Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Nabla

GRC Manager

Nabla

GRC Manager responsible for scaling security and compliance programs for AI healthcare assistant. Collaborating with cross-functional teams to enhance governance and risk management frameworks.

Posted 7/29/2026full-timeRemote • 🇺🇸 United StatesMid-LevelSenior💰 $130,000 - $160,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in Governance, Risk, and Compliance (GRC) management, with a strong focus on compliance frameworks such as SOC 2 Type II and ISO 27001. Proficient in vendor risk management, security assessments, and the implementation of security awareness training programs.

Highest-signal resume keywords
GRC Program ManagementCompliance Framework ExpertiseVendor Risk ManagementSecurity Awareness TrainingRelevant Certifications

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
GRC Program ManagementRisk AssessmentCompliance FrameworksAudit Evidence CollectionPolicy Lifecycle ManagementWorkflow AutomationRisk Quantification MethodologiesSecurity Assurance Artifacts ReviewControl Evidence ManagementSecurity Policy Maintenance
Soft Skills
CollaborationCommunicationProblem-SolvingAttention to DetailAdaptability
Tools & Technologies
GRC PlatformsCompliance ToolsRisk Management SoftwareSecurity Assessment ToolsAudit Management Systems
Certifications & Qualifications
CISMCRISCCISACCSP
Industry Keywords
Information SecurityComplianceRisk ManagementSaaSHealthcareHIPAASOC 2 Type IIISO 27001

About the role

Key responsibilities & impact
  • Reporting to the Head of Information Security & Compliance, you will work alongside Security, Engineering, Product and Legal teams to mature Nabla’s Governance, Risk & Compliance programs
  • Manage the GRC control evidence library including investigation of control flags and evidence collection
  • Manage the vendor risk program including intake of new vendor requests, security and risk assessments, periodic reviews and ongoing vendor monitoring
  • Review and interpret security assurance artifacts such as SOC 2 Type II reports, penetration test reports, CAIQ, SIG, ISO certifications, and other compliance attestations
  • Assist the Head of Information Security with the implementation and ongoing operation of security and risk management frameworks, including net new control additions (e.g., GDPR, ISO, SOC 2)
  • Assist the Head of Information Security with security questionnaires and client audits including management of knowledge base and tracking
  • Support cyber GRC activities, including tracking information security risks, risk exceptions, and remediation plans
  • Manage security/compliance onboarding requirements including security awareness training, access checklists, and quarterly access reviews
  • Assist with the administration and continuous improvement of the company’s security awareness and training program, including tracking completion metrics and updating training content as needed
  • Own the ongoing review and maintenance of organizational security policies, standards, and procedures. Assist in identifying policy gaps based on evolving regulatory requirements, business needs, and industry best practices

Requirements

What you’ll need
  • 4+ years of experience in GRC, Information Security, or a closely related function — with meaningful time spent building or scaling programs, not just running them
  • Demonstrated hands-on experience in GRC program at scale — ideally in a high-growth SaaS or technology company
  • Experience working with GRC platforms and tooling to manage compliance activities, risk registers, policy lifecycle management, audit evidence collection, and workflow automation
  • Deep expertise across multiple compliance and security frameworks, including SOC 2 Type II, ISO 27001
  • Healthcare experience preferred - HIPAA background and understanding of controls
  • Experience conducting and managing product & enterprise risk assessments, with a working knowledge of risk quantification methodologies
  • AI forward individual who will look to automate manual processes today
  • Relevant certifications strongly preferred: CISM, CRISC, CISA, CCSP, or comparable credentials

Benefits

Comp & perks
  • Competitive salary and stock options
  • 100% individual coverage for Medical, Dental, and Vision insurance
  • Unlimited paid time off and 11 national holidays
  • Unlimited sick leave
  • Paid leave for new parents
  • $1,000 to purchase home office equipment
  • Full ownership of your time and schedule