Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Virta Health

Senior Manager, Governance, Risk, Compliance

Virta Health

Lead Governance, Risk, and Compliance for healthcare company focused on reversing metabolic disease. Oversee compliance automation and collaborate with teams to ensure security readiness.

Posted 7/31/2026full-timeRemote • Alaska, Hawaii, Maine, Mississippi, New Mexico, Oklahoma, Rhode Island, South Dakota, Vermont, Wisconsin • 🇺🇸 United StatesSenior💰 $161,500 - $209,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates extensive experience in Cybersecurity GRC and Information Security Compliance, with a strong focus on managing frameworks such as HITRUST CSF, HIPAA, and SOC 2. Proven ability to lead cross-functional teams and implement effective compliance programs using modern SaaS platforms.

Highest-signal resume keywords
Cybersecurity GRC ManagementHITRUST CSF ComplianceHIPAA ComplianceSOC 2 ComplianceSaaS GRC Automation

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Information Security ComplianceRisk AssessmentVendor Risk AssessmentSecurity Policy DevelopmentAudit Readiness
Soft Skills
Client-Facing CommunicationCross-Functional LeadershipInfluencing Skills
Tools & Technologies
VantaDrataZendeskJira
Industry Keywords
Healthcare ComplianceDigital HealthAI GovernanceNIST AI RMFISO 42001

Tech Stack

Tools & technologies
Cyber Security

About the role

Key responsibilities & impact
  • Maintain and mature Virta Health's information security compliance program, policies, procedures, and controls to address emerging risks as the organization scales.
  • Oversee Virta’s GRC function, scaling our platform (Vanta) to automate continuous evidence collection, ensuring audit-readiness and defending our HIPAA, HITRUST CSF, and SOC 2 certifications.
  • Partner directly with Sales and Customer Success to navigate enterprise customer evaluations and security reviews, communicating Virta's strong security compliance posture to external stakeholders.
  • Define and own Virta's security policy lifecycle, exception management processes, vendor risk assessments, and executive risk reporting.
  • Conduct regular risk assessments to identify vulnerabilities, assess potential impact, and guide business owners on mitigation.
  • Manage the administrative security queue for Virta employees. Design and optimize frictionless ticketing workflows (such as Zendesk or Jira) and SLAs for access governance reviews, SaaS tool compliance evaluations, and policy exception requests.
  • Collaborate closely with IT, Enterprise Security Engineering, and Product Development teams to ensure operational GRC policies map seamlessly into our technical architectures and evolving AI governance frameworks (e.g., ISO 42001, NIST AI RMF).
  • Champion a culture of security awareness across all levels of the organization. Design and deliver targeted training programs so employees understand their roles in maintaining compliance and data privacy.

Requirements

What you’ll need
  • 7+ years of dedicated experience in Cybersecurity GRC, IT Auditing, or Information Security Compliance, with at least 2+ years leading programs or managing teams in regulated environments (such as Healthcare or Digital Health).
  • Direct, hands-on experience managing and maintaining at least one of the major security and healthcare frameworks, specifically HITRUST CSF, HIPAA, and SOC 2.
  • Proven track record of leveraging modern SaaS GRC automation platforms (such as Vanta or Drata) to scale continuous compliance programs.
  • Outstanding client-facing communication skills with a track record of partnering with Sales/CS teams to navigate complex enterprise security evaluations, vendor questionnaires, and RFP processes.
  • Successfully designed and implemented repeatable AI-enabled workflows that address team bottlenecks and improve efficiency.
  • Ability to operate in gray areas, finding the right balance between corporate risk tolerance, operational efficiency, and regulatory requirements.
  • Strong cross-functional leadership skills with the ability to influence technical and non-technical business partners to align on security compliance objectives.

Benefits

Comp & perks
  • Offers Equity 📊 Check your resume score for this job Improve your chances of getting an interview by checking your resume score before you apply. Check Resume Score