Security GRC Manager
ABOUT THE ROLE:
Join Rightway as a Security GRC Manager, a role that owns and matures our GRC function. You will enhance our policies and procedures, streamline workflows, mature our risk management program, own our integrated SOC 2 + HITRUST attestation as we scale, and lead the GRC team.
WHAT YOU’LL DO:
Team Leadership: Lead and mentor a small GRC team, setting priorities, reviewing work, and growing the function alongside the business.
Control Library Development: Own and evolve our unified control library, maintaining mappings across SOC 2, SOC 1, and the latest HITRUST version, and addressing gaps or inefficiencies as the organization and framework requirements change.
Audit Ownership: In partnership with Engineering, IT, People, and Finance, lead the audit program for control requirements and evidence production, proactively in anticipation of SOC 1, SOC 2/HITRUST, and customer audits.
Data Privacy and Protection: Partner with Legal as a key stakeholder in the Data Privacy program, including HIPAA/HITECH, BAAs, data privacy and protection impact assessments, incident/breach analysis, and data handling requirements.
AI Governance: Own and mature the AI governance program modeled after ISO/IEC 42001, including the AI risk register, Statement of Applicability, and AI risk assessments for internal use cases. Respond to customer and partner AI governance questionnaires, and maintain alignment to emerging requirements such as the Colorado Automated Decision-Making Technology Act (ADMTA).
Contract security and privacy review: Review and negotiate security, privacy, data protection, incident notification, audit rights, AI, and related language in customer and vendor agreements.
Control Monitoring: Monitor, measure, and report on control effectiveness for security and compliance in Drata, maintaining continuous control monitoring and evidence collection, and adjusting strategy and implementation as needed.
Policy Enhancement: Collaborate cross-functionally to improve policies and related procedures, boosting operational efficiency, control maturity, security, and compliance
Business Continuity Planning: Lead business continuity planning and testing, with a focus on a Business Impact Analysis (BIA) informed program.
Third Party Risk Management: Revamp and execute a flexible yet thorough Third Party Risk Management (TPRM) program, keeping a keen eye on data security and technical risk, not just compliance.
Risk Management: Own the security risk management program, participating in preparation, discussion, tracking (risk register), and remediation of enterprise risks within your sphere of influence, in addition to annual risk assessments activities.
Training Programs Development: Engage with organizational stakeholders to develop and implement effective security and compliance training programs.
Customer Trust: Own and maintain the customer assurance program, including the security questionnaire and RFP response process, trust center content, and the tooling that supports timely, accurate responses for the Proposal Unit and prospective clients.
WHO YOU ARE:
5-10 years of related work experience.
Maintains a certification relevant to the role (e.g, CISSP, CISA, CISM).
Personally led SOC2 with HITRUST CSF certification in a high growth environment and understands how to mature controls consistent with organizational maturity and capacity.
Familiarity with AI governance frameworks (e.g., ISO/IEC 42001) and the risk considerations of AI systems that process sensitive data.
Experience leading or mentoring GRC analysts, with the ability to set priorities, review work, and grow the function alongside the business.
A deep understanding of risk assessment methodology, HIPAA, and HITECH, including the practical distinction between covered entity and business associate obligations. Comfortable negotiating and redlining BAAs and conducting four-factor breach risk assessments alongside Privacy and legal.
Passionate advocate for governance, risk, and compliance, believing that these are not merely check box activities, but vital tools that significantly improve security posture and protect the organization.
Possess an intermediate to advanced understanding of the Software Development Life Cycle and of IT and security tooling (Jamf, CrowdStrike, Arctic Wolf, Wiz, Serval, Knowbe4, Drata) as it relates to controls (e.g. AWS, Okta, JIRA, GIT/GITHUB).
Ability to perform qualitative and quantitative risk assessment.
EXTRA CREDIT:
Experience with joint SOC 2/HITRUST attestations.
A blend of deep, technical and compliance knowledge and experience.
COMPENSATION: $144,000 - $175,000 annually, in addition to bonus and equity
Compensation offered will be determined by geographic location, experience, and qualifications.