Senior Manager, GRC
AI summary of the role
Lead GRC for a B2B health benefits platform, owning SOC 2/HITRUST renewals and standing up ISO 27001/42001 from scratch.
What you’ll do
- Own end-to-end SOC 2 Type II and HITRUST certification renewals, including scoping, evidence collection, and auditor management.
- Lead the ground-up establishment of ISO 27001 and ISO 42001 certification programs, including gap assessments and policy writing.
- Manage the audit calendar across frameworks, coordinating with Engineering, IT, HR, and Legal to close findings on time.
- Serve as primary owner of security questionnaires and RFIs/RFPs, partnering with Sales and Customer Success to support deals.
What you’ll bring
- 6+ years in GRC, information security compliance, or IT audit with direct ownership of at least one SOC 2 audit cycle.
- Hands-on working knowledge of SOC 2, HITRUST, and ISO 27001 frameworks.
- Experience responding to customer security questionnaires/RFIs in a B2B SaaS or healthcare-adjacent environment.
- Strong cross-team collaboration and project management skills to sequence overlapping audits and hit deadlines.
Technologies
SOC 2 · HITRUST · ISO 27001 · ISO 42001 · HIPAA · Vanta · Drata · Secureframe · Hyperproof · CISA · CRISC · CISSP
About Maven Clinic
Virtual clinic and benefits platform covering fertility, maternity, parenting, and menopause for 2,000+ employers and health plans.
Series F · 1000–2000 people
Source and classification
Technical pre-sales · Evidence for this classification:
platform. You'll act as the team lead for our GRC function, working closely with one other team member to run audits, write policies, answer RFIs, and monitor controls day to day. This role touches almost every team: partnering with Engineering, IT, and HR to gather evidence and close gaps; working directly with customers and their security teams during due diligence; and managing auditor relationships through certification cycles. You'll also bring solid project management skills, sequencing audits, tracking remediation, and hitting deadlines across multiple concurrent workstreams. You'll report directly to the CISO/Head of Security and act as the organization's primary voice on compliance posture. You will interface internally and externally with customers, auditors, and partners. Our platform facilitates virtual health visits for employer-sponsored benefits, which means security,
More from the job description
Maven Clinic is the world's largest virtual clinic for women and families on a mission to make healthcare work for all of us. Through Maven Enterprise, the company partners with more than 2,300 employers and health plans to provide end-to-end women's and family health programs spanning fertility and family building, maternity and newborn care, parenting and pediatrics, and menopause and midlife — improving clinical outcomes, reducing healthcare costs, and expanding equitable access to high-quality care at scale. Through its consumer platform, Maven provides direct access to virtual care across 30+ specialties, as well as dedicated hormone and GLP-1 care programs purpose-built for women. Founded in 2014 by CEO Kate Ryder, Maven Clinic has raised more than $425 million from leading healthcare and technology investors including General Catalyst, Sequoia, Dragoneer Investment Group, Oak HC/FT, StepStone Group, Icon Ventures, and Lux Capital. Recognized for innovation and industry leadership, Maven has been named to the TIME100 Most Influential Companies, CNBC Disruptor 50, Fast Company's Most Innovative Companies, and FORTUNE Best Places to Work. Learn more at mavenclinic.com An award-winning culture working towards an important mission – Maven Clinic is a recipient of over 30 workplace and innovation awards, including: TIME 100 Most Influential Companies (2023, 2026) Fortune Ch [... source excerpt omitted ...] e Best Workplaces NY (2020, 2021, 2022, 2023, 2024) About the Role: We're looking for a GRC Manager to own governance, risk, and compliance for our B2B health benefits platform. You'll act as the team lead for our GRC function, working closely with one other team member to run audits, write policies, answer RFIs, and monitor controls day to day. This role touches almost every team: partnering with Engineering, IT, and HR to gather evidence and close gaps; working directly with customers and their security teams during due diligence; and managing auditor relationships through certification cycles. You'll also bring solid project management skills, sequencing audits, tracking [... source excerpt omitted ...] nd hitting deadlines across multiple concurrent workstreams. You'll report directly to the CISO/Head of Security and act as the organization's primary voice on compliance posture. You will interface internally and externally with customers, auditors, and partners. Our platform facilitates virtual health visits for employer-sponsored benefits, which means security, privacy, and compliance are core to customer trust and our ability to sell into enterprise and health-plan accounts. What You'll Do: External Audit & Certification Management Own continuation and renewal of our SOC 2 (Type II) and HITRUST certifications end-to-end. You'll scope each cycle, pull evidence, work direct
Employer postings · Data from · Sources