SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Manager, GRC

Maven Clinic - New York, NY, United States - Hybrid - posted 2026-09-08

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Maven Clinic, a leading virtual healthcare platform for women and families, is seeking a Senior Manager of Governance, Risk & Compliance (GRC) to lead the company's compliance and audit function. Reporting to the CISO/Head of Security, you will own end-to-end governance, risk management, and compliance across the organization, serving as the primary internal and external voice on Maven's security and compliance posture. Key responsibilities include: **External Audit & Certification Management:** Own continuation and renewal of SOC 2 Type II and HITRUST certifications. Lead ground-up establishment of ISO 27001 and ISO 42001 certification programs, including gap assessments, control mapping, policy writing, and readiness for initial audits. Manage the annual audit calendar across all frameworks, coordinating with Engineering, IT, HR, and Legal to gather evidence and close findings. Track regulatory changes (HIPAA, state privacy laws, ISO updates) and translate them into control updates. **Customer-Facing Security & Compliance:** Serve as primary owner of security questionnaires, RFIs, and RFPs for Sales and Customer Success teams. Build and maintain a security knowledge base to accelerate responses to recurring due-diligence questions. Partner with Sales Engineering and Account teams to represent Maven's security posture in customer calls when security is a deal blocker. Manage relationships with customers' security and compliance teams during onboarding and renewal cycles. **Internal Audit & Control Monitoring:** Build and run an internal audit and control-monitoring program focused on verifying that externally audited controls operate day-to-day. Flag control gaps and process drift to leadership before they become audit findings. Expand scope into broader internal audit territory (policy adherence, vendor risk, operational risk) as bandwidth allows. You will work closely with one other team member on the GRC function, touching nearly every team across the organization. Maven's platform facilitates virtual health visits for employer-sponsored benefits, making security, privacy, and compliance core to customer trust and enterprise sales.

Similar roles