Senior GRC Manager

MediSolution

Northern (KY)

Hybrid

USD 135,000 - 165,000

Full time

12 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Full benefits package (medical, dental
Flexible work arrangements
3 weeks vacation + 5 personal days
Employee stock ownership and RRSP
Community involvement opportunities

Job summary

Harris Computer is seeking a Senior GRC Manager to own the GRC program end-to-end, aligning with HIPAA, GDPR, HITRUST and SOC 2. This hands-on role will maintain the Information Security Management Program, manage audit cycles, and work with auditors to ensure up-to-date policies and control mappings.

The ideal candidate has 5+ years in GRC/information security compliance, direct experience with audits, and strong ability to translate technical detail into policy language.

Qualifications

  • 5+ years in GRC, IT compliance, or information security compliance.
  • Direct experience maintaining an Information Security Management Program or similar.

Responsibilities

  • Governance, Risk & Compliance ownership for the program.
  • Maintain information security management program policies, procedures, and standards.
  • Support audits, assessments, and certification renewals (HIPAA, GDPR, HITRUST, SOC 2).
  • Maintain the risk register including third-party and vendor risk.
  • Keep control mapping and audit evidence current and organized.
  • Coordinate with auditors to close gaps before findings arise.
  • Act as the go-to compliance resource across the company.

Skills

GRC
Audits & audit evidence
Policy language
Risk management
Cloud compliance
cross-functional collaboration
Executive communication

Tools

Thoropass
OneTrust
AWS
Azure
GCP

Job description

We're looking for a Senior GRC Manager to own our GRC program end to end and keep ClearDATA aligned with HIPAA, GDPR, HITRUST, SOC 2, etc. You'll maintain our Information Security Management Program, manage audit cycles, and work directly with auditors, including keeping policy and compliance documentation accurate as our systems and vendors evolve. We want someone who treats compliance as a way to help the business move with confidence, not a set of hoops for other teams to jump through. You'll look for the practical, risk-based path to "yes" whenever one exists, and reserve hard stops for when they're truly warranted. This is a hands-on, senior role on our IT/ITSec team. You won't have direct reports, but you won't be working alone either — you'll have security engineers, DevSecOps, and leadership alongside you. We're looking for someone who'd rather build the control mapping than write a memo about who should build it.

What You'll Own
  • Governance, Risk & Compliance
  • Maintain ClearDATA's Information Security Management Program: the policies, procedures, and standards behind our security and compliance posture.
  • Support audits, assessments, and certification renewals for HIPAA, GDPR, HITRUST, and SOC 2.
  • Maintain the risk register, including tracking third-party and vendor risk.
  • Keep control mapping and audit evidence current and organized.
  • Support incident response planning alongside the IT/ITSec Manager and security team.
  • Partner with security engineers and DevSecOps to translate control requirements into how systems are actually built and operated - and to turn what they've built into defensible audit evidence.
  • Documentation & Audit Liaison
  • Update policies and program documentation as systems, vendors, or ownership of shared responsibilities change.
  • Work directly with auditors to catch and close compliance gaps before they become findings.
  • Flag open risk or outstanding items that need attention.
  • Act as the go-to compliance resource across the company — engineering, DevSecOps, management, and executive leadership — helping teams find a workable path forward rather than just pointing at policy, and giving leadership a clear read on where the program stands.
What We're Looking For
  • 5+ years in GRC, IT compliance, or information security compliance, ideally in a regulated industry, in hands-on roles rather than oversight or advisory.
  • Direct experience maintaining an Information Security Management Program or similar compliance program.
  • Working knowledge of HIPAA, SOC 2, HITRUST, or GDPR; healthcare experience strongly preferred.
  • Experience working directly with external auditors.
  • Proven ability to work across a technical organization and up to executive leadership — credible with security engineers and DevSecOps on the details, and able to give management and execs a straight answer on risk without burying it in framework language.
  • Strong writing skills.
  • You should be comfortable turning operational and technical detail into clear policy language.
  • Organized and detail-oriented, able to manage several compliance workstreams at once.
  • A pragmatic approach to risk: you can tell the difference between a real compliance issue and a theoretical one, and you'd rather solve a problem than just document it.
  • Nice to Have CISA, HITRUST CCSFP, or CRISC certification — useful, but we care more about what you've actually run than what you've been certified in.
  • Experience with AWS, Azure, or GCP and related compliance considerations.
  • Experience with GRC tooling (e.g., Thoropass, OneTrust, or similar platforms).
  • A background that spans both compliance and a technical discipline (IT, security, or engineering), so you can speak both languages.
Why ClearDATA

You'll own a GRC program that matters, at a company where security and compliance are the product, not an afterthought.

Established in 2009, ClearDATA was born out of a need to address significant inefficiencies within the U.S. healthcare system. From slow data processing to security concerns, these challenges often stood between patients and timely and effective care. As the healthcare industry began to embrace the public cloud, technology leaders faced a new set of challenges. Organizations found themselves navigating the fast-paced world of cloud innovations, regulatory compliance changes, and looming cyber threats. ClearDATA’s founders understood the complexities involved this highly-regulated industry and created the first cloud compliance and security solution exclusively for healthcare.

