Senior GRC Manager

MediSolution

Washington (NC)

On-site

USD 120,000 - 180,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

ClearDATA is seeking a Senior GRC Manager to own the GRC program end to end and keep us aligned with HIPAA, GDPR, HITRUST, SOC 2, and related standards.

You will maintain the Information Security Management Program, manage audit cycles, and work with auditors to keep policy and compliance documentation accurate as systems and vendors evolve. This is a hands-on senior role on the IT/ITSec team with collaboration across security engineers, DevSecOps, and leadership.

Qualifications

  • 5+ years in GRC, IT compliance, or information security compliance.
  • Direct experience maintaining an Information Security Management Program.
  • Working knowledge of HIPAA, SOC 2, HITRUST, or GDPR; healthcare experience preferred.
  • Experience working directly with external auditors.
  • Able to collaborate with security engineers, DevSecOps, and leadership and communicate risk clearly.

Responsibilities

  • Maintain ClearDATA's Information Security Management Program: policies, procedures, and standards behind our security and compliance posture.
  • Support audits, assessments, and certification renewals for HIPAA, GDPR, HITRUST, and SOC 2.
  • Maintain the risk register, including tracking third-party and vendor risk.
  • Keep control mapping and audit evidence current and organized.
  • Support incident response planning alongside the IT/ITSec Manager and security team.
  • Partner with security engineers and DevSecOps to translate control requirements into how systems are built and operated, and turn what they've built into defensible audit evidence.
  • Update policies and program documentation as systems, vendors, or ownership of shared responsibilities change; work directly with auditors to close gaps.

Job description

We're looking for a Senior GRC Manager to own our GRC program end to end and keep ClearDATA aligned with HIPAA, GDPR, HITRUST, SOC 2, etc. You'll maintain our Information Security Management Program, manage audit cycles, and work directly with auditors, including keeping policy and compliance documentation accurate as our systems and vendors evolve. We want someone who treats compliance as a way to help the business move with confidence, not a set of hoops for other teams to jump through. You'll look for the practical, risk-based path to "yes" whenever one exists, and reserve hard stops for when they're truly warranted. This is a hands‑on, senior role on our IT/ITSec team. You won't have direct reports, but you won't be working alone either — you'll have security engineers, DevSecOps, and leadership alongside you. We're looking for someone who'd rather build the control mapping than write a memo about who should build it.

What You’ll Own
  • Maintain ClearDATA's Information Security Management Program: the policies, procedures, and standards behind our security and compliance posture.
  • Support audits, assessments, and certification renewals for HIPAA, GDPR, HITRUST, and SOC 2.
  • Maintain the risk register, including tracking third-party and vendor risk.
  • Keep control mapping and audit evidence current and organized.
  • Support incident response planning alongside the IT/ITSec Manager and security team.
  • Partner with security engineers and DevSecOps to translate control requirements into how systems are actually built and operated — and to turn what they've built into defensible audit evidence.
  • Documentation & Audit Liaison
    • Update policies and program documentation as systems, vendors, or ownership of shared responsibilities change.
    • Work directly with auditors to catch and close compliance gaps before they become findings.
    • Flag open risk or outstanding items that need attention.
  • Act as the go-to compliance resource across the company — engineering, DevSecOps, management, and executive leadership — helping teams find a workable path forward rather than just pointing at policy, and giving leadership a clear read on where the program stands.
What We're Looking For
  • 5+ years in GRC, IT compliance, or information security compliance, ideally in a regulated industry, in hands‑on roles rather than oversight or advisory.
  • Direct experience maintaining an Information Security Management Program or similar compliance program.
  • Working knowledge of HIPAA, SOC 2, HITRUST, or GDPR; healthcare experience strongly preferred.
  • Experience working directly with external auditors.
  • Proven ability to work across a technical organization and up to executive leadership — credible with security engineers and DevSecOps on the details, and able to give management and execs a straight answer on risk without burying it in framework
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior GRC Manager - Hands-on Security & Compliance
Senior GRC Manager - Hands-on Security & Compliance

Harris Computer • Illinois

On-site
USD 130,000 - 150,000
We empower our employees to make a dif
Award-winning culture
Opportunity to learn
+2
Senior GRC Manager — Compliance, Risk & Audit
Senior GRC Manager — Compliance, Risk & Audit

MediSolution • Washington (NC)

On-site
USD 120,000 - 180,000
Senior GRC Manager - Flexible, Impactful Compliance Lead
Senior GRC Manager - Flexible, Impactful Compliance Lead

Harris Computer • Idaho

On-site
USD 130,000 - 150,000
Full benefits package
3 weeks of vacation + 5 personal days
Employee stock ownership
+2
Senior GRC Lead — Build Compliance that Drives Confidence
Senior GRC Lead — Build Compliance that Drives Confidence

ClearData Networks, Inc. in • Raleigh (NC)

On-site
USD 130,000 - 170,000
Opportunity to learn
Vacation + personal days
Employee stock ownership
+2
Senior GRC Manager — Flexible, Audit‑Driven Security Lead
Senior GRC Manager — Flexible, Audit‑Driven Security Lead

Harris Computer • Colorado

On-site
USD 130,000 - 150,000
We empower our employees to make a dif
We have an award-winning culture
We offer opportunity to learn
+2
Senior GRC Manager: Practical Compliance & Audit Readiness
Senior GRC Manager: Practical Compliance & Audit Readiness

Harris Computer • Minnesota

On-site
USD 130,000 - 150,000
Benefits package
3 weeks vacation + 5 personal days
Employee stock ownership
+2
Senior GRC Manager: Lead Practical HIPAA & SOC2 Compliance
Senior GRC Manager: Lead Practical HIPAA & SOC2 Compliance

Harris Computer • Maine

On-site
USD 130,000 - 150,000
We empower our employees to make a差 a
We have an award‑winning culture
We offer opportunity to learn
+2
Senior GRC Leader — HIPAA, SOC 2 & HITRUST
Senior GRC Leader — HIPAA, SOC 2 & HITRUST

Harris Computer • Oregon (WI)

On-site
USD 130,000 - 150,000
Health benefits
Vacation + personal days
Stock ownership
+2
Senior GRC Manager: Lead HIPAA, GDPR & SOC 2 Compliance
Senior GRC Manager: Lead HIPAA, GDPR & SOC 2 Compliance

Harris Computer • Arizona

On-site
USD 130,000 - 150,000
Full benefits package medical, dental,
3 weeks of vacation
5 personal days
+3
Senior GRC Lead: End-to-End HIPAA & SOC 2 Compliance
Senior GRC Lead: End-to-End HIPAA & SOC 2 Compliance

Harris Computer • Arkansas

On-site
USD 130,000 - 150,000
Full benefits package
3 weeks vacation + 5 personal days
Employee stock ownership
+2