Senior Manager, GRC

mavenclinic

United States

On-site

USD 120,000 - 180,000

Full time

4 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Maven Clinic is seeking a GRC Manager to own governance, risk, and compliance for our B2B health benefits platform. You will lead audits, write policies, manage certifications, and interact with auditors, customers, and partners.

You will partner with Engineering, IT, and HR to gather evidence, close gaps, and maintain compliance posture across initiatives.

Qualifications

  • 6+ years of experience in GRC, information security compliance, or IT audit.
  • Direct ownership of at least one SOC 2 or similar audit cycle from start to finish.
  • Experience coordinating audits with cross-functional teams.

Responsibilities

  • Own external audit & certification management end-to-end (SOC 2, HITRUST).
  • Lead ISO 27001 / ISO 42001 program development and readiness.
  • Manage internal audit and control-monitoring program.
  • Serve as primary security & compliance owner in customer interactions.
  • Collaborate with Engineering, IT, HR, Legal and Sales to close findings.

Skills

GRC experience
SOC 2 ownership
Audit management
ISO 27001 readiness
Regulatory knowledge

Job description

Maven Clinic is the world's largest virtual clinic for women and families on a mission to make healthcare work for all of us. Through Maven Enterprise, the company partners with more than 2,300 employers and health plans to provide end-to-end women's and family health programs spanning fertility and family building, maternity and newborn care, parenting and pediatrics, and menopause and midlife - improving clinical outcomes, reducing healthcare costs, and expanding equitable access to high-quality care at scale. Through its consumer platform, Maven provides direct access to virtual care across 30+ specialties, as well as dedicated hormone and GLP-1 care programs purpose-built for women. Founded in 2014 by CEO Kate Ryder, Maven Clinic has raised more than $425 million from leading healthcare and technology investors including General Catalyst, Sequoia, Dragoneer Investment Group, Oak HC/FT, StepStone Group, Icon Ventures, and Lux Capital. Recognized for innovation and industry leadership, Maven has been named to the TIME100 Most Influential Companies, CNBC Disruptor 50, Fast Company's Most Innovative Companies, and FORTUNE Best Places to Work. Learn more at mavenclinic.com

An award-winning culture working towards an important mission - Maven Clinic is a recipient of over 30 workplace and innovation awards, including:

  • TIME 100 Most Influential Companies (2023, 2026)
  • Fortune Change the World (2024)
  • CNBC Disruptor 50 List (2022, 2023, 2024)
  • Fortune Best Workplaces for Millennials (2024)
  • Fortune Best Workplaces in Health Care (2024)
  • Fast Company Most Innovative Companies (2020, 2023)
  • Fortune Best Workplaces NY (2020, 2021, 2022, 2023, 2024)
About the Role:

We're looking for a GRC Manager to own governance, risk, and compliance for our B2B health benefits platform. You'll act as the team lead for our GRC function, working closely with one other team member to run audits, write policies, answer RFIs, and monitor controls day to day.

This role touches almost every team: partnering with Engineering, IT, and HR to gather evidence and close gaps; working directly with customers and their security teams during due diligence; and managing auditor relationships through certification cycles. You'll also bring solid project management skills, sequencing audits, tracking remediation, and hitting deadlines across multiple concurrent workstreams. You'll report directly to the CISO/Head of Security and act as the organization's primary voice on compliance posture. You will interface internally and externally with customers, auditors, and partners.

Our platform facilitates virtual health visits for employer-sponsored benefits, which means security, privacy, and compliance are core to customer trust and our ability to sell into enterprise and health-plan accounts.

What You'll Do:
External Audit & Certification Management
  • Own continuation and renewal of our SOC 2 (Type II) and HITRUST certifications end-to-end. You'll scope each cycle, pull evidence, work directly with auditors, and track remediation through to the final report.
  • Lead the ground-up establishment of ISO 27001 and ISO 42001 certification programs. That means gap assessments, control mapping, writing ISMS/AIMS policies and statements of applicability, gaining cross team buy in, and getting us ready for initial certification audits.
  • Manage the annual/ongoing audit calendar across all frameworks, coordinating with internal stakeholders (Engineering, IT, HR, Legal) to gather evidence and close findings on time.
  • Track regulatory and framework changes (HIPAA, state privacy laws, ISO updates) and translate them into control updates.
Customer-Facing Security & Compliance
  • Serve as the primary owner of security questionnaires and RFIs/RFPs for the Sales and Customer Success teams. Ensure responses to prospect and customer's due-diligence requests are accurate and on deadline.
  • Maintain a security knowledge base / answer library to reduce turnaround time on recurring questions.
  • Partner with Sales Engineering and Account teams to represent our security and compliance posture directly in customer calls when needed. You'll join customer calls directly when security is a blocker in the deal.
  • Manage relationships with customers' internal security/compliance teams during onboarding and renewal cycles.
Internal Audit & Control Monitoring
  • Build and run an internal audit/control-monitoring program focused first on verifying that externally audited controls are actually operating day-to-day.
  • Flag control gaps or process drift to the CISO/Head of Security before they become audit findings.
  • Over time, expand scope beyond audited-control verification into broader internal audit territory (policy adherence, vendor risk, operational risk) as bandwidth allows.
What You'll Bring:
Required:
  • 6+ years of experience in GRC, information security compliance, or IT audit, with direct ownership of at least one SOC 2 or similar audit cycle from start to finish.
  • Working kno
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Manager, GRC
Senior Manager, GRC

Femtech Insider Ltd. • Town of Texas (WI)

Hybrid
USD 170,000 - 201,000
Hybrid work model
Equity
16 weeks paid parental leave
+3
Senior Manager, GRC
Senior Manager, GRC

Maven Clinic Co. • New York (NY), Northern (KY)

Hybrid
USD 170,000 - 201,000
Hybrid work model
Parental leave & family support
401K matching
GRC Leader: SOC 2, HITRUST & ISO 27001 Expert
GRC Leader: SOC 2, HITRUST & ISO 27001 Expert

Maven Clinic Co. • New York (NY), Northern (KY)

Hybrid
USD 170,000 - 201,000
Hybrid work model
Parental leave & family support
401K matching
GRC Manager: SOC2/HITRUST Security Leader
GRC Manager: SOC2/HITRUST Security Leader

Femtech Insider Ltd. • Town of Texas (WI)

Hybrid
USD 170,000 - 201,000
Hybrid work model
Equity
16 weeks paid parental leave
+3
GRC Analyst
GRC Analyst

Fireworks AI • San Mateo (CA)

On-site
USD 110,000 - 170,000
Senior Manager, GRC
Senior Manager, GRC

Jobtailor • California (MO)

On-site
USD 130,000 - 165,000
GRC Compliance Auditor
GRC Compliance Auditor

NMC2 • Dallas (TX), Northern (KY)

Hybrid
USD 120,000 - 160,000
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

RELX • Raleigh (NC)

On-site
USD 118,000 - 220,000
Annual incentive bonus
GRC Analyst
GRC Analyst

NMC2 • Dallas (TX), Northern (KY)

Hybrid
USD 81,000 - 99,000
Senior Governance, Risk & Compliance (GRC) Analyst
Senior Governance, Risk & Compliance (GRC) Analyst

Cianbro • Pittsfield (ME)

On-site
Employee-owned
Equal opportunity employer