GRC Manager
NablaClinical AI company
RemoteManager
Highland Europe
Cathay Innovation
DST Global
HV Capital
Artemis Health
ZEBOX
Legal & Compliance
About the role
TL;DR
Manage and mature Nabla's security and compliance programs to enable secure business growth.
- •As the GRC Manager, you will be instrumental in scaling Nabla's security and compliance programs.
- •You will collaborate with various teams to build and mature governance, risk, and compliance programs that enable secure business growth.
- •Key Responsibilities Mature Nabla’s Governance, Risk & Compliance programs in partnership with Security, Engineering, Product, and Legal teams.
- •Manage the GRC control evidence library, including control flags and evidence collection.
- •Oversee the vendor risk program, including assessments and ongoing monitoring.
- •Review security assurance artifacts like SOC 2 Type II reports and ISO certifications.
- •Assist with security questionnaires and client audits.
- •Requirements 4+ years of experience in GRC, Information Security, or a related function, with experience building or scaling programs.
- •Hands-on experience in GRC program management, ideally in a high-growth SaaS or technology company.
- •Deep expertise across multiple compliance and security frameworks, including SOC 2 Type II and ISO 27001.
- •Healthcare experience preferred, with a strong understanding of HIPAA controls.
- •Experience with GRC platforms and tooling.
Required skills
SOC 2HIPAAGDPRIAMSSOMFAVaultVendor ManagementContract ManagementRisk ManagementCompliance ManagementJiraConfluence
Domain expertise
healthtechcybersecurity
Benefits & perks
Competitive salary and stock options, 100% individual coverage for Medical, Dental, and Vision insurance, Unlimited paid time off and 11 national holidays, Unlimited sick leave, Paid leave for new parents, $1,000 to purchase home office equipment, Full ownership of your time and schedule
Tech stack
SOC 2HIPAAGDPRVaultIAMSSOMFAGitJiraConfluenceNotionSlack