17h ago

Senior Governance, Risk, Compliance (GRC) Analyst

New York, NY | San Francisco, CA | Seattle, WA

$161.6k-$202k / year

full-timeseniorhealthcare

๐Ÿ›  Tech Stack

๐Ÿ’ผ About This Role

You'll join Headway's Security team to build and mature a modern, AI-enabled GRC program. Your work directly protects millions of patients accessing mental healthcare. You'll stand up the GRC function from scratch, not inherit legacy processes.

๐ŸŽฏ What You'll Do

  • Support HITRUST, SOC 2, PCI-DSS, and HIPAA audit readiness
  • Build and manage vendor security assessment lifecycle
  • Stand up and run security awareness training program
  • Operate centralized risk register and surface risk-informed priorities

๐Ÿ“‹ Requirements

  • 5+ years in a GRC, compliance, or security risk role
  • Working knowledge of at least two of: HITRUST, SOC 2, PCI-DSS, or HIPAA
  • Experience with a GRC platform like Vanta, Drata, OneTrust, or similar
  • Ability to communicate compliance requirements to both technical and non-technical audiences

โœจ Nice to Have

  • Worked in healthcare or healthtech
  • Understanding of HIPAA in practice, not just theory

๐ŸŽ Benefits & Perks

  • ๐Ÿ’ฐ Equity compensation
  • ๐Ÿฅ Medical, Dental, and Vision coverage
  • ๐Ÿ–๏ธ Flexible PTO
  • ๐Ÿ‘ถ 16-week parental leave
  • ๐Ÿ“š Training and professional development

๐Ÿ“จ Hiring Process

Estimated timeline: 2-4 weeks ยท AI estimate

  1. 1Recruiter Phone Screenยท 30 min
  2. 2Technical Interview with Hiring Managerยท 60 min
  3. 3Cross-functional Panelยท 60 min
  4. 4Offerยท N/A
0 0 0