1

Director Operational Risk Jobs in Seattle, WA (NOW HIRING)

... operational risk) as bandwidth allows. What You'll Bring: Required: * 6+ years of experience in GRC, information security compliance, or IT audit, with direct ownership of at least one SOC 2 or ...

Science-line partnership & risk enablement: advise senior scientific and operational leaders on ... Demonstrated Director-level (or equivalent senior) EH&S leadership, including owning or influencing ...

This position will assist the Value Engineering/Risk Director in the development of strategic ... directors and operations staff. * Be willing to travel domestically up to 75% of their time.

This position will assist the Value Engineering/Risk Director in the development of strategic ... directors and operations staff. * Be willing to travel domestically up to 75% of their time.

The Director of Operations is an effective change leader who spurs the enthusiasm and buy-in of ... risk, or opportunity to the organization. * Manage and drive cost reduction roadmaps for company ...

The Director of Operations is an effective change leader who spurs the enthusiasm and buy-in of ... risk, or opportunity to the organization. * Manage and drive cost reduction roadmaps for company ...

Showing results 41-60

Director Operational Risk information

See Seattle, WA salary details

$61.7K

$163.6K

$297K

How much do director operational risk jobs pay per year?

As of Sep 13, 2026, the average yearly pay for director operational risk in Seattle, WA is $163,586.00, according to ZipRecruiter salary data. Most workers in this role earn between $120,500.00 and $191,400.00 per year, depending on experience, location, and employer.

What does a director of operational risk do?

A Director of Operational Risk is responsible for identifying, assessing, and mitigating risks that could impact an organization's operations. They develop risk management strategies, implement controls, and ensure compliance with relevant regulations. This role typically involves collaborating with different departments, reporting to senior management, and overseeing risk assessments and audits. The goal is to minimize losses and protect the organization from potential operational failures or external threats.

How does a director of operational risk typically collaborate with other departments to manage enterprise-wide risks?

A Director of Operational Risk works closely with teams across the organization—including compliance, internal audit, IT, and business unit leaders—to identify, assess, and mitigate potential risks. This collaboration often involves organizing risk assessments, sharing best practices, and developing response strategies for incidents. Regular cross-functional meetings and reporting are common, ensuring that risk management is integrated into day-to-day business operations. Effective communication and relationship-building are crucial for success in this role, as the Director must foster a risk-aware culture throughout the company.

What are the key skills and qualifications needed to thrive as a director of operational risk, and why are they important?

A Director of Operational Risk needs deep knowledge of risk management frameworks, regulatory requirements, and operational processes, typically supported by a degree in finance, business, or a related field. Familiarity with risk assessment tools, data analytics platforms, and certifications such as FRM or CRM is highly valued. Strong leadership, analytical thinking, and effective communication are essential soft skills for guiding teams and influencing stakeholders. These competencies are crucial for identifying, assessing, and mitigating risks that could impact organizational objectives and regulatory compliance.

What is the difference between Director Operational Risk vs Risk Manager?

AspectDirector Operational RiskRisk Manager
CredentialsTypically requires advanced degrees (e.g., MBA, Risk Management certifications)Often requires similar certifications but may have less emphasis on advanced degrees
Work EnvironmentStrategic, leadership-focused, overseeing risk frameworks across departmentsOperational, focused on identifying and mitigating specific risks within teams
Employer & Industry UsageCommon in banking, finance, insurance, and large corporationsFound across various industries including finance, healthcare, and manufacturing

The main difference is that the Director of Operational Risk typically holds a senior leadership role responsible for setting risk strategies and policies, while the Risk Manager focuses on implementing risk mitigation measures at the operational level. Both roles require relevant certifications and experience, but the Director position involves broader strategic oversight.

What are the most commonly searched types of Operational Risk jobs in Seattle, WA?

The most popular types of Operational Risk jobs in Seattle, WA are:

What are popular job titles related to Director Operational Risk jobs in Seattle, WA?

For Director Operational Risk jobs in Seattle, WA, the most frequently searched job titles are:

What job categories do people searching Director Operational Risk jobs in Seattle, WA look for?

The top searched job categories for Director Operational Risk jobs in Seattle, WA are:

What cities near Seattle, WA are hiring for Director Operational Risk jobs?

