Senior Manager, GRC

Maven ClinicNew York, NY
$170,000 - $201,000Hybrid

About The Position

Maven Clinic is seeking a GRC Manager to lead governance, risk, and compliance for their B2B health benefits platform. This role involves acting as the team lead for the GRC function, working with another team member to manage audits, develop policies, respond to RFIs, and monitor controls. The position requires collaboration with various teams including Engineering, IT, and HR for evidence gathering and gap closure, direct engagement with customers and their security teams during due diligence, and managing auditor relationships through certification cycles. Strong project management skills are essential for sequencing audits, tracking remediation, and meeting deadlines across multiple projects. The role reports directly to the CISO/Head of Security and serves as the primary point of contact for the organization's compliance posture, interacting with customers, auditors, and partners. Security, privacy, and compliance are critical for customer trust and sales success in the enterprise and health-plan markets.

Requirements

  • 6+ years of experience in GRC, information security compliance, or IT audit.
  • Direct ownership of at least one SOC 2 or similar audit cycle from start to finish.
  • Working knowledge of SOC 2, HITRUST, and ISO 27001 frameworks.
  • Experience responding to customer security questionnaires/RFIs, ideally in a B2B SaaS or healthcare-adjacent environment.
  • Strong cross-team collaboration skills, with experience working with Engineering, IT, HR, Legal, and Sales.
  • Solid project management instincts, including sequencing overlapping projects, tracking dependencies, and managing remediation.
  • Strong written communication skills for policy writing, RFI responses, and audit narratives.

Nice To Haves

  • Direct experience standing up a new certification (SOC2, HITRUST, ISO 27001 and/or ISO 42001) rather than just maintaining an existing one.
  • Experience with GRC/compliance automation tooling (Vanta, Drata, Secureframe, Hyperproof, or similar).
  • Background in health tech, digital health, or another regulated B2B vertical (fintech, insurtech).
  • A relevant certification such as CISA, CRISC, CISSP, PMP or CAPM, CISM, CTRC/CAP.
  • Exposure to vulnerability management or IT operations.
  • Experience partnering with Sales/Sales Engineering as a technical or compliance resource during the deal cycle.

Responsibilities

  • Own continuation and renewal of SOC 2 (Type II) and HITRUST certifications end-to-end, including scoping, evidence pulling, auditor liaison, and remediation tracking.
  • Lead the establishment of ISO 27001 and ISO 42001 certification programs, including gap assessments, control mapping, policy writing, and preparing for audits.
  • Manage the annual/ongoing audit calendar across all frameworks, coordinating with internal stakeholders to gather evidence and close findings.
  • Track regulatory and framework changes (HIPAA, state privacy laws, ISO updates) and translate them into control updates.
  • Serve as the primary owner of security questionnaires and RFIs/RFPs for Sales and Customer Success teams, ensuring accurate and timely responses.
  • Maintain a security knowledge base/answer library to expedite responses to recurring questions.
  • Partner with Sales Engineering and Account teams to represent security and compliance posture in customer calls when needed.
  • Manage relationships with customers' internal security/compliance teams during onboarding and renewal cycles.
  • Build and run an internal audit/control-monitoring program to verify the day-to-day operation of externally audited controls.
  • Flag control gaps or process drift to the CISO/Head of Security proactively.
  • Expand internal audit scope over time to include policy adherence, vendor risk, and operational risk.

Benefits

  • Employer-covered health, dental, and insurance plan options
  • Access to the full Maven platform and specialists (care for mental health, reproductive health, family planning, pediatrics)
  • Wellness partnerships
  • Hybrid work model
  • In-office meals
  • Work together days
  • 16 weeks 100% paid parental leave
  • New parent stipend (for employees with 1+ year of service)
  • Annual professional development stipend
  • Access to a personal career coach through Maven for Mavens
  • 401K matching for US-based employees, with immediate vesting
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service