduct regular risk assessments to identify vulnerabilities, assess potential impact, and guide business owners on mitigation. •Champion GRC Employee Experience: Manage the administrative security queue for Virta employees. Design and optimize frictionless ticketing workflows (such as Zendesk or Jira) and SLAs for access governance reviews, SaaS tool compliance evaluations, and policy exception requests. •Coordinate Cross-Functional Security Alignment: Collaborate closely with IT, Enterprise Security Engineering, and Product Development teams to ensure operational GRC policies map seamlessly into our technical architectures and evolving AI governance frameworks (e.g., ISO 42001, NIST AI RMF). •Security Awareness & Compliance Training: Champion a culture of security awareness across all levels of the organization. Design and deliver targeted training programs so employees understand their roles in maintaining compliance and data privacy. •First 30 days: Deep dive into our current GRC tool configurations (Vanta), evaluate our control framework status, meet with key stakeholders across IT and Security Engineering, and take ownership of the daily employee SaaS review and GRC request queue. •Day 30-60: Establish baseline SLAs for employee compliance requests (SaaS reviews, access reviews) and optimize automation workflows to streamline customer security questionnaire and RFP responses. Initiate coordination with external auditors and partners for upcoming assessments. •Day 60-90: Complete a comprehensive internal risk assessment and present a clean, unified risk and compliance metric dashboard to senior leadership covering GRC control health, exception trends, and upcoming audit preparation timelines. Qualifications: •Lead GRC & Compliance Automation: Oversee Virta’s GRC function, scaling our platform (Vanta) to automate continuous evidence collection, ensuring audit-readiness and defending our HIPAA, HITRUST CSF, and SOC 2 certifications. Compensation: •$161,500 - $209,000 / year •Flexible work environment (work from home / hybrid options) Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!