Cities near Seattle, WA with the most Director Operational Risk job openings:

Infographic showing various Director Operational Risk job openings in Seattle, WA as of August 2026, with employment types broken down into 84% Full Time, 14% Part Time, and 2% Contract. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution, with an average salary of $163,040 per year, or $78.4 per hour.

Senior Manager, GRC

Seattle, WA • Remote

Maven Clinic
Health Care and Social Assistance • 501 - 1,000 employees

Full-time

Medical, Dental, Retirement

Posted 5 days ago


Job description

Maven Clinic is the world's largest virtual clinic for women and families on a mission to make healthcare work for all of us. Through Maven Enterprise, the company partners with more than 2,300 employers and health plans to provide end-to-end women's and family health programs spanning fertility and family building, maternity and newborn care, parenting and pediatrics, and menopause and midlife — improving clinical outcomes, reducing healthcare costs, and expanding equitable access to high-quality care at scale. Through its consumer platform, Maven provides direct access to virtual care across 30+ specialties, as well as dedicated hormone and GLP-1 care programs purpose-built for women. Founded in 2014 by CEO Kate Ryder, Maven Clinic has raised more than $425 million from leading healthcare and technology investors including General Catalyst, Sequoia, Dragoneer Investment Group, Oak HC/FT, StepStone Group, Icon Ventures, and Lux Capital. Recognized for innovation and industry leadership, Maven has been named to the TIME100 Most Influential Companies, CNBC Disruptor 50, Fast Company's Most Innovative Companies, and FORTUNE Best Places to Work. Learn more at mavenclinic.com

An award-winning culture working towards an important mission –  Maven Clinic is a recipient of over 30 workplace and innovation awards, including: 

  • TIME 100 Most Influential Companies (2023, 2026)
  • Fortune Change the World (2024)
  • CNBC Disruptor 50 List (2022, 2023, 2024)
  • Fortune Best Workplaces for Millennials (2024)
  • Fortune Best Workplaces in Health Care (2024)
  • Fast Company Most Innovative Companies (2020, 2023)
  • Fortune Best Workplaces NY (2020, 2021, 2022, 2023, 2024)

About the Role:

We're looking for a GRC Manager to own governance, risk, and compliance for our B2B health benefits platform. You'll act as the team lead for our GRC function, working closely with one other team member to run audits, write policies, answer RFIs, and monitor controls day to day.

This role touches almost every team: partnering with Engineering, IT, and HR to gather evidence and close gaps; working directly with customers and their security teams during due diligence; and managing auditor relationships through certification cycles. You'll also bring solid project management skills, sequencing audits, tracking remediation, and hitting deadlines across multiple concurrent workstreams. You'll report directly to the CISO/Head of Security and act as the organization's primary voice on compliance posture. You will interface internally and externally with customers, auditors, and partners.

Our platform facilitates virtual health visits for employer-sponsored benefits, which means security, privacy, and compliance are core to customer trust and our ability to sell into enterprise and health-plan accounts.

What You'll Do:

External Audit & Certification Management
  • Own continuation and renewal of our SOC 2 (Type II) and HITRUST certifications end-to-end. You'll scope each cycle, pull evidence, work directly with auditors, and track remediation through to the final report.
  • Lead the ground-up establishment of ISO 27001 and ISO 42001 certification programs. That means gap assessments, control mapping, writing ISMS/AIMS policies and statements of applicability, gaining cross team buy in, and getting us ready for initial certification audits.
  • Manage the annual/ongoing audit calendar across all frameworks, coordinating with internal stakeholders (Engineering, IT, HR, Legal) to gather evidence and close findings on time.
  • Track regulatory and framework changes (HIPAA, state privacy laws, ISO updates) and translate them into control updates.
Customer-Facing Security & Compliance
  • Serve as the primary owner of security questionnaires and RFIs/RFPs for the Sales and Customer Success teams. Ensure responses to prospect and customer's due-diligence requests are accurate and on deadline.
  • Maintain a security knowledge base / answer library to reduce turnaround time on recurring questions.
  • Partner with Sales Engineering and Account teams to represent our security and compliance posture directly in customer calls when needed. You'll join customer calls directly when security is a blocker in the deal.
  • Manage relationships with customers' internal security/compliance teams during onboarding and renewal cycles.
Internal Audit & Control Monitoring
  • Build and run an internal audit/control-monitoring program focused first on verifying that externally audited controls are actually operating day-to-day. 
  • Flag control gaps or process drift to the CISO/Head of Security before they become audit findings.
  • Over time, expand scope beyond audited-control verification into broader internal audit territory (policy adherence, vendor risk, operational risk) as bandwidth allows.

