1

Grc Lead Jobs (NOW HIRING)

Role Overview We are seeking a Security GRC Lead to build our first in-house GRC program from the ground up. In this role, you won't just write policies or collect manual screenshots in spreadsheets ...

GRC Analyst

Fairfax, VA · On-site

$75 - $95/hr

You report to the GRC Lead. Salary Range: $75,000-$95,000 Role Fit & Non‑Negotiables * Onsite at our Fairfax, VA headquarters. This role is hands‑on and evidence‑heavy. * U.S. citizen, required ...

$121K - $185K/yr

As our Senior GRC Security Lead, you will be the architect of foundational programs we are building - Gong's first-ever Common Controls Framework, standing up a formal risk process and register ...

GRC Engineer

Manhattan, NY · On-site

$120 - $190/hr

The GRC Lead owns the program and the judgment calls; you own the machinery that turns certifications into an output of normal operations. You will sit in the Security organization and work daily ...

$174 - $205/hr

About The Role As a Senior GRC Lead at Jasper, you will own our Governance, Risk, and Compliance program end-to-end--building a program that scales with our AI-native products. You will step in to ...

New

GRC Engineer

New York, NY · On-site

$151K - $273K/yr

The GRC Lead owns the program and the judgment calls; you own the machinery that turns certifications into an output of normal operations. You will sit in the Security organization and work daily ...

$174 - $205/hr

About The Role As a Senior GRC Lead at Jasper, you will own our Governance, Risk, and Compliance program end-to-end--building a program that scales with our AI-native products. You will step in to ...

ABOUT THE ROLE Aaru is building out its governance, risk, and compliance function and is hiring its first dedicated GRC Lead to own it. Our customers are large enterprises that use Aaru to pressure ...

... SOD, GRC Tools (Access Risk Management, Access Risk Analysis and EAM), IDM Tool. Experience in BOBJ 4.x security, BODS Security, Solution Manager Security. Ability to manage multiple tasks of ...

... SOD, GRC Tools (Access Risk Management, Access Risk Analysis and EAM), IDM Tool. Experience in BOBJ 4.x security, BODS Security, Solution Manager Security. Ability to manage multiple tasks of ...

The InfoSec GRC Analyst role will be a member of a 4-person team, reporting to the GRC Lead and will work closely with the Chief Information Security Officer (CISO) and InfoSec Lead. The ideal ...

The InfoSec GRC Analyst role will be a member of a 4-person team, reporting to the GRC Lead and will work closely with the Chief Information Security Officer (CISO) and InfoSec Lead. The ideal ...

GRC Lead Package Solution Consultant - Oracle Financials. This specialty recognizes the subject matter expert for guidance related to audits and other controls reviews using Oracle GRC. Additional ...

$120 - $180/hr

Summary IT SAP Security/GRC Lead Specialist: Responsible for managing and providing SAP support to Energy Transfer users within functional and technical areas of expertise. This includes interacting ...

New

GRC Engineer

Palo Alto, CA · On-site

$90 - $120/hr

GRC Engineer Why Zania Every enterprise spends millions of dollars on Governance, Risk, and ... Lead onboarding and deployment for enterprise customers from scoping and configuration through to a ...

GRC Engineer

Palo Alto, CA · On-site

$130K - $170K/yr

GRC Engineer Why Zania Every enterprise spends millions of dollars on Governance, Risk, and ... Lead onboarding and deployment for enterprise customers from scoping and configuration through to a ...

Showing results 21-40

Grc Lead information

What is a GRC lead?

GRC Leads are professionals responsible for overseeing Governance, Risk, and Compliance (GRC) programs within an organization. They ensure that the company adheres to legal, regulatory, and internal policy requirements while managing risks and maintaining effective controls. GRC Leads coordinate across departments to implement frameworks, conduct risk assessments, and drive compliance initiatives. Their role is crucial in protecting the organization from legal and reputational risks and ensuring operational integrity.

