Back to Jobs
Legal & HR 1h ago

GRC Manager

United StatesUnited States
Full-time
Not Disclosed
Mid-Level

Job Description

Key Skills Required

Master these to land this role

ComplianceRisk ManagementHIPAASOC 2Cybersecurity

Want to know if you're a match for this job?

Calculate My Match Score

The Role

As our GRC Manager, you'll play a key role in scaling Nabla's security and compliance programs as we continue to grow. In this highly cross-functional role, you'll partner with Security, Engineering, Product, Legal, and customer-facing teams to build and mature our governance, risk, and compliance programs that enable the business to scale securely. This is an opportunity to shape foundational security processes, support enterprise growth, and help maintain the trust of clinicians, healthcare organizations, and partners.

Responsibilities

  • Reporting to the Head of Information Security & Compliance, you will work alongside Security, Engineering, Product and Legal teams to mature Nabla’s Governance, Risk & Compliance programs

  • Manage the GRC control evidence library including investigation of control flags and evidence collection

  • Manage the vendor risk program including intake of new vendor requests, security and risk assessments, periodic reviews and ongoing vendor monitoring

  • Review and interpret security assurance artifacts such as SOC 2 Type II reports, penetration test reports, CAIQ, SIG, ISO certifications, and other compliance attestations

  • Assist the Head of Information Security with the implementation and ongoing operation of security and risk management frameworks, including net new control additions (e.g., GDPR, ISO, SOC 2)

  • Assist the Head of Information Security with security questionnaires and client audits including management of knowledge base and tracking

  • Support cyber GRC activities, including tracking information security risks, risk exceptions, and remediation plans

  • Manage security/compliance onboarding requirements including security awareness training, access checklists, and quarterly access reviews

  • Assist with the administration and continuous improvement of the company’s security awareness and training program, including tracking completion metrics and updating training content as needed

  • Own the ongoing review and maintenance of organizational security policies, standards, and procedures. Assist in identifying policy gaps based on evolving regulatory requirements, business needs, and industry best practices

Qualifications

  • 4+ years of experience in GRC, Information Security, or a closely related function — with meaningful time spent building or scaling programs, not just running them

  • Demonstrated hands-on experience in GRC program at scale — ideally in a high-growth SaaS or technology company

  • Experience working with GRC platforms and tooling to manage compliance activities, risk registers, policy lifecycle management, audit evidence collection, and workflow automation

  • Deep expertise across multiple compliance and security frameworks, including SOC 2 Type II, ISO 27001

  • Healthcare experience preferred - HIPAA background and understanding of controls

  • Experience conducting and managing product & enterprise risk assessments, with a working knowledge of risk quantification methodologies

  • AI forward individual who will look to automate manual processes today

  • Relevant certifications strongly preferred: CISM, CRISC, CISA, CCSP, or comparable credentials

How would you rate this job post?

See what other professionals think about this role.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More