L3Harris

Senior GRC Manager

L3Harris$130K — $150K *
US-Anywhere
+ 50 other locationsRemote
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years experience in GRC, IT compliance, or information security compliance, preferably in a regulated industry.
  • Hands-on experience maintaining an Information Security Management Program or similar compliance program.
  • Understanding of HIPAA, SOC 2, HITRUST, or GDPR, with healthcare experience preferred.
  • Experience engaging with external auditors to manage compliance assessments.
  • Ability to communicate effectively with technical teams and executive leadership regarding risk and compliance statuses.
  • Strong writing skills to articulate policy language from operational details.
  • Highly organized and detail-oriented, capable of managing multiple compliance responsibilities.

Responsibilities

  • Maintain ClearDATA's Information Security Management Program and compliance posture.
  • Support audits and assessments for HIPAA, GDPR, HITRUST, and SOC 2 certifications.
  • Manage the risk register, focusing on third-party and vendor risks.
  • Keep control mapping and audit evidence organized and up to date.
  • Assist with incident response planning alongside the IT/ITSec Manager.
  • Collaborate with security engineers and DevSecOps to implement compliance requirements in system operations.
  • Serve as the primary compliance resource for various teams within the company.

Benefits

  • Opportunity to lead a meaningful GRC program integral to the company's operations.
  • Collaborative work environment with security engineers and technical leadership.
  • Focus on pragmatic risk management rather than bureaucratic compliance procedures.
Full Job Description

We're looking for a Senior GRC Manager to own our GRC program end to end and keep ClearDATA aligned with HIPAA, GDPR, HITRUST, SOC 2, etc. You'll maintain our Information Security Management Program, manage audit cycles, and work directly with auditors, including keeping policy and compliance documentation accurate as our systems and vendors evolve.


We want someone who treats compliance as a way to help the business move with confidence, not a set of hoops for other teams to jump through. You'll look for the practical, risk-based path to "yes" whenever one exists, and reserve hard stops for when they're truly warranted. This is a hands-on, senior role on our IT/ITSec team. You won't have direct reports, but you won't be working alone either — you'll have security engineers, DevSecOps, and leadership alongside you. We're looking for someone who'd rather build the control mapping than write a memo about who should build it.


What You'll Own

Governance, Risk & Compliance

  • Maintain ClearDATA's Information Security Management Program: the policies, procedures, and standards behind our security and compliance posture.
  • Support audits, assessments, and certification renewals for HIPAA, GDPR, HITRUST, and SOC 2.
  • Maintain the risk register, including tracking third-party and vendor risk.
  • Keep control mapping and audit evidence current and organized.
  • Support incident response planning alongside the IT/ITSec Manager and security team.
  • Partner with security engineers and DevSecOps to translate control requirements into how systems are actually built and operated — and to turn what they've built into defensible audit evidence.

Documentation & Audit Liaison

  • Update policies and program documentation as systems, vendors, or ownership of shared responsibilities change.
  • Work directly with auditors to catch and close compliance gaps before they become findings.
  • Flag open risk or outstanding items that need attention.
  • Act as the go-to compliance resource across the company — engineering, DevSecOps, management, and executive leadership — helping teams find a workable path forward rather than just pointing at policy, and giving leadership a clear read on where the program stands.

What We're Looking For
  • 5+ years in GRC, IT compliance, or information security compliance, ideally in a regulated industry, in hands-on roles rather than oversight or advisory.
  • Direct experience maintaining an Information Security Management Program or similar compliance program.
  • Working knowledge of HIPAA, SOC 2, HITRUST, or GDPR; healthcare experience strongly preferred.
  • Experience working directly with external auditors.
  • Proven ability to work across a technical organization and up to executive leadership — credible with security engineers and DevSecOps on the details, and able to give management and execs a straight answer on risk without burying it in framework language.
  • Strong writing skills. You should be comfortable turning operational and technical detail into clear policy language.
  • Organized and detail-oriented, able to manage several compliance workstreams at once.
  • A pragmatic approach to risk: you can tell the difference between a real compliance issue and a theoretical one, and you'd rather solve a problem than just document it.

Nice to Have
  • CISA, HITRUST CCSFP, or CRISC certification — useful, but we care more about what you've actually run than what you've been certified in.
  • Experience with AWS, Azure, or GCP and related compliance considerations.
  • Experience with GRC tooling (e.g., Thoropass, OneTrust, or similar platforms).
  • A background that spans both compliance and a technical discipline (IT, security, or engineering), so you can speak both languages.

Why ClearDATA

You'll own a GRC program that matters, at a company where security and compliance are the product, not an afterthought.

Salary Range:

$130 - 150K

About L3Harris

L3Harris Technologies, Inc. is an American technology company, defense contractor and information technology services provider that produces C6ISR systems and products, wireless equipment, tactical radios, avionics and electronic systems, night vision equipment, and both terrestrial and spaceborne antennas for use in the government, defense, and commercial sectors. They specialize in areas such as electronic warfare and night vision. L3Harris Technologies was formed on June 29, 2019, through the merger of Harris Corporation and L3 Technologies. The company is based in Melbourne, Florida.
Learn more about L3Harris
Size
50,000 employees
Industry

Similar Jobs

More Jobs at L3Harris

More Information Technology Jobs

Find similar Senior GRC Manager jobs: