Security GRC Manager

RightwayMiami, FloridaRemoteFull-timeSenior, 5–8 yearsListed 4 hours ago

Apply now

About this role

ABOUT THE ROLE:

Join Rightway as a Security GRC Manager, a role that owns and matures our GRC function. You will enhance our policies and procedures, streamline workflows, mature our risk management program, own our integrated SOC 2 + HITRUST attestation as we scale, and lead the GRC team.

WHAT YOU’LL DO:

- Team Leadership: Lead and mentor a small GRC team, setting priorities, reviewing work, and growing the function alongside the business.

- Control Library Development: Own and evolve our unified control library, maintaining mappings across SOC 2, SOC 1, and the latest HITRUST version, and addressing gaps or inefficiencies as the organization and framework requirements change.

- Audit Ownership: In partnership with Engineering, IT, People, and Finance, lead the audit program for control requirements and evidence production, proactively in anticipation of SOC 1, SOC 2/HITRUST, and customer audits.

- Data Privacy and Protection: Partner with Legal as a key stakeholder in the Data Privacy program, including HIPAA/HITECH, BAAs, data privacy and protection impact assessments, incident/breach analysis, and data handling requirements.

- AI Governance: Own and mature the AI governance program modeled after ISO/IEC 42001, including the AI risk register, Statement of Applicability, and AI risk assessments for internal use cases. Respond to customer and partner AI governance questionnaires, and maintain alignment to emerging requirements such as the Colorado Automated Decision-Making Technology Act (ADMTA).

- Contract security and privacy review: Review and negotiate security, privacy, data protection, incident notification, audit rights, AI, and related language in customer and vendor agreements.

- Control Monitoring: Monitor, measure, and report on control effectiveness for security and compliance in Drata, maintaining continuous control monitoring and evidence collection, and adjusting strategy and implementation as needed.

- Policy Enhancement: Collaborate cross-functionally to improve policies and related procedures, boosting operational efficiency, control maturity, security, and compliance

- Business Continuity Planning: Lead business continuity planning and testing, with a focus on a Business Impact Analysis (BIA) informed program.

- Third Party Risk Management: Revamp and execute a flexible yet thorough Third Party Risk Management (TPRM) program, keeping a keen eye on data security and technical risk, not just compliance.

- Risk Management: Own the security risk management program, participating in preparation, discussion, tracking (risk register), and remediation of enterprise risks within your sphere of influence, in addition to annual risk assessments activities.

- Training Programs Development: Engage with organizational stakeholders to develop and implement effective security and compliance training programs.

- Customer Trust: Own and maintain the customer assurance program, including the security questionnaire and RFP response process, trust center content, and the tooling that supports timely, accurate responses for the Proposal Unit and prospective clients.

WHO YOU ARE:

- 5-10 years of related work experience.

- Maintains a certification relevant to the role (e.g, CISSP, CISA, CISM).

- Personally led SOC2 with HITRUST CSF certification in a high growth environment and understands how to mature controls consistent with organizational maturity and capacity.

- Familiarity with AI governance frameworks (e.g., ISO/IEC 42001) and the risk considerations of AI systems that process sensitive data.

- Experience leading or mentoring GRC analysts, with the ability to set priorities, review work, and grow the function alongside the business.

- A deep understanding of risk assessment methodology, HIPAA, and HITECH, including the practical distinction between covered entity and business associate obligations. Comfortable negotiating and redlining BAAs and conducting four-factor breach risk assessments alongside Privacy and legal.

- Passionate advocate for governance, risk, and compliance, believing that these are not merely check box activities, but vital tools that significantly improve security posture and protect the organization.

- Possess an intermediate to advanced understanding of the Software Development Life Cycle and of IT and security tooling (Jamf, CrowdStrike, Arctic Wolf, Wiz, Serval, Knowbe4, Drata) as it relates to controls (e.g. AWS, Okta, JIRA, GIT/GITHUB).

- Ability to perform qualitative and quantitative risk assessment.

EXTRA CREDIT:

- Experience with joint SOC 2/HITRUST attestations.

- A blend of deep, technical and compliance knowledge and experience.

COMPENSATION: $144,000 - $175,000 annually, in addition to bonus and equity

Compensation offered will be determined by geographic location, experience, and qualifications.

CYBERSECURITY AWARENESS NOTICE

In response to ongoing and industry-wide fraudulent recruitment activities (i.e., job scams), Rightway wants to inform potential candidates that we will only contact them from the @ rightwayhealthcare.com email domain. We will never ask for bank details or deposits of any kind as a condition of employment.

ABOUT RIGHTWAY:

Rightway is on a mission to harmonize healthcare for everyone, everywhere. Our products guide patients to the best care and medications by inserting clinicians and pharmacists into a patient’s care journey through a modern, mobile app. Rightway is a front door to healthcare, giving patients the tools they need along with on-demand access to Rightway health guides, human experts that answer their questions and manage the frustrating parts of healthcare for them.

Since its founding in 2017, Rightway has raised over $300mm from investors including Khosla Ventures, Thrive Capital, Francisco Partners, and Tiger Global. We’re headquartered in New York City, with satellite offices in Denver and Dallas. Our clients rely on us to transform the healthcare experience, improve outcomes for their teams, and decrease their healthcare costs.

HOW WE LIVE OUR VALUES TO OUR TEAMMATES:

We’re seeking those with passion for healthcare and relentless devotion to our goal. We need team members that embody our core values:

1) We are human, first
Our humanity binds us together. We bring the same empathetic approach to every individual we engage with, whether it be our members, our clients, or each other. We are all worthy of respect and understanding and we engage in our interactions with care and intention. We honor our stories. We listen to—and hear—each other, we celebrate our differences and similarities, we are present for each other, and we strive for mutual understanding.

2) We redefine what is possible
We always look beyond the obstacles in front of us to imagine new solutions. We approach our work with inspiration from other industries, other leaders, and other challenges. We use ingenuity and resourcefulness when faced with tough problems.

3) We debate then commit
We believe that a spirit of open discourse is part of a healthy culture. We understand and appreciate different perspectives and we challenge our assumptions. When working toward a decision or a new solution, we actively listen to one another, approach it with a “yes, and” mentality, and assume positive intent. Once a decision is made, we align and champion it as one team.

4) We cultivate grit
Changing healthcare doesn’t happen overnight. We reflect and learn from challenges and approach the future with a determination to strive for better. In the face of daunting situations, we value persistence. We embrace failure as a stepping stone to future success. On this journey, we seek to act with guts, resilience, initiative, and tenacity.

5) We seek to delight
Healthcare is complicated and personal. We work tirelessly to meet the goals of our clients while also delivering the best experience to our members. We recognize that no matter the role or team, we each play a crucial part in our members’ care and take that responsibility seriously. When faced with an obstacle, we are kind, respectful, and solution-oriented in our approach. We hold ourselves accountable to our clients and our members’ success.

Rightway is proud to be an Equal Opportunity Employer that believes in the strength of diverse thought, beliefs, backgrounds, and education. We foster an inclusive culture where differences are celebrated to drive the best business decisions possible. We do not discriminate on any basis protected by applicable law. All employment decisions are based on merit, qualifications, need, and performance.