17h ago
Senior Governance, Risk, Compliance (GRC) Analyst
New York, NY | San Francisco, CA | Seattle, WA
$161.6k-$202k / year
full-timeseniorhealthcare
๐ Tech Stack
๐ผ About This Role
You'll join Headway's Security team to build and mature a modern, AI-enabled GRC program. Your work directly protects millions of patients accessing mental healthcare. You'll stand up the GRC function from scratch, not inherit legacy processes.
๐ฏ What You'll Do
- Support HITRUST, SOC 2, PCI-DSS, and HIPAA audit readiness
- Build and manage vendor security assessment lifecycle
- Stand up and run security awareness training program
- Operate centralized risk register and surface risk-informed priorities
๐ Requirements
- 5+ years in a GRC, compliance, or security risk role
- Working knowledge of at least two of: HITRUST, SOC 2, PCI-DSS, or HIPAA
- Experience with a GRC platform like Vanta, Drata, OneTrust, or similar
- Ability to communicate compliance requirements to both technical and non-technical audiences
โจ Nice to Have
- Worked in healthcare or healthtech
- Understanding of HIPAA in practice, not just theory
๐ Benefits & Perks
- ๐ฐ Equity compensation
- ๐ฅ Medical, Dental, and Vision coverage
- ๐๏ธ Flexible PTO
- ๐ถ 16-week parental leave
- ๐ Training and professional development
๐จ Hiring Process
Estimated timeline: 2-4 weeks ยท AI estimate
- 1Recruiter Phone Screenยท 30 min
- 2Technical Interview with Hiring Managerยท 60 min
- 3Cross-functional Panelยท 60 min
- 4Offerยท N/A
0 0 0