What are some common challenges a GRC lead might face when implementing new compliance frameworks across an organization?

A GRC Lead often encounters challenges such as resistance to change from staff, aligning diverse departmental processes with new compliance requirements, and ensuring consistent communication across teams. Balancing the need for thorough documentation with operational efficiency can also prove difficult. Successfully overcoming these obstacles requires strong interpersonal skills, a strategic approach to change management, and the ability to educate and motivate stakeholders at all levels of the organization.

What are the key skills and qualifications needed to thrive as a GRC lead, and why are they important?

To thrive as a GRC Lead, you need expertise in governance, risk management, and compliance frameworks, often supported by a relevant degree and certifications such as CISA, CRISC, or CISSP. Familiarity with GRC platforms like RSA Archer, ServiceNow GRC, or MetricStream is typically required. Strong analytical thinking, leadership, and communication skills distinguish top performers in this role. These capabilities are crucial for ensuring organizational compliance, minimizing risks, and effectively aligning security strategies with business goals.

What is the difference between Grc Lead vs Grc Analyst?

AspectGrc LeadGrc Analyst
CredentialsCertifications like CISA, CRISC often preferredSimilar certifications, often entry to mid-level
Work EnvironmentLeads teams, manages projects, strategic planningPerforms analysis, audits, and reporting tasks
Employer & Industry UsageUsed in large organizations for governance, risk, complianceCommon in security and compliance departments
Search & Comparison IntentOften searched for career progression or role differencesOften searched for entry-level or role clarification

The Grc Lead typically oversees GRC teams, manages strategic initiatives, and requires advanced certifications. The Grc Analyst focuses on conducting audits, analyzing risks, and supporting compliance activities. While both roles require similar certifications, the Lead has more managerial responsibilities, whereas the Analyst is more hands-on with analysis and reporting.

Is GRC still in demand?

GRC (Governance, Risk, and Compliance) roles are currently in high demand due to increasing regulatory requirements and cybersecurity concerns. Professionals with skills in risk management, compliance frameworks, and familiarity with tools like RSA Archer or ServiceNow are sought after across various industries. Certifications such as CISA or CISSP can enhance job prospects in this field.
More about Grc Lead jobs

What cities are hiring for Grc Lead jobs?

Cities with the most Grc Lead job openings:

What states have the most Grc Lead jobs?

States with the most job openings for Grc Lead jobs include:

What job categories do people searching Grc Lead jobs look for?

The top searched job categories for Grc Lead jobs are:

Infographic showing various Grc Lead job openings in the United States as of August 2026, with employment types broken down into 89% Full Time, 9% Part Time, and 2% Contract. Highlights an 91% Physical, 3% Hybrid, and 6% Remote job distribution.

