GRC Manager

Nabla Technologies

$110K — $130K *
US-AnywhereRemote in United States
Healthcare
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 4+ years of experience in GRC, Information Security, or a closely related function, with a focus on building or scaling programs.
  • Hands-on experience in a high-growth SaaS or technology company.
  • Proficient in using GRC platforms and tools for compliance and risk management.
  • Expertise in compliance frameworks like SOC 2 Type II and ISO 27001.
  • Preferred experience in healthcare, with knowledge of HIPAA regulations.
  • Experience in conducting product and enterprise risk assessments, alongside risk quantification methodologies.
  • Interest in automation, particularly in relation to AI.

Responsibilities

  • Collaborate with cross-functional teams to advance GRC programs.
  • Manage the library of GRC control evidence and oversee investigation processes.
  • Administer the vendor risk program, including assessments and ongoing monitoring.
  • Interpret security assurance artifacts and compliance attestations.
  • Assist in implementing security and risk management frameworks and adding new controls.
  • Support security questionnaires and client audits, managing related documentation.
  • Track information security risks and remediation plans within GRC activities.

Benefits

  • Competitive salary and stock options.
  • 100% coverage for Medical, Dental, and Vision insurance.
  • Unlimited paid time off and 11 national holidays.
  • Unlimited sick leave available.
  • Paid parental leave for new parents.
  • $1,000 allowance for home office equipment.
  • Full ownership of your time and schedule.
Full Job Description
The Role

As our GRC Manager, you'll play a key role in scaling Nabla's security and compliance programs as we continue to grow. In this highly cross-functional role, you'll partner with Security, Engineering, Product, Legal, and customer-facing teams to build and mature our governance, risk, and compliance programs that enable the business to scale securely. This is an opportunity to shape foundational security processes, support enterprise growth, and help maintain the trust of clinicians, healthcare organizations, and partners.

Responsibilities
  • Reporting to the Head of Information Security & Compliance, you will work alongside Security, Engineering, Product and Legal teams to mature Nabla's Governance, Risk & Compliance programs
  • Manage the GRC control evidence library including investigation of control flags and evidence collection
  • Manage the vendor risk program including intake of new vendor requests, security and risk assessments, periodic reviews and ongoing vendor monitoring
  • Review and interpret security assurance artifacts such as SOC 2 Type II reports, penetration test reports, CAIQ, SIG, ISO certifications, and other compliance attestations
  • Assist the Head of Information Security with the implementation and ongoing operation of security and risk management frameworks, including net new control additions (e.g., GDPR, ISO, SOC 2)
  • Assist the Head of Information Security with security questionnaires and client audits including management of knowledge base and tracking
  • Support cyber GRC activities, including tracking information security risks, risk exceptions, and remediation plans
  • Manage security/compliance onboarding requirements including security awareness training, access checklists, and quarterly access reviews
  • Assist with the administration and continuous improvement of the company's security awareness and training program, including tracking completion metrics and updating training content as needed
  • Own the ongoing review and maintenance of organizational security policies, standards, and procedures. Assist in identifying policy gaps based on evolving regulatory requirements, business needs, and industry best practices
Qualifications
  • 4+ years of experience in GRC, Information Security, or a closely related function - with meaningful time spent building or scaling programs, not just running them
  • Demonstrated hands-on experience in GRC program at scale - ideally in a high-growth SaaS or technology company
  • Experience working with GRC platforms and tooling to manage compliance activities, risk registers, policy lifecycle management, audit evidence collection, and workflow automation
  • Deep expertise across multiple compliance and security frameworks, including SOC 2 Type II, ISO 27001
  • Healthcare experience preferred - HIPAA background and understanding of controls
  • Experience conducting and managing product & enterprise risk assessments, with a working knowledge of risk quantification methodologies
  • AI forward individual who will look to automate manual processes today
  • Relevant certifications strongly preferred: CISM, CRISC, CISA, CCSP, or comparable credentials
Benefits

Just like we're dedicated to supporting doctors' well-being, ensuring yours is a top priority. We firmly believe that by prioritizing your well-being, we support you to excel in your work.

Here are the benefits you get when joining Nabla:
  • Compensation and Equity: Competitive salary and stock options
  • Comprehensive Health Plans: 100% individual coverage for Medical, Dental, and Vision insurance
  • Time Off: Unlimited paid time off and 11 national holidays
  • Health Comes First: Unlimited sick leave
  • Parental Leave: Paid leave for new parents
  • Remote-friendly: $1,000 to purchase home office equipment
  • Trust & accountability: Full ownership of your time and schedule

Similar Jobs

More Jobs at Nabla Technologies

  • GRC Manager
    $110K — $130K *
    Remote
    Healthcare
    Remote in United States
  • Senior Brand Designer
    $90K — $120K *
    Remote
    Media
    Remote in United States
  • SRE / Backend Engineer
    $120K — $150K *
    New York, NY 10025 (New York County)
    Information Technology
    In-Person

More Healthcare Jobs

Find similar GRC Manager jobs: