Senior Manager, GRC

Jobtailor

California (MO)

On-site

USD 130,000 - 165,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Jobtailor is seeking a Senior GRC/Compliance Lead to own end-to-end certification programs (SOC 2, HITRUST, ISO 27001) and drive audit calendars in a fast-paced SaaS environment. You will coordinate with Engineering, IT, HR, Legal, andSales to gather evidence, close findings, and translate regulatory changes into control updates.

The role requires 6+ years in GRC or IT audit, direct ownership of at least one audit cycle, and strong communications.

Qualifications

  • 6+ years of experience in GRC, information security compliance, or IT audit.
  • Direct ownership of at least one SOC 2 or similar audit cycle from start to finish.
  • Working knowledge of SOC 2, HITRUST, and ISO 27001 frameworks.
  • Experience responding to customer security questionnaires/RFIs, ideally in a B2B SaaS or healthcare-adjacent environment.
  • Strong cross-team collaboration skills.
  • Project management skills, including sequencing overlapping audits and certification projects, tracking dependencies and remediation items, and meeting deadlines.
  • Strong written communication skills for policies, RFI responses, and audit narratives.
  • Strongly preferred: experience establishing new certifications such as SOC 2, HITRUST, ISO 27001, or ISO 42001.
  • Strongly preferred: experience with GRC/compliance automation tools such as Vanta, Drata, Secureframe, or Hyperproof.
  • Strongly preferred: background in health tech, digital health, fintech, insurtech, or another regulated B2B vertical.
  • Strongly preferred: CISA, CRISC, CISSP, PMP, CAPM, CISM, or CTRC/CAP certification.
  • Strongly preferred: exposure to vulnerability management or IT operations.
  • Strongly preferred: experience partnering with Sales or Sales Engineering as a technical or compliance resource.

Responsibilities

  • Demonstrates expertise in managing SOC 2, HITRUST, and ISO certification processes, including audit preparation and compliance management.
  • Possesses strong project management and cross-team collaboration skills to effectively coordinate with various stakeholders and ensure adherence to regulatory requirements.

Skills

GRC
Information Security
IT Audit
SOC 2
HITRUST
ISO 27001
Control Mapping
Audit Calendar Management
Regulatory Tracking
Security Questionnaire Management
Policy Adherence
Cross-Team Collaboration
Project Management
Written Communication
SOC 2/Audit Ownership

Tools

Vanta
Drata
Secureframe
Hyperproof

Job description

  • Own continuation and renewal of SOC 2 Type II and HITRUST certifications end-to-end
  • Establish ISO 27001 and ISO 42001 certification programs, including gap assessments, control mapping, ISMS/AIMS policies, statements of applicability, and certification-audit preparation
  • Manage the annual and ongoing audit calendar across frameworks
  • Coordinate with Engineering, IT, HR, Legal, and other stakeholders to gather evidence and close findings
  • Track regulatory and framework changes, including HIPAA, state privacy laws, and ISO updates, and translate them into control updates
  • Own security questionnaires and RFIs/RFPs for Sales and Customer Success
  • Maintain a security knowledge base and answer library
  • Represent security and compliance posture on customer calls when needed
  • Manage relationships with customer security and compliance teams during onboarding and renewals
  • Build and run an internal audit and control-monitoring program
  • Identify control gaps or process drift and report them to the CISO/Head of Security
  • Expand internal audit scope into policy adherence, vendor risk, and operational risk
  • Report directly to the CISO/Head of Security and serve as the primary voice on compliance posture
Requirements
  • 6+ years of experience in GRC, information security compliance, or IT audit
  • Direct ownership of at least one SOC 2 or similar audit cycle from start to finish
  • Working knowledge of SOC 2, HITRUST, and ISO 27001 frameworks
  • Experience responding to customer security questionnaires/RFIs, ideally in a B2B SaaS or healthcare-adjacent environment
  • Strong cross-team collaboration skills
  • Project management skills, including sequencing overlapping audits and certification projects, tracking dependencies and remediation items, and meeting deadlines
  • Strong written communication skills for policies, RFI responses, and audit narratives
  • Strongly preferred: experience establishing new certifications such as SOC 2, HITRUST, ISO 27001, or ISO 42001
  • Strongly preferred: experience with GRC/compliance automation tools such as Vanta, Drata, Secureframe, or Hyperproof
  • Strongly preferred: background in health tech, digital health, fintech, insurtech, or another regulated B2B vertical
  • Strongly preferred: CISA, CRISC, CISSP, PMP, CAPM, CISM, or CTRC/CAP certification
  • Strongly preferred: exposure to vulnerability management or IT operations
  • Strongly preferred: experience partnering with Sales or Sales Engineering as a technical or compliance resource
Core Competencies

Demonstrates expertise in managing SOC 2, HITRUST, and ISO certification processes, including audit preparation and compliance management. Possesses strong project management and cross-team collaboration skills to effectively coordinate with various stakeholders and ensure adherence to regulatory requirements.

Highest-signal resume keywords
  • SOC 2 Audit Management
  • HITRUST Certification
  • ISO 27001 Framework Knowledge
  • GRC/Compliance Automation Tools
  • Project Management Skills
Hard Skills
  • GRC
  • Information Security Compliance
  • IT Audit
  • Control Mapping
  • Audit Calendar Management
  • Regulatory Tracking
  • Control Gap Identification
  • Internal Audit Program Management
  • Security Questionnaire Management
  • Policy Adherence
Soft Skills
  • Cross-Team Collaboration
  • Written Communication
Certifications & Qualifications
  • CISA
  • CRISC
  • CISSP
  • PMP
  • CAPM
  • CISM
  • CTRC
  • CAP
Industry Keywords
  • B2B SaaS
  • Healthcare
  • Health Tech
  • Digital Health
  • Fintech
  • Insurtech
  • Regulated B2B Vertical
Tools & Technologies
  • Vanta
  • Drata
  • Secureframe
  • Hyperproof
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Analyst
GRC Analyst

Fireworks AI • San Mateo (CA)

On-site
USD 110,000 - 170,000
Senior Manager, GRC
Senior Manager, GRC

mavenclinic • United States

On-site
USD 120,000 - 180,000
Senior Technical Governance Program Manager
Senior Technical Governance Program Manager

Jobtailor • California (MO)

On-site
USD 120,000 - 190,000
Senior Security GRC Analyst
Senior Security GRC Analyst

Jobtailor • California (MO)

On-site
USD 120,000 - 170,000
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

RELX • Raleigh (NC)

On-site
USD 118,000 - 220,000
Annual incentive bonus
Security Compliance Analyst
Security Compliance Analyst

Harbinger Motors • Garden Grove (CA)

On-site
USD 110,000 - 160,000
Stock options
Flexible PTO
Health coverage
+2
Information Security Program Lead
Information Security Program Lead

MSA - The Safety Company • Cranberry Township

On-site
USD 120,000 - 180,000
Business Control Manager – Technology Risk & Regulatory Lead
Business Control Manager – Technology Risk & Regulatory Lead

Jobtailor • Pennington (NJ)

On-site
USD 120,000 - 180,000
Senior Manager of Risk and Compliance
Senior Manager of Risk and Compliance

PTR Global • United States

On-site
USD 100,000 - 130,000
GRC Intern
GRC Intern

Jobtailor • Center Square (PA)

On-site
USD 35,000 - 52,000