Security GRC Manager
MiddleRemoteSalary undisclosed
Required Skills
AWS
Job Description
ABOUT THE ROLE:
Join Rightway as a Security GRC Manager, a role that owns and matures our GRC function. You will enhance our policies and procedures, streamline workflows, mature our risk management program, own our integrated SOC 2 + HITRUST attestation as we scale, and lead the GRC team.
WHAT YOU’LL DO:
- Team Leadership: Lead and mentor a small GRC team, setting priorities, reviewing work, and growing the function alongside the business.
- Control Library Development: Own and evolve our unified control library, maintaining mappings across SOC 2, SOC 1, and the latest HITRUST version, and addressing gaps or inefficiencies as the organization and framework requirements change.
- Audit Ownership: In partnership with Engineering, IT, People, and Finance, lead the audit program for control requirements and evidence production, proactively in anticipation of SOC 1, SOC 2/HITRUST, and customer audits.
- Data Privacy and Protection: Partner with Legal as a key stakeholder in the Data Privacy program, including HIPAA/HITECH, BAAs, data privacy and protection impact assessments, incident/breach analysis, and data handling requirements.
- AI Governance: Own and mature the AI governance program modeled after ISO/IEC 42001, including the AI risk register, Statement of A
Ready to apply? Optimize your CV for this specific jobAI customizes your experience bullets and increases chances to get hired.