Governance, Risk & Compliance (GRC) Lead – Information Security & Risk

icaremanager| Posted on 10/30/2025full timeLead
Active

Job description

About iCareManagerAt iCareManager (iCM), we build cloud-based software that empowers care teams serving individuals in long-term care, IDD, and case management programs. As we expand our technology and operations, maintaining the highest standards of data security and compliance is a top priority.Role OverviewThe GRC Lead will be responsible for developing, implementing, and maintaining iCareManager’s governance, risk, and compliance framework. The role ensures continued compliance with SOC 2 Type 2, HIPAA, and other regulatory and security frameworks, while driving consistent, measurable processes across departments.This position connects three key areas of iCM’s security model:GRC & Compliance Oversight (this role)Internal IT Security OperationsExternal Managed Detection and Response (MDR) PartnerWhile this is not a hands-on technical role, it requires strong understanding of IT and security controls to ensure governance, documentation, and accountability are in place.Key ResponsibilitiesLead and sustain SOC 2 Type 2 certification, ensuring alignment with Trust Services Criteria.Administer and manage the Vanta compliance automation platform — track controls, evidence, and remediation.Translate company policies into department-level procedures and monitor compliance activities.Conduct quarterly and annual risk assessments; maintain the Risk Register with mitigation tracking.Serve as liaison between IT Security and MDR provider to ensure continuous monitoring and evidence collection for audits.Coordinate external audits and ensure timely collection of compliance documentation and evidence.Maintain a compliance calendar covering monthly policy checks, quarterly internal audits, and annual risk assessments.Track and report control status, incidents, and audit findings to closure with department heads.Drive company-wide security and compliance awareness training.Promote a culture of proactive compliance, governance, and continuous improvement.RequirementsRequired QualificationsBachelor’s degree in Information Technology, Computer Science, Cybersecurity, or related field.5–7 years of combined experience in IT Security, Compliance, Governance, or Risk Management.Practical knowledge of frameworks like SOC 2, HIPAA, ISO 27001, and NIST.Experience performing internal audits, risk assessments, and control implementation.Familiarity with compliance automation platforms (Vanta preferred).Excellent communication and documentation skills; able to bridge technical and non-technical teams.Preferred CertificationsOne or more: CISM, CISSP, CRISC, CISA, or ISO 27001 Lead Implementer/Auditor.Experience in SaaS, cloud environments (AWS or Azure), and vendor risk management.Growth PathThis is a high-visibility role with strong career advancement opportunities. As iCareManager continues to scale its governance and operational maturity, the GRC Lead will play a pivotal role — with potential growth into positions such as Director of Security Governance, Head of GRC, or Operations Director overseeing broader enterprise functions.About iCareManagerAt iCareManager (iCM), we build cloud-based software that empowers care teams serving individuals in long-term care, IDD, and case management programs. As we expand our technology and operations, maintaining the highest standards of data security and compliance is a top priority.Role OverviewThe GRC Lead will be responsible for developing, implementing, and maintaining iCareManager’s governance, risk, and compliance framework. The role ensures continued compliance with SOC 2 Type 2, HIPAA, and other regulatory and security frameworks, while driving consistent, measurable processes across departments.This position connects three key areas of iCM’s security model:GRC & Compliance Oversight (this role)Internal IT Security OperationsExternal Managed Detection and Response (MDR) PartnerWhile this is not a hands-on technical role, it requires strong understanding of IT and security controls to ensure governance, documentation, and accountability are in place.Key ResponsibilitiesLead and sustain SOC 2 Type 2 certification, ensuring alignment with Trust Services Criteria.Administer and manage the Vanta compliance automation platform — track controls, evidence, and remediation.Translate company policies into department-level procedures and monitor compliance activities.Conduct quarterly and annual risk assessments; maintain the Risk Register with mitigation tracking.Serve as liaison between IT Security and MDR provider to ensure continuous monitoring and evidence collection for audits.Coordinate external audits and ensure timely collection of compliance documentation and evidence.Maintain a compliance calendar covering monthly policy checks, quarterly internal audits, and annual risk assessments.Track and report control status, incidents, and audit findings to closure with department heads.Drive company-wide security and compliance awareness training.Promote a culture of proactive compliance, governance, and continuous improvement.About iCareManagerAt iCareManager (iCM), we build cloud-based software that empowers care teams serving individuals in long-term care, IDD, and case management programs. As we expand our technology and operations, maintaining the highest standards of data security and compliance is a top priority.Role OverviewThe GRC Lead will be responsible for developing, implementing, and maintaining iCareManager’s governance, risk, and compliance framework. The role ensures continued compliance with SOC 2 Type 2, HIPAA, and other regulatory and security frameworks, while driving consistent, measurable processes across departments.This position connects three key areas of iCM’s security model:GRC & Compliance Oversight (this role)Internal IT Security OperationsExternal Managed Detection and Response (MDR) PartnerWhile this is not a hands-on technical role, it requires strong understanding of IT and security controls to ensure governance, documentation, and accountability are in place.Key ResponsibilitiesLead and sustain SOC 2 Type 2 certification, ensuring alignment with Trust Services Criteria.Administer and manage the Vanta compliance automation platform — track controls, evidence, and remediation.Translate company policies into department-level procedures and monitor compliance activities.Conduct quarterly and annual risk assessments; maintain the Risk Register with mitigation tracking.Serve as liaison between IT Security and MDR provider to ensure continuous monitoring and evidence collection for audits.Coordinate external audits and ensure timely collection of compliance documentation and evidence.Maintain a compliance calendar covering monthly policy checks, quarterly internal audits, and annual risk assessments.Track and report control status, incidents, and audit findings to closure with department heads.Drive company-wide security and compliance awareness training.Promote a culture of proactive compliance, governance, and continuous improvement.

