Senior Manager, Governance, Risk, and Compliance
Job Description
Virta Health is on a mission to reverse metabolic disease in one billion people. Current treatment approaches aren’t working—over half of US adults have either type 2 diabetes or prediabetes, and obesity rates are at an all-time high. Virta is changing this by helping people reverse their metabolic condition through innovations in technology, personalized nutrition, and virtual care delivery reinvented from the ground up. We have raised over $350 million from top-tier investors, and partner with the largest health plans, employers, and government organizations to help their employees and members restore their health and take back their lives. Join us on our mission to reverse metabolic disease in one billion people. As our Senior Manager of GRC, you will have a high-impact, transformative opportunity to lead Virta’s Governance, Risk, and Compliance (GRC) function in a highly automated, AI-first environment. You will be the ultimate champion of security compliance and risk culture across the enterprise—collaborating closely with Sales to unblock commercial velocity, supervising compliance audits, and hardening our HIPAA, HITRUST, and SOC 2 frameworks. If you are passionate about driving risk governance, designing automated evidence collection, and enabling employees with frictionless SaaS reviews and compliance workflows, this role is your opportunity to redefine healthcare compliance. RESPONSIBILITIES Information Security GRC Program Management: Maintain and mature Virta Health's information security compliance program, policies, procedures, and controls to address emerging risks as the organization scales. Continuously evaluate and enhance the GRC framework to align with industry best practices and regulatory requirements. This is inclusive of: - Lead GRC & Compliance Automation: Oversee Virta’s GRC function, scaling our platform (Vanta) to automate continuous evidence collection, ensuring audit-readiness and defending our HIPAA, HITRUST CSF, and SOC 2 certifications.
- Enable Commercial Velocity (RFPs & Security Questionnaires): Partner directly with Sales and Customer Success to navigate enterprise customer evaluations and security reviews, communicating Virta's strong security compliance posture to external stakeholders.
- Own Policy, Risk & Compliance Governance: Define and own Virta's security policy lifecycle, exception management processes, vendor risk assessments, and executive risk reporting.
- Champion GRC Employee Experience: Manage the administrative security queue for Virta employees. Design and optimize frictionless ticketing workflows (such as Zendesk or Jira) and SLAs for access governance reviews, SaaS tool compliance evaluations, and policy exception requests.
- Coordinate Cross-Functional Security Alignment: Collaborate closely with IT, Enterprise Security Engineering, and Product Development teams to ensure operational GRC policies map seamlessly into our technical architectures and evolving AI governance frameworks (e.g., ISO 42001, NIST AI RMF).
- Security Awareness & Compliance Training: Champion a culture of security awareness across all levels of the organization.
- Day 30-60: Establish baseline SLAs for employee compliance requests (SaaS reviews, access reviews) and optimize automation workflows to streamline customer security questionnaire and RFP responses.
- Day 60-90: Complete a comprehensive internal risk assessment and present a clean, unified risk and compliance metric dashboard to senior leadership covering GRC control health, exception trends, and upcoming audit preparation timelines.
- Direct, hands-on experience managing and maintaining at least one of the major security and healthcare frameworks, specifically HITRUST CSF, HIPAA, and SOC 2.
- Proven track record of leveraging modern SaaS GRC automation platforms (such as Vanta or Drata) to scale continuous compliance programs.
- Outstanding client-facing communication skills with a track record of partnering with Sales/CS teams to navigate complex enterprise security evaluations, vendor questionnaires, and RFP processes.
- Successfully designed and implemented repeatable AI-enabled workflows that address team bottlenecks and improve efficiency.
- Ability to operate in gray areas, finding the right balance between corporate risk tolerance, operational efficiency, and regulatory requirements.
- Strong cross-functional leadership skills with the ability to influence technical and non-technical business partners to align on security compliance objectives.
This is a remote position listed on WFA Digital, the platform for professionals who work from anywhere. Browse more remote jobs across all categories.