Senior Manager, GRC
Maven Clinic - New York, NY
Hiring: Senior Manager, GRC Company: Maven Clinic Location: New York, NY Job Posted Time: 2026-09-10 12:20:41 Employment Type: Full-time / Remote Target Skills & Keywords : HIPAA, Maven, Project Management, SOC 2, SaaS About the job Experience: •6+ years of experience in GRC, information security compliance, or IT audit, with direct ownership of at least one SOC 2 or similar audit cycle from start to finish. Required Skills: •Our platform facilitates virtual health visits for employer-sponsored benefits, which means security, privacy, and compliance are core to customer trust and our ability to sell into enterprise and health-plan accounts. •External Audit & Certification Management •Own continuation and renewal of our SOC 2 (Type II) and HITRUST certifications end-to-end. You'll scope each cycle, pull evidence, work directly with auditors, and track remediation through to the final report. •Lead the ground-up establishment of ISO 27001 and ISO 42001 certification programs. That means gap assessments, control mapping, writing ISMS/AIMS policies and statements of applicability, gaining cross team buy in, and getting us ready for initial certification audits. •Manage the annual/ongoing audit calendar across all frameworks, coordinating with internal stakeholders (Engineering, IT, HR, Legal) to gather evidence and close findings on time. •Track regulatory and framework changes (HIPAA, state privacy laws, ISO updates) and translate them into control updates. •Serve as the primary owner of security questionnaires and RFIs/RFPs for the Sales and Customer Success teams. Ensure responses to prospect and customer’s due-diligence requests are accurate and on deadline. •Maintain a security knowledge base / answer library to reduce turnaround time on recurring questions. Qualifications: •Solid functional working knowledge of SOC 2, HITRUST, and ISO 27001 frameworks hands-on . •Strong cross-team collaboration skills. You'll regularly work with Engineering, IT, HR, Legal, and Sales to gather evidence, close control gaps, and keep everyone aligned on deadlines. •Solid project management instincts: able to sequence overlapping audits and certification projects, track dependencies and remediation items, and hit dates without needing someone else to manage the plan for you. •Strong written communication; you'll be writing policies, RFI responses, and audit narratives that both auditors and non-technical stakeholders need to understand. •Direct experience standing up a new certification (SOC2, HITRUST, ISO 27001 and/or the newer 42001 AI management standard) rather than just maintaining an existing one. •Background in health tech, digital health, or another regulated B2B vertical (fintech, insurtech) where compliance is a sales enabler. •A relevant certification such as CISA, CRISC, CISSP, PMP or CAPM, CISM, CTRC/CAP. •Exposure to vulnerability management or IT operations well enough to meaningfully audit those processes rather than just take reports at face value. •The base salary range for this role is $170,000 - $201,000 per year. You will also be entitled to receive equity and benefits. Individual pay decisions are based on a number of factors, including qualifications for the role, experience level, and skillset. •At Maven we believe that a diverse set of backgrounds and experiences enrich our teams and allow us to achieve above and beyond our goals. If you do not have experience in all of the areas detailed above, we hope that you will share your unique background with us in your application and how it can be additive to our teams. Compensation: •$170,000 - $201,000 / year •Flexible work environment (work from home / hybrid options) •Competitive benefits and rewards package Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!