Lead Virta Health's Governance, Risk, and Compliance (GRC) function in an AI-first healthcare environment. Manage compliance automation with Vanta, support commercial RFPs/questionnaires, maintain HITRUST/HIPAA/SOC 2 certifications, conduct risk assessments, and drive security awareness while optimizing employee compliance workflows.
162k – 209k/yr
Remote7+ YOESecurity Engineering
About the role
Responsibilities
Maintain and mature Virta Health's information security compliance program, policies, procedures, and controls to address emerging risks as the organization scales.
Continuously evaluate and enhance the GRC framework to align with industry best practices and regulatory requirements.
Lead GRC & Compliance Automation: Oversee Virta’s GRC function, scaling our platform (Vanta) to automate continuous evidence collection, ensuring audit-readiness and defending our HIPAA, HITRUST CSF, and SOC 2 certifications.
Enable Commercial Velocity (RFPs & Security Questionnaires): Partner directly with Sales and Customer Success to navigate enterprise customer evaluations and security reviews, communicating Virta's strong security compliance posture to external stakeholders.
Own Policy, Risk & Compliance Governance: Define and own Virta's security policy lifecycle, exception management processes, vendor risk assessments, and executive risk reporting. Conduct regular risk assessments to identify vulnerabilities, assess potential impact, and guide business owners on mitigation.
Champion GRC Employee Experience: Manage the administrative security queue for Virta employees. Design and optimize frictionless ticketing workflows (such as Zendesk or Jira) and SLAs for access governance reviews, SaaS tool compliance evaluations, and policy exception requests.
Coordinate Cross-Functional Security Alignment: Collaborate closely with IT, Enterprise Security Engineering, and Product Development teams to ensure operational GRC policies map seamlessly into our technical architectures and evolving AI governance frameworks (e.g., ISO 42001, NIST AI RMF).
Security Awareness & Compliance Training: Champion a culture of security awareness across all levels of the organization. Design and deliver targeted training programs so employees understand their roles in maintaining compliance and data privacy.
90 Day Plan
First 30 days: Deep dive into our current GRC tool configurations (Vanta), evaluate our control framework status, meet with key stakeholders across IT and Security Engineering, and take ownership of the daily employee SaaS review and GRC request queue.
Day 30-60: Establish baseline SLAs for employee compliance requests (SaaS reviews, access reviews) and optimize automation workflows to streamline customer security questionnaire and RFP responses. Initiate coordination with external auditors and partners for upcoming assessments.
Day 60-90: Complete a comprehensive internal risk assessment and present a clean, unified risk and compliance metric dashboard to senior leadership covering GRC control health, exception trends, and upcoming audit preparation timelines.
Must-Haves
7+ years of dedicated experience in Cybersecurity GRC, IT Auditing, or Information Security Compliance, with at least 2+ years leading programs or managing teams in regulated environments (such as Healthcare or Digital Health).
Direct, hands-on experience managing and maintaining at least one of the major security and healthcare frameworks, specifically HITRUST CSF, HIPAA, and SOC 2.
Proven track record of leveraging modern SaaS GRC automation platforms (such as Vanta or Drata) to scale continuous compliance programs.
Outstanding client-facing communication skills with a track record of partnering with Sales/CS teams to navigate complex enterprise security evaluations, vendor questionnaires, and RFP processes.
Successfully designed and implemented repeatable AI-enabled workflows that address team bottlenecks and improve efficiency.
Ability to operate in gray areas, finding the right balance between corporate risk tolerance, operational efficiency, and regulatory requirements.
Strong cross-functional leadership skills with the ability to influence technical and non-technical business partners to align on security compliance objectives.
Senior Detection Engineer responds to security incidents, triages alerts, tunes runbooks, and builds automation for threat detection in federal environments. Requires 3-4 years IT experience, SOC background, and log analysis tools like ELK/Datadog.
Lead AWS and network security infrastructure, zero-trust initiatives, and cloud automation for enterprise environments. Requires strong AWS, networking, IAM, and scripting experience.
160k – 215k/yrOn-site5+ YOESecurity Engineering
Senior Software Engineer, Information Security
CommureMountain View, CA
Senior Software Engineer architects scalable detection frameworks, integrates threat intelligence into automated security pipelines, and builds AI-driven security operations using Python, Java, and tools like Splunk and AWS. Requires 6+ years experience, bachelor's in CS/cybersecurity, and expertise in SIEMs, cloud security, and compliance.
160k – 190k/yrHybrid6+ YOESecurity Engineering
Risk and Compliance Lead
Applied IntuitionSunnyvale, CA
Leads security GRC program, conducts enterprise risk assessments, manages compliance audits like SOC2/ISO 27001/TISAX, drives TPRM, and builds GRC infrastructure. Requires 6+ years in security compliance with hands-on audit and tooling experience.
160k – 190k/yrOn-site6+ YOESecurity Engineering
Senior Privacy Engineer
UpstartUnited States
Senior Privacy Engineer building and operating privacy-by-design systems, APIs, and controls for data governance, minimization, and ML pipelines at an AI lending platform. Requires 5+ years software engineering experience and background in privacy/security domains.