Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Rightway

Security GRC Manager

Rightway

. Lead and mentor a small GRC team, setting priorities, reviewing work, and growing the function .

Posted 10/9/2026full-timeRemote • Florida • United StatesMid-LevelSenior💰 $144,000 - $175,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in Governance, Risk, and Compliance (GRC) leadership, with a strong focus on SOC 2 and HITRUST certification processes, AI governance frameworks, and risk assessment methodologies. Proven ability to mentor teams, negotiate compliance agreements, and enhance operational efficiency through effective policy implementation.

Highest-signal resume keywords
GRC LeadershipSOC 2/HITRUST CertificationAI Governance FrameworksRisk Assessment MethodologyCompliance Negotiation

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Risk AssessmentControl MaturityData Privacy ComplianceIncident/Breach AnalysisOperational Efficiency ImprovementSecurity Risk ManagementAudit Program ManagementThird Party Risk ManagementSecurity Training DevelopmentContinuous Control Monitoring
Soft Skills
Team LeadershipMentoringNegotiationCollaborationCommunication
Tools & Technologies
DrataJamfCrowdStrikeArctic WolfWizServalKnowbe4AWSOktaJIRA
Certifications & Qualifications
CISSPCISACISM
Industry Keywords
SOC 2HITRUSTHIPAAHITECHBAAISO/IEC 42001AI Risk RegisterData Handling RequirementsBusiness Continuity PlanningControl Effectiveness

Tech Stack

Tools & technologies
AWSJamfSDLC

About the role

Key responsibilities & impact
  • Lead and mentor a small GRC team, setting priorities, reviewing work, and growing the function
  • Own and evolve the unified control library, maintaining mappings across SOC 2, SOC 1, and the latest HITRUST version
  • Lead the audit program for control requirements and evidence production in partnership with Engineering, IT, People, and Finance
  • Partner with Legal on data privacy programs, including HIPAA/HITECH, BAAs, privacy and protection impact assessments, incident/breach analysis, and data handling requirements
  • Own and mature the AI governance program modeled after ISO/IEC 42001, including the AI risk register, Statement of Applicability, and AI risk assessments
  • Respond to customer and partner AI governance questionnaires and maintain alignment with emerging requirements such as Colorado ADMTA
  • Review and negotiate security, privacy, data protection, incident notification, audit rights, AI, and related language in customer and vendor agreements
  • Monitor, measure, and report control effectiveness in Drata, maintaining continuous control monitoring and evidence collection
  • Improve policies and procedures to increase operational efficiency, control maturity, security, and compliance
  • Lead business continuity planning and testing, focusing on a BIA-informed program
  • Revamp and execute the Third Party Risk Management program
  • Own the security risk management program, including enterprise risk preparation, discussion, tracking, remediation, and annual risk assessments
  • Develop and implement security and compliance training programs
  • Own and maintain the customer assurance program, including security questionnaires, RFP responses, trust center content, and supporting tooling

Requirements

What you’ll need
  • 5-10 years of related work experience
  • Maintains a certification relevant to the role (e.g, CISSP, CISA, CISM)
  • Personally led SOC2 with HITRUST CSF certification in a high growth environment and understands how to mature controls consistent with organizational maturity and capacity
  • Familiarity with AI governance frameworks (e.g., ISO/IEC 42001) and the risk considerations of AI systems that process sensitive data
  • Experience leading or mentoring GRC analysts
  • Deep understanding of risk assessment methodology, HIPAA, and HITECH, including the practical distinction between covered entity and business associate obligations
  • Comfortable negotiating and redlining BAAs and conducting four-factor breach risk assessments alongside Privacy and legal
  • Intermediate to advanced understanding of the Software Development Life Cycle and IT and security tooling (Jamf, CrowdStrike, Arctic Wolf, Wiz, Serval, Knowbe4, Drata, AWS, Okta, JIRA, GIT/GITHUB) as it relates to controls
  • Ability to perform qualitative and quantitative risk assessment
  • Experience with joint SOC 2/HITRUST attestations (extra credit)
  • A blend of deep, technical and compliance knowledge and experience (extra credit)

Benefits

Comp & perks
  • Bonus
  • Equity
  • Equal Opportunity Employer with an inclusive culture where differences are celebrated