What You'll Bring:

Required:

  • 6+ years of experience in GRC, information security compliance, or IT audit, with direct ownership of at least one SOC 2 or similar audit cycle from start to finish.
  • Working knowledge of SOC 2, HITRUST, and ISO 27001 frameworks hands-on .
  • Experience responding to customer security questionnaires/RFIs, ideally in a B2B SaaS or healthcare-adjacent environment.
  • Strong cross-team collaboration skills. You'll regularly work with Engineering, IT, HR, Legal, and Sales to gather evidence, close control gaps, and keep everyone aligned on deadlines.
  • Solid project management instincts: able to sequence overlapping audits and certification projects, track dependencies and remediation items, and hit dates without needing someone else to manage the plan for you.
  • Strong written communication; you'll be writing policies, RFI responses, and audit narratives that both auditors and non-technical stakeholders need to understand.

Strongly preferred:

  • Direct experience standing up a new certification (SOC2, HITRUST, ISO 27001 and/or the newer 42001 AI management standard) rather than just maintaining an existing one.
  • Experience with GRC/compliance automation tooling (Vanta, Drata, Secureframe, Hyperproof, or similar).
  • Background in health tech, digital health, or another regulated B2B vertical (fintech, insurtech) where compliance is a sales enabler.
  • A relevant certification such as CISA, CRISC, CISSP, PMP or CAPM, CISM, CTRC/CAP.
  • Exposure to vulnerability management or IT operations well enough to meaningfully audit those processes rather than just take reports at face value.
  • Experience partnering with Sales/Sales Engineering as a technical or compliance resource during the deal cycle.

The base salary range for this role is $170,000 - $201,000 per year. You will also be entitled to receive equity and benefits. Individual pay decisions are based on a number of factors, including qualifications for the role, experience level, and skillset.

Maven embraces a flexible hybrid work model. Our teams primarily operate from the New York Metropolitan area, NY, and remotely via San Francisco/Bay Area, CA, Seattle, WA. For those in our New York City office, we encourage in-person collaboration by requiring team members to work onsite three days a week  (Tuesday, Wednesday, Thursday). For those based in Boston, DC, Chicago, Seattle, and San Francisco, we encourage in-person collaboration by requiring team members to attend monthly Work Together Days within these cities. This policy aims to balance remote work flexibility with the benefits of face-to-face interaction.

At Maven we believe that a diverse set of backgrounds and experiences enrich our teams and allow us to achieve above and beyond our goals. If you do not have experience in all of the areas detailed above, we hope that you will share your unique background with us in your application and how it can be additive to our teams.

Benefits That Work For You

Our benefits are designed to support your health, well-being and career development, helping you thrive both personally and professionally. We remain focused on providing a competitive benefits package for our employees. On top of standards such as employer-covered health, dental, and insurance plan options, we offer an inclusive approach to benefits:

  • Maven for Mavens: access to the full platform and specialists, including care for mental health, reproductive health, family planning and pediatrics.
  • Whole-self care through wellness partnerships
  • Hybrid work, in office meals, and work together days 
  • 16 weeks 100% paid parental leave and new parent stipend (for Mavens who've been with us for 1 year+)
  • Annual professional development stipend and access to a personal career coach through Maven for Mavens
  • 401K matching for US-based employees, with immediate vesting

These benefits are applicable to Maven Clinic Co., US-based, full-time employees only. 1099/Contract Providers are ineligible for these benefits. 

Maven is an affirmative action and equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, veteran status, or genetic information. Maven is committed to providing access, equal opportunity and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. Maven Clinic interview requests and job offers only originate from an @mavenclinic.com email address (e.g jsmith@mavenclinic.com). Maven Clinic will never ask for sensitive information to be delivered over email or phone. If you receive a scam issue or a security issue involving Maven Clinic please notify us at: security@mavenclinic.com. For general and additional inquiries, please contact us at careers@mavenclinic.com.