Governance, Risk & Compliance (GRC) Manager

MillimanSeattle, WA
$117,500 - $222,985Remote

About The Position

This position manages the corporate governance, risk, and compliance (GRC) teams, including internal security review, security contract review, and vendor risk management. The GRC Program Manager supervises employees across experience levels and works with IT compliance stakeholders to assess risk and provide practical guidance aligned with Milliman’s risk appetite. The position works with 60+ offices worldwide and their local administrators to coordinate internal assessments, support external audits, and identify and assess critical vendors. The position reports directly to the Chief Information Security Officer (CISO) and resides within Global Corporate Services (GCS). The GRC Manager will support program planning, staff supervision, and execution of GRC-related projects. This position will oversee the technical work of GRC team personnel and work directly with IT leads, managers, the project management office (PMO), and executives to communicate relevant business and technical information. The GRC Manager will set performance expectations for team members and provide regular, constructive feedback.

Requirements

  • Bachelor's degree in Risk Management, Information Systems, Computer Science, or Cybersecurity (or equivalent years of relevant professional hands-on work experience).
  • Minimum 7 years of hands-on IT Cybersecurity or Risk Management experience.

Nice To Haves

  • Certified in at least one of the following: Risk and Information Systems Control (CRISC), Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP) or willingness to obtain.
  • Experience using GRC/VRM tools and platforms.
  • Experience with HIPAA/HITRUST, GDPR, ISO 27001 /2, and other industry regulatory controls and compliance.
  • Experience within consulting or professional service organizations.
  • Experience with SharePoint administration.

Responsibilities

  • Manage the Global GRC team across regions and serve as an escalation point for complex issues.
  • Support Talent Management: Support hiring, performance reviews, compensation discussions, and staffing decisions.
  • Support Client Engagement: Work with GCS Legal and business stakeholders on information security contract requirements, escalating to the CISO as needed.
  • Monitor Regulatory Requirements: Monitor applicable requirements, including HIPAA, GDPR, and CCPA, and assess impact to GRC responsibilities.
  • Support Compliance Initiatives: Work with GDPT and internal stakeholders to support regulatory and client compliance requirements.
  • Oversee Vendor Risk Management: Oversee vendor security risk processes and support alignment with vendor management.
  • Track Team Performance: Monitor team performance against SLAs and address gaps as needed.
  • Report on Program Performance: Provide program updates and align GRC work with organizational priorities.
  • Coordinate with IT, Legal, Finance, and GCS leadership on risk and compliance priorities.
  • Communicate and Share risk and compliance updates and support targeted security training when policies or gaps require it.

Benefits

  • Medical, Dental and Vision – Coverage for employees, dependents, and domestic partners.
  • Employee Assistance Program (EAP) – Confidential support for personal and work-related challenges.
  • 401(k) Plan – Includes a company matching program and profit-sharing contributions.
  • Discretionary Bonus Program – Recognizing employee contributions.
  • Flexible Spending Accounts (FSA) – Pre-tax savings for dependent care, transportation, and eligible medical expenses.
  • Paid Time Off (PTO) – Begins accruing on the first day of work. Full-time employees accrue 15 days per year, and employees working less than full-time accrue PTO on a prorated basis.
  • Holidays – A minimum of 10 paid holidays per year.
  • Family Building Benefits – Includes adoption and fertility assistance.
  • Paid Parental Leave – 11 weeks of paid leave for employees who meet eligibility criteria.
  • Life Insurance & AD&D – 100% of premiums covered by Milliman.
  • Short-Term and Long-Term Disability – Fully paid by Milliman.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service