SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Manager, Governance, Risk, and Compliance

Virta Health - Remote - Remote - posted 2026-07-31

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Virta Health is seeking a Senior Manager of Governance, Risk, and Compliance to lead the company's GRC function in a highly automated, AI-first environment. You will serve as the enterprise champion of security compliance and risk culture, collaborating with Sales to accelerate commercial velocity while maintaining and maturing Virta's information security compliance program. Key responsibilities include: - Lead GRC & Compliance Automation: Oversee Virta's GRC function and scale the Vanta platform to automate continuous evidence collection, ensuring audit-readiness and defending HIPAA, HITRUST CSF, and SOC 2 certifications. - Enable Commercial Velocity: Partner directly with Sales and Customer Success to navigate enterprise customer evaluations and security reviews, communicating Virta's strong security compliance posture to external stakeholders. - Own Policy, Risk & Compliance Governance: Define and own Virta's security policy lifecycle, exception management processes, vendor risk assessments, and executive risk reporting. Conduct regular risk assessments to identify vulnerabilities and guide business owners on mitigation. - Champion GRC Employee Experience: Manage the administrative security queue for Virta employees. Design and optimize frictionless ticketing workflows and SLAs for access governance reviews, SaaS tool compliance evaluations, and policy exception requests. - Coordinate Cross-Functional Security Alignment: Collaborate with IT, Enterprise Security Engineering, and Product Development teams to ensure operational GRC policies map into technical architectures and evolving AI governance frameworks (ISO 42001, NIST AI RMF). - Security Awareness & Compliance Training: Champion a culture of security awareness across all organizational levels. Design and deliver targeted training programs so employees understand their roles in maintaining compliance and data privacy. Within your first 90 days, you will conduct a deep dive into current GRC tool configurations, establish baseline SLAs for employee compliance requests, optimize automation workflows for customer security questionnaires and RFP responses, and complete a comprehensive internal risk assessment with a unified risk and compliance metrics dashboard for senior leadership. Required qualifications: 7+ years of dedicated experience in Cybersecurity GRC, IT Auditing, or Information Security Compliance, with at least 2+ years leading programs or managing teams in regulated environments (Healthcare or Digital Health). Direct hands-on experience managing HITRUST CSF, HIPAA, and SOC 2 frameworks. Proven track record leveraging modern SaaS GRC automation platforms (Vanta or Drata). Outstanding client-facing communication skills with a track record of partnering with Sales/CS teams on complex enterprise security evaluations. Successfully designed and implemented repeatable AI-enabled workflows. Ability to operate in gray areas, balancing corporate risk tolerance, operational efficiency, and regulatory requirements. Strong cross-functional leadership skills with the ability to influence technical and non-technical business partners.

Similar roles