Security GRC Lead

Candid Health

New York, NY • On-site

Full-time

Posted 11 days ago


Job description

About Candid Health
In simple terms, healthcare in the U.S. has a massive, invisible problem behind the scenes: getting doctors paid by insurance companies is notoriously complicated. Insurance rules are constantly changing, and every bill (or "claim") requires mountains of paperwork. When mistakes happen, bills get rejected, patients end up with unexpected charges, and healthcare providers waste billions of dollars and countless hours on administrative bureaucracy instead of focusing on patient care.
That is where Candid Health steps in. Founded by former Palantir leaders who experienced these pain points firsthand, we are building the modern financial backbone for American healthcare. Instead of relying on decades-old legacy software or attempting to patch broken systems with superficial tools, we've rebuilt the underlying infrastructure from the ground up.
Our core product is an autonomous Revenue Cycle Management (RCM) platform. Powered by AI agents and a configurable rules engine, the platform unifies clinical, billing, and insurance data into a single smart system. It acts like an intelligent, automated back-office that handles complex medical claims from start to finish-submitting them accurately on the first pass, cutting down administrative costs, and dramatically increasing cash flow for healthcare providers.
Today, we are trusted by over 200 fast-growing healthcare organizations-from digital health innovators to large enterprise medical groups-processing billions in claims annually. Backed by top investors like Sixth Street Growth, Oak HC/FT, 8VC, and Y Combinator, Candid Health recently raised a $120 million Series D to fuel the AI-driven transformation of healthcare payments and eliminate administrative friction for good.
Role Overview
We are seeking a Security GRC Lead to build our first in-house GRC program from the ground up. In this role, you won't just write policies or collect manual screenshots in spreadsheets; you will treat compliance as an engineering and data problem.
You will build automated evidence pipelines, implement compliance-as-code, and establish continuous controls monitoring across our GCP infrastructure, identity systems, and CI/CD pipelines. You will turn point-in-time audits into a continuous compliance telemetry system that keeps our platform secure, resilient, and audit-ready at all times.
Key Responsibilities
1) Compliance Automation & Engineering
  • Develop automated scripts and API integrations to collect compliance evidence directly from system sources instead of collecting manual screenshots.
  • Write and deploy infrastructure-as-code and policy enforcement rules to enforce security baselines automatically.
  • Maintain live compliance dashboards and alerts that flag configuration drift or policy violations in real time.
  • Partnering with Legal on Medicare and Medicaid compliance
  • Partnering closely with legal and finance teams on future due diligence and compliance projects

2) Framework Mapping & Control Architecture
  • Convert regulatory, security, and industry standards (SOC 2, HiTrust, PCI, HIPAA) into clear, testable technical controls.
  • Map single technical controls across multiple overlapping frameworks to eliminate redundant work.
  • Work alongside DevOps and Software Engineering teams to build compliance controls directly into CI/CD pipelines without slowing down delivery.

3) Risk Management & Audits
  • Lead technical audit readiness and external audit engagements using programmatic evidence pipelines.
  • Automate vendor risk management workflows and API-driven vendor evaluations.
  • Build continuous risk tracking tools fed by live vulnerability telemetry and identity logs rather than static quarterly surveys.

Required Qualifications
  • 3+ years in a technical security role, such as Security Engineering, Cloud Security, or Technical GRC.
  • Proficiency in Python, TypeScript, SQL and hands on experience interacting with APIs, parsing logs, and querying databases.
  • Hands-on experience with at least one primary cloud platform, GCP Preferred and Infrastructure-as-Code tools such as Terraform
  • Deep familiarity with core frameworks such as SOC 1/2, PCI, NIST, and/or HITRUST.
  • Understanding of CI/CD pipelines, Git workflows, and container environments (Docker/Kubernetes).

Preferred Qualifications
  • Certifications such as CISSP, CISA, CRISC, AWS Certified Security - Specialty, or CCSP.
  • Experience with Policy-as-Code engines
  • HITRUST experience
  • Background in software development, DevOps, or platform engineering.
  • Experience with modern continuous compliance platforms (e.g., Vanta, Drata, Anecdotes).

Our values
We spend at least as much time with our coworkers as we do with our closest friends + family - if we intend to do the most important + challenging work of our lives, it's important that these folks energize us, support us, inspire us, and push us to do our best work. This is what you can expect of your teammates at Candid (in no particular order):
  • We put our customers first
  • We take care of each other and ourselves
  • We anchor on outcomes and work relentlessly and creatively to achieve them
  • We collectively prioritize building a diverse and inclusive workspace
  • We believe humility is our greatest strength
  • We are candid, kind, and committed
  • We strive to be the most prepared person in the room
  • We are truth seekers

Pay Transparency
The estimated starting annual salary range for this position is $180,000 - 258,000 USD. The listed range is a guideline from Pave data, and the actual base salary may be modified based on factors including job-related skills, experience/qualifications, interview performance, market data, etc. Total compensation for this position may also include equity, sales incentives (for sales roles), and employee benefits. Given Candid Health's funding and size, we heavily value the potential upside from equity in our compensation package. Further note that Candid Health has minimal hierarchy and titles, but has broad ranges of experience represented within roles.