Senior Governance, Risk, Compliance (GRC) Analyst
$161.6k - $202kHeadway - Design & Development
Senior Governance, Risk, Compliance (GRC) Analyst
New York, New York, United States; San Francisco, California, United States; Seattle, Washington, United States
1 in 4 people in the US have a treatable mental health condition, but most providers don't accept insurance, making therapy too expensive for most people. Headway's mission is to fix this by building a new mental healthcare system everyone can access. We started by solving the biggest barrier to care: insurance. The admin work - credentialing, claims, payment reconciliation - is a nightmare. We've automated that.
But we're going further. Over 75,000 providers across all 50 states run their practice on our software, serving over 1 million patients. We are building the best tools for therapists to run their entire practice, reimagining the experience of finding a therapist, and investing in the platform foundations to enable this at scale. We aren't just a billing layer; we are becoming the platform where care actually happens.
We're a Series D company with $325M+ in funding (a16z, Accel, Spark Capital, etc.), looking for exceptional people to help us achieve this mission. We want your time here to be the most meaningful experience of your career. Join us, and help change mental healthcare for the better.
About the Role
Headway handles sensitive health data for millions of patients — and that responsibility demands a security and compliance program that scales with the business. We're building out our dedicated GRC team to improve and mature our program!
You'll join the Security team and work across four pillars: security certifications (HITRUST, SOC 2, PCI-DSS, HIPAA), third-party risk management, security awareness training, and technical risk management. You won't be maintaining a stale compliance program — you'll be building a modern, AI-enabled one at a company that's transforming how mental healthcare is delivered in the United States.
This role reports to Blake Atkinson, Director of Security, and partners closely with Privacy and Engineering teams.
What You'll Own
- Support HITRUST, SOC 2, PCI-DSS, and HIPAA audit readiness — collecting evidence, coordinating with assessors, tracking control gaps and remediation timelines.
- Build and manage the vendor security assessment lifecycle — questionnaires, SOC 2/ISO reviews, risk scoring, and policy enforcement across procurement and renewals.
- Stand up and run Headway's security awareness training program — onboarding modules, phishing simulations, annual compliance training, and completion tracking.
- Operate the centralized risk register — identifying, assessing, and tracking technical security risks through mitigation, and surfacing risk-informed priorities to engineering and security leadership.
- Partner cross-functionally with Privacy, Legal, IT, and Engineering to embed compliance into how Headway operates — not bolt it on after the fact.
You'd be a great fit if…
- You have 5+ years of experience in a GRC, compliance, or security risk role.
- You have working knowledge of at least two of: HITRUST, SOC 2, PCI-DSS, or HIPAA.
- You've used a GRC platform like Vanta, Drata, OneTrust, or similar to automate evidence collection or manage controls.
- You communicate compliance requirements clearly to both technical and non-technical audiences.
- You default to building repeatable processes over one-off heroics.
- You're excited about using AI and modern tooling to scale compliance operations.
- Bonus: you've worked in healthcare or healthtech and understand what HIPAA means in practice, not just in theory.
Why Headway
- Mission that matters — your work directly protects millions of patients accessing mental healthcare.
- Real risk mitigation — this isn't checkbox compliance; the data you're protecting and the programs you're building have direct, tangible impact.
- Forward-thinking healthtech — Headway is investing in AI-enabled security workflows and modern GRC tooling, not spreadsheet-driven compliance.
- Build from scratch — you're standing up Headway's GRC function, not inheriting legacy processes.
Compensation and Benefits:
The expected base pay range for this position is $161,600 to 202,000 based on a variety of factors including qualifications, experience, and geographic location. In addition to base salary, this role may be eligible for an equity grant, depending on the position and level.
We are committed to offering a comprehensive and competitive total rewards package, including robust health and wellness benefits, retirement savings, and meaningful ownership opportunities through equity. Compensation decisions are made holistically, ensuring fairness and alignment with market benchmarks while recognizing individual contributions and potential.
- Benefits offered include:
- Equity compensation
- Medical, Dental, and Vision coverage
- HSA / FSA
- 401K
- Work-from-Home Stipend
- Therapy Reimbursement
- 16-week parental leave for eligible employees
- Carrot Fertility annual reimbursement and membership
- 13 paid holidays each year as well as a Holiday Break during the week between December 25th and December 31st
- Flexible PTO
- Employee Assistance Program (EAP)
- Training and professional development
Headway participates in E-Verify. To learn more, click here.
A notice to Headway applicants: To protect yourself against phishing and recruitment fraud, please note that Headway only accepts applications through our official careers page at Headway will never refer you to external websites, ask for payment or personal information, or conduct interviews via messaging apps. All official communication will come from a @findheadway.com email address. If you are contacted by someone claiming to be from Headway via an unofficial channel, please do not share any information and report it as spam.
