Senior GRC Manager

Posted Yesterday
Be an Early Applicant
48 Locations
In-Office or Remote
130K-150K Annually
Senior level
Healthtech
The Role
Own and maintain the company’s governance, risk, and compliance program, including security policies, control mapping, risk registers, audit evidence, and third-party risk. Manage HIPAA, GDPR, HITRUST, and SOC 2 audits and certification renewals while partnering with auditors, security engineers, DevSecOps, executives, and business teams. Translate technical controls into defensible compliance evidence, support incident response planning, identify compliance gaps, and provide practical, risk-based guidance.
Summary Generated by Built In

We're looking for a Senior GRC Manager to own our GRC program end to end and keep ClearDATA aligned with HIPAA, GDPR, HITRUST, SOC 2, etc. You'll maintain our Information Security Management Program, manage audit cycles, and work directly with auditors, including keeping policy and compliance documentation accurate as our systems and vendors evolve.

We want someone who treats compliance as a way to help the business move with confidence, not a set of hoops for other teams to jump through. You'll look for the practical, risk-based path to "yes" whenever one exists, and reserve hard stops for when they're truly warranted. This is a hands-on, senior role on our IT/ITSec team. You won't have direct reports, but you won't be working alone either — you'll have security engineers, DevSecOps, and leadership alongside you. We're looking for someone who'd rather build the control mapping than write a memo about who should build it.

What You'll Own

Governance, Risk & Compliance

  • Maintain ClearDATA's Information Security Management Program: the policies, procedures, and standards behind our security and compliance posture.
  • Support audits, assessments, and certification renewals for HIPAA, GDPR, HITRUST, and SOC 2.
  • Maintain the risk register, including tracking third-party and vendor risk.
  • Keep control mapping and audit evidence current and organized.
  • Support incident response planning alongside the IT/ITSec Manager and security team.
  • Partner with security engineers and DevSecOps to translate control requirements into how systems are actually built and operated — and to turn what they've built into defensible audit evidence.

Documentation & Audit Liaison

  • Update policies and program documentation as systems, vendors, or ownership of shared responsibilities change.
  • Work directly with auditors to catch and close compliance gaps before they become findings.
  • Flag open risk or outstanding items that need attention.
  • Act as the go-to compliance resource across the company — engineering, DevSecOps, management, and executive leadership — helping teams find a workable path forward rather than just pointing at policy, and giving leadership a clear read on where the program stands.
What We're Looking For
  • 5+ years in GRC, IT compliance, or information security compliance, ideally in a regulated industry, in hands-on roles rather than oversight or advisory.
  • Direct experience maintaining an Information Security Management Program or similar compliance program.
  • Working knowledge of HIPAA, SOC 2, HITRUST, or GDPR; healthcare experience strongly preferred.
  • Experience working directly with external auditors.
  • Proven ability to work across a technical organization and up to executive leadership — credible with security engineers and DevSecOps on the details, and able to give management and execs a straight answer on risk without burying it in framework language.
  • Strong writing skills. You should be comfortable turning operational and technical detail into clear policy language.
  • Organized and detail-oriented, able to manage several compliance workstreams at once.
  • A pragmatic approach to risk: you can tell the difference between a real compliance issue and a theoretical one, and you'd rather solve a problem than just document it.
Nice to Have
  • CISA, HITRUST CCSFP, or CRISC certification — useful, but we care more about what you've actually run than what you've been certified in.
  • Experience with AWS, Azure, or GCP and related compliance considerations.
  • Experience with GRC tooling (e.g., Thoropass, OneTrust, or similar platforms).
  • A background that spans both compliance and a technical discipline (IT, security, or engineering), so you can speak both languages.
Why ClearDATA

You'll own a GRC program that matters, at a company where security and compliance are the product, not an afterthought.

About us:

Established in 2009, ClearDATA was born out of a need to address significant inefficiencies within the U.S. healthcare system. From slow data processing to security concerns, these challenges often stood between patients and timely and effective care. 

As the healthcare industry began to embrace the public cloud, technology leaders faced a new set of challenges. Organizations found themselves navigating the fast-paced world of cloud innovations, regulatory compliance changes, and looming cyber threats. ClearDATA’s founders understood the complexities involved this highly-regulated industry and created the first cloud compliance and security solution exclusively for healthcare.

About Harris Computer:

Harris provides mission critical software solutions for the Public Sector, Healthcare, Utilities and Private Sector verticals throughout North America, Europe, Asia and Australia.
Working for Harris is the perfect opportunity to fulfill your professional goals as well as achieve your personal dreams!
Our employees enjoy a casual work environment that offers comfort while providing superior service to our customers. We offer a comprehensive benefit package as well as other additional “Perks”!