About Harris Computer

Harris provides mission critical software solutions for the Public Sector, Healthcare, Utilities and Private Sector verticals throughout North America, Europe, Asia and Australia. Working for Harris is the perfect opportunity to fulfill your professional goals as well as achieve your personal dreams! Our employees enjoy a casual work environment that offers comfort while providing superior service to our customers.

We offer a comprehensive benefit package as well as other additional "Perks"! We empower our employees to make a difference We have an award-winning culture We offer opportunity to learn We are financially strong and we are owned by the largest software company in Canada (CSI) We have fun! Follow us on social media to learn more about our company values, culture and initiatives! Instagram: @weareharris LinkedIn: Harris Computer

What we offer
  • Plenty of opportunities to grow your career
  • Full benefits package medical, dental, vision, STD, Life benefits
  • 3 weeks of vacation plus 5 personal days to recharge
  • Employee stock ownership and RRSP program
  • A chance to give back through community involvement
  • Flexible work arrangements to suit your lifestyle
  • Salary Range: $130 - 150K

Harris fournit des solutions logicielles essentielles pour le secteur public, les soins de santé, les services publics et le secteur privé en Amérique du Nord, en Europe, en Asie et en Australie. Travailler pour Harris est l'occasion idéale de réaliser vos objectifs professionnels ainsi que vos rêves personnels ! Nos employés bénéficient d'un environnement de travail décontracté qui offre confort tout en fournissant un service de qualité supérieure à nos clients. Nous offrons un ensemble complet d'avantages sociaux ainsi que d'autres "avantages" supplémentaires ! Nous donnons à nos employés les moyens de faire la différence Nous avons une culture d'entreprise riche Nous offrons la possibilité d'apprendre Nous sommes financièrement solides et nous appartenons à la plus grande société de logiciels du Canada (CSI) On s'amuse beaucoup ! Suivez-nous sur les médias sociaux pour en savoir plus sur les valeurs, la culture et les initiatives de notre entreprise ! Harris est un employeur à égalité de chances et d'action positive. Nous considérons les candidats sans considération de race, couleur, religion, âge, origine nationale, ascendance, origine ethnique, sexe, identité de genre, expression de genre, orientation sexuelle, statut matrimonial, statut de vétéran, handicap, information génétique, statut de citoyen ou autre groupe protégé par la loi fédérale, provinciale ou locale.

Harris is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status and will not be discriminated against on the basis of disability. Applicants who require a reasonable accommodation due to a disability may contact us by email at HarrisTalentAcquisition@harriscomputer.com. Accommodation requests may be made at any time. This email address is dedicated solely to accommodation requests and cannot be used to inquire about application status. Know Your Rights Poster EO 13496: Notification of Employee Rights under Federal Labor Laws Our commitment to fair and equitable hiring. As part of our recruitment process, we use artificial intelligence (AI) tools during the initial screening phase to help identify candidates whose qualifications most closely align with the requirements of the role. This technology supports efficiency and consistency in the early stages, but it never replaces human judgement. All subsequent evaluations and final hiring decisions are made by our recruitment professionals. AI does not make final hiring decisions.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior GRC Manager
Senior GRC Manager

MediSolution • North Carolina

Hybrid
USD 130,000 - 150,000
Full benefits package
Vacation + personal days
Employee stock ownership
+1
Project Manager
Project Manager

MediSolution • Northern (KY)

Hybrid
USD 115,000 - 120,000
Medical benefits
Dental benefits
Vision benefits
+3
Customer Success Manager
Customer Success Manager

MediSolution • Northern (KY)

On-site
USD 75,000 - 85,000
Senior GRC Manager
Senior GRC Manager

Harris Computer • Washington

On-site
USD 130,000 - 150,000
We empower our employees to make a dif
We have an award-winning culture
We offer opportunity to learn
+2
Senior GRC Manager
Senior GRC Manager

Harris Computer • Illinois

On-site
USD 130,000 - 150,000
We empower our employees to make a dif
Award-winning culture
Opportunity to learn
+2
Senior GRC Manager
Senior GRC Manager

Harris Computer • Missouri

On-site
USD 130,000 - 150,000
Flexible work arrangements
Full benefits package
3 weeks vacation + 5 personal days
+2
Senior GRC Manager
Senior GRC Manager

Harris Computer • South Carolina

On-site
USD 130,000 - 150,000
We empower employees
Award-winning culture
Learning opportunities
+2
Deal Desk Contracts Administrator
Deal Desk Contracts Administrator

MediSolution • Northern (KY)

Hybrid
USD 45,000 - 75,000
Comprehensive medical, dental, vision
Career growth opportunities
Generous vacation
+1
Senior GRC Manager
Senior GRC Manager

Harris Computer • Colorado

On-site
USD 130,000 - 150,000
We empower our employees to make a dif
We have an award-winning culture
We offer opportunity to learn
+2
Senior GRC Manager
Senior GRC Manager

Harris Computer • Delaware

On-site
USD 130,000 - 150,000
Full benefits package
Vacation and personal days
Employee stock ownership
+2