$161.6k - $202k
...that responsibility demands a security and compliance program that scales with the business. We're building out our dedicated GRC team to improve and mature our program! You... ...HITRUST, SOC 2, PCI-DSS, HIPAA), third-party risk management, security awareness training, and...SeniorWork from homeFlexible hours- ...Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We're partnering with the world's leading AI research labs to build smarter, safer AI - and we need practitioners who know how compliance and risk management actually work inside real organizations...SuggestedHourly payOngoing contractContract workFreelanceRemote workWorldwideFlexible hours
$74.58k - $120k
...GRC Analyst Apply Online Tyler Technologies is seeking a Governance, Risk, and Compliance (GRC) Analyst to support our Data & Insights (D&I) solutions within the Security team. This role offers a meaningful opportunity to own and evolve the compliance posture...SuggestedLocal areaRemote workShift work- A prominent technology firm in Seattle is seeking a Governance, Risk, and Compliance (GRC) Analyst to enhance its data and insights solutions. The role emphasizes sustaining FedRAMP Moderate Authorization and requires strong organizational skills and collaboration across...Suggested
$145.19k - $203.26k
...Origin, providing oversight and governance to align technology and... ...Use automation for various GRC tasks including scorecard creation, roadmap updates, and compliance evidence gathering. Use outcome... ...actions. Generate reports on risk assessments, compliance status...SeniorPermanent employmentTemporary workLocal area$120k - $165k
True Anomaly is looking for a driven Enterprise Risk Analyst in Long Beach, CA, to enhance its risk management capabilities. This role... ...managing vendor risks, and collaborating across teams to ensure compliance with standards like NIST. Applicants should have over 5 years...Senior- Affirm is seeking a Compliance Analyst II to support its compliance governance and oversight program in Seattle. The role involves challenging operations teams to... ...Candidates should have 3-5+ years in compliance or risk within financial services, excellent communication...Remote jobFlexible hours
- ...Senior Vice President, Legal and Chief Compliance Officer (CCO) About the Company Nationally recognized healthcare services organization... ...role that directly impacts organizational strategy, governance, and risk posture. The successful candidate will be a trusted...Senior
$143k - $210k
...Senior Supply Chain Compliance Analyst (SOX) Livingston, NJ / Sunnyvale, CA / Bellevue, WA CoreWeave is The... ...variances) and use them to surface risks and drive continuous improvement.... ...management). Familiarity with broader governance and compliance frameworks (e.g.,...SeniorTemporary workWork at officeFlexible hours$77k - $202k
PwC is seeking a Senior Associate in Cybersecurity & Privacy in Seattle. The role involves... ...in cybersecurity or technology risk management. The position offers a salary... ..., and more. Join PwC to impact regulatory compliance and risk management. #J-18808-Ljbffr PwCSenior$77k - $202k
...time Travel Requirements: Up to 60% At PwC, our people in risk and compliance focus on maintaining regulatory compliance and managing risks... ...programs using industry frameworks and methodologies. As a Senior Associate you are expected to analyze complex problems, mentor...SeniorFull time$88k - $124k
...IG Compliance & Security Analyst Cooley is seeking an IG Compliance... ...join the Information Governance & Data Privacy team.... ...requests. This role tracks risks, monitors adherence... ..., and working in the GRC platform Conduct... ...for consideration of Senior designation with 5+ years...Full timeContract workTemporary workWork experience placementWork at officeFlexible hoursWeekend work$153.6k - $192k
Brex is seeking a Senior GRC Engineer in Seattle to drive critical Governance, Risk, and Compliance processes. This role involves automating security controls and building integrations to maintain compliance as Brex expands. Candidates should have over 5 years of experience...Senior$88k - $124k
IG Compliance & Security Analyst Cooley is seeking an IG Compliance & Security... ...join the Information Governance & Data Privacy team.... .../support periodic risk assessments and... ...risk and compliance (GRC) processes, solutions... ...for consideration of Senior designation with 5+ years...Full timeTemporary workWork experience placementFlexible hoursWeekend work$88k - $124k
Cooley LLP is seeking an IG Compliance & Security Analyst to join their Information Governance & Data Privacy team. The ideal candidate will conduct audits to ensure... ...initiatives. They should have a background in governance, risk and compliance as well as experience with ISO 270...- ...GRC Business Analyst Lululemon is a yoga-inspired technical apparel company up to big things.... ...implementation of the ServiceNow Integrated Risk Management (IRM) modules. This is a... ...of GRC processes including policy and compliance, and risk management. This role will...
- ...DescriptionJob Description About the Role: Join CFM Partners GRC, Inc. as a Regulatory Compliance Specialist - Content & Product. In this dynamic role... ...Partners GRC, Inc. helps organizations strengthen governance, manage risk, and build a lasting culture of compliance. Based in...
$148.7k - $201.2k
...team at the forefront of global compliance innovation, where you'll... ...compliance-orchestrating real-time risk detection to catch... ...patterns, and creating adaptive governance frameworks that stay ahead of... ...businesses and reporting to senior leadership Amazon is an equal...SeniorFlexible hours- KellyMitchell Group is seeking a Senior Analyst in Third Party Risk Management. This remote position involves assessing and managing third-party risk through enhancement of Vendor Risk Management practices, supporting security assessments, and improving processes. Ideal...SeniorRemote job
$119k - $193k
...Forrester is currently looking for a Senior Analyst to conduct research and deliver strategic advice for risk management leaders and their teams... ...business strategy. Expertise in compliance management, internal or external audit, and GRC platforms is strongly desired....SeniorFor contractors- An international consulting firm seeks a Senior Consultant for Risk Technology in Seattle. This role involves designing and implementing risk management solutions using ServiceNow IRM and leading cross-disciplinary projects. Ideal candidates have a relevant educational...Senior
- Travelers Canada