  • We empower our employees to make a difference
  • We have an award-winning culture
  • We offer opportunity to learn
  • We are financially strong and we are owned by the largest software company in Canada (CSI)
  • We have fun!

Follow us on social media to learn more about our company values, culture and initiatives!

  • Instagram: ⁠@weareharris
  • LinkedIn: ⁠Harris Computer

What we offer:

  • Plenty of opportunities to grow your career
  • Full benefits package medical, dental, vision, STD, Life benefits
  • 3 weeks of vacation plus 5 personal days to recharge
  • Employee stock ownership and RRSP program
  • A chance to give back through community involvement
  • Flexible work arrangements to suit your lifestyle

Salary Range:

$130 - 150K

Skills Required

  • 5+ years of experience in GRC, IT compliance, or information security compliance
  • Hands-on experience maintaining an Information Security Management Program or similar compliance program
  • Working knowledge of HIPAA, SOC 2, HITRUST, or GDPR
  • Experience working directly with external auditors
  • Ability to collaborate across technical teams and communicate risk to management and executives
  • Strong writing skills, including translating technical and operational details into clear policy language
  • Strong organizational and detail-management skills across multiple compliance workstreams
  • Pragmatic, risk-based approach to compliance and problem solving
  • Experience in a regulated industry, preferably healthcare
  • CISA, HITRUST CCSFP, or CRISC certification
  • Experience with AWS, Azure, or GCP and related compliance considerations
  • Experience with GRC tooling such as Thoropass, OneTrust, or similar platforms
  • Background spanning compliance and a technical discipline such as IT, security, or engineering

Harris healthcare Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Harris healthcare and has not been reviewed or approved by Harris healthcare.

  • Leave & Time Off Breadth PTO and paid holidays are characterized as generous, with ample time off emphasized. This breadth of time-off options is highlighted alongside favorable impressions of vacation and sick leave.
  • Flexible Benefits Remote-work flexibility and trust to work from home are emphasized, indicating adaptable arrangements for many roles. Flexibility is positioned as a tangible part of the overall package.
  • Healthcare Strength Core coverage includes medical, dental, and vision, along with life and disability insurance and HSA/FSA options. Health plans are often characterized as good, contributing to a solid foundational offering.

Harris healthcare Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Niagara Falls, New York
185 Employees
Year Founded: 1993

What We Do

For over 25 years, Harris Healthcare has been rising to the challenge of bringing together the most innovative and sustainable solutions for today’s ever-changing healthcare environment, in order to improve patient care and safety. Each one of our solutions brings organizational efficiencies on its own. Powerful synergies are achieved when multiple solutions are implemented together. The Harris Healthcare portfolio includes the following solutions: ♦ HARRIS Flex - an enterprise-level EHR solution that improves patient safety and clinical workflows. It includes a full complement of applications integrated in one single database, provides solid clinical decision support to your clinicians and helps standardize care while enforcing protocols and best practices at any Healthcare Organization. HARRIS Flex conveys the digital solution’s flexibility and strength. Healthcare organizations are continuously faced with new challenges and situations and require flexible EHR’s that can be rapidly adapted to their evolving clinical practice. Contrary to other EHR solutions which are inflexible and where customizations require costly support from the vendor, HARRIS Flex gives you the freedom to "flex" your EHR as you need it entirely on your own. The enhanced HARRIS Flex solution comes with new functionality including: ♦Flex Telehealth which enables virtual visits directly from within the EHR/EPR, and ♦Flex Clinical Insight which facilitates extraction and analysis of your EHR/EPR data to improve your processes and outcomes. ♦ SynergyCheck – a proactive interface monitoring solution watching over Clinical, Financial and other interfaces 24/7 to ensure data is flowing between systems

Similar Jobs

Remote
United States
200 Employees

Workstreet Logo Workstreet

Senior Manager, GRC Engineering (Special Programs)

Artificial Intelligence • Information Technology • Software
Remote
United States
102 Employees
Remote
U.S.
361 Employees
207K-244K Annually

Workstreet Logo Workstreet

Senior Manager, GRC Engineering

Artificial Intelligence • Information Technology • Software
Remote
United States
102 Employees

Similar Companies Hiring

Sailor Health Thumbnail
Healthtech • Social Impact • Telehealth
New York City, NY
20 Employees
Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
OneImaging Thumbnail
Healthtech
Miami, FL
62 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account