CronJobs

security jobs

Security GRC Manager

Rightway Health Care · Remote

remotemid$144,000–$175,000Posted Oct 9, 2026SOC 2HITRUSTISO/IEC 42001HIPAAHITECHDrataAWSOkta

Apply on the employer site

About this role

**Security GRC Manager — Rightway** **About the Role** Join Rightway as a **Security GRC Manager**, owning and maturing the GRC function. You’ll enhance policies and procedures, streamline workflows, mature risk management, own the integrated **SOC 2 + HITRUST** attestation as we scale, and lead the GRC team. **What You’ll Do** - **Team Leadership:** Lead and mentor a small GRC team; set priorities, review work, and grow the function alongside the business. - **Control Library Development:** Own and evolve a unified control library with mappings across **SOC 2, SOC 1, and HITRUST**; address gaps and inefficiencies as requirements change. - **Audit Ownership:** Partner with Engineering, IT, People, and Finance to lead the audit program for control requirements and evidence production—proactively for **SOC 1, SOC 2/HITRUST, and customer audits**. - **Data Privacy & Protection:** Partner with Legal on the Data Privacy program, including **HIPAA/HITECH**, BAAs, privacy/protection impact assessments, incident/breach analysis, and data handling requirements. - **AI Governance:** Own and mature an AI governance program modeled after **ISO/IEC 42001** (AI risk register, Statement of Applicability, AI risk assessments). Respond to customer/partner AI governance questionnaires and stay aligned to emerging requirements (e.g., **Colorado ADMTA**). - **Contract Security & Privacy Review:** Review and negotiate security, privacy, data protection, incident notification, audit rights, AI, and related language in customer/vendor agreements. - **Control Monitoring:** Monitor, measure, and report on control effectiveness in **Drata**, maintaining continuous control monitoring and evidence collection. - **Policy Enhancement:** Collaborate cross-functionally to improve policies and procedures to boost operational efficiency, control maturity, security, and compliance. - **Business Continuity Planning:** Lead business continuity planning and testing, informed by a **Business Impact Analysis (BIA)**. - **Third Party Risk Management (TPRM):** Revamp and execute a flexible yet thorough TPRM program with a focus on data security and technical risk—not just compliance. - **Risk Management:** Own the security risk management program (risk register, tracking, remediation) and support annual risk assessment activities. - **Training Program Development:** Develop and implement security and compliance training programs with organizational stakeholders. - **Customer Trust:** Own and maintain the customer assurance program (security questionnaire/RFP responses, trust center content, and tooling for timely, accurate responses). **Who You Are** - **5–10 years** of related experience. - Holds a relevant certification (e.g., **CISSP, CISA, CISM**). - Has personally led **SOC 2** with **HITRUST CSF** certification in a high-growth environment; understands how to mature controls aligned to organizational maturity and capacity. - Familiar with **AI governance frameworks** (e.g., ISO/IEC 42001) and AI risk considerations for sensitive data. - Experience leading/mentoring GRC analysts; able to set priorities, review work, and grow the function. - Deep understanding of risk assessment methodology, **HIPAA**, and **HITECH** (including covered entity vs. business associate obligations). Comfortable negotiating/redlining **BAAs** and conducting four-factor breach risk assessments with Privacy and Legal. - Passionate advocate for governance, risk, and compliance as essential to im

Listing freshness

CronJobs last confirmed this listing 2h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord