GRC Manager
United StatesJob Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
The Role
As our GRC Manager, you'll play a key role in scaling Nabla's security and compliance programs as we continue to grow. In this highly cross-functional role, you'll partner with Security, Engineering, Product, Legal, and customer-facing teams to build and mature our governance, risk, and compliance programs that enable the business to scale securely. This is an opportunity to shape foundational security processes, support enterprise growth, and help maintain the trust of clinicians, healthcare organizations, and partners.
Responsibilities
Reporting to the Head of Information Security & Compliance, you will work alongside Security, Engineering, Product and Legal teams to mature Nabla’s Governance, Risk & Compliance programs
Manage the GRC control evidence library including investigation of control flags and evidence collection
Manage the vendor risk program including intake of new vendor requests, security and risk assessments, periodic reviews and ongoing vendor monitoring
Review and interpret security assurance artifacts such as SOC 2 Type II reports, penetration test reports, CAIQ, SIG, ISO certifications, and other compliance attestations
Assist the Head of Information Security with the implementation and ongoing operation of security and risk management frameworks, including net new control additions (e.g., GDPR, ISO, SOC 2)
Assist the Head of Information Security with security questionnaires and client audits including management of knowledge base and tracking
Support cyber GRC activities, including tracking information security risks, risk exceptions, and remediation plans
Manage security/compliance onboarding requirements including security awareness training, access checklists, and quarterly access reviews
Assist with the administration and continuous improvement of the company’s security awareness and training program, including tracking completion metrics and updating training content as needed
Own the ongoing review and maintenance of organizational security policies, standards, and procedures. Assist in identifying policy gaps based on evolving regulatory requirements, business needs, and industry best practices
Qualifications
4+ years of experience in GRC, Information Security, or a closely related function — with meaningful time spent building or scaling programs, not just running them
Demonstrated hands-on experience in GRC program at scale — ideally in a high-growth SaaS or technology company
Experience working with GRC platforms and tooling to manage compliance activities, risk registers, policy lifecycle management, audit evidence collection, and workflow automation
Deep expertise across multiple compliance and security frameworks, including SOC 2 Type II, ISO 27001
Healthcare experience preferred - HIPAA background and understanding of controls
Experience conducting and managing product & enterprise risk assessments, with a working knowledge of risk quantification methodologies
AI forward individual who will look to automate manual processes today
Relevant certifications strongly preferred: CISM, CRISC, CISA, CCSP, or comparable credentials
How would you rate this job post?
See what other professionals think about this role.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.