About iCareManager

About iCareManager

At iCareManager (iCM), we build cloud-based software that empowers care teams serving individuals in long-term care, IDD, and case management programs. As we expand our technology and operations, maintaining the highest standards of data security and compliance is a top priority.

Role Overview

Role Overview

The GRC Lead will be responsible for developing, implementing, and maintaining iCareManager’s governance, risk, and compliance framework. The role ensures continued compliance with SOC 2 Type 2, HIPAA, and other regulatory and security frameworks, while driving consistent, measurable processes across departments.

GRC LeadSOC 2 Type 2HIPAA

This position connects three key areas of iCM’s security model:

  • GRC & Compliance Oversight (this role)

GRC & Compliance Oversight (this role)

GRC & Compliance Oversight
  • Internal IT Security Operations

Internal IT Security Operations

Internal IT Security Operations
  • External Managed Detection and Response (MDR) Partner

External Managed Detection and Response (MDR) Partner

External Managed Detection and Response (MDR) Partner

While this is not a hands-on technical role, it requires strong understanding of IT and security controls to ensure governance, documentation, and accountability are in place.

Key Responsibilities

Key Responsibilities
  • Lead and sustain SOC 2 Type 2 certification, ensuring alignment with Trust Services Criteria.

Lead and sustain SOC 2 Type 2 certification, ensuring alignment with Trust Services Criteria.

  • Administer and manage the Vanta compliance automation platform — track controls, evidence, and remediation.

Administer and manage the Vanta compliance automation platform — track controls, evidence, and remediation.

Vanta compliance automation platform
  • Translate company policies into department-level procedures and monitor compliance activities.

Translate company policies into department-level procedures and monitor compliance activities.

  • Conduct quarterly and annual risk assessments; maintain the Risk Register with mitigation tracking.

Conduct quarterly and annual risk assessments; maintain the Risk Register with mitigation tracking.

risk assessmentsRisk Register
  • Serve as liaison between IT Security and MDR provider to ensure continuous monitoring and evidence collection for audits.

Serve as liaison between IT Security and MDR provider to ensure continuous monitoring and evidence collection for audits.

  • Coordinate external audits and ensure timely collection of compliance documentation and evidence.

Coordinate external audits and ensure timely collection of compliance documentation and evidence.

  • Maintain a compliance calendar covering monthly policy checks, quarterly internal audits, and annual risk assessments.

Maintain a compliance calendar covering monthly policy checks, quarterly internal audits, and annual risk assessments.

compliance calendar
  • Track and report control status, incidents, and audit findings to closure with department heads.

Track and report control status, incidents, and audit findings to closure with department heads.

  • Drive company-wide security and compliance awareness training.

Drive company-wide security and compliance awareness training.

  • Promote a culture of proactive compliance, governance, and continuous improvement.

Promote a culture of proactive compliance, governance, and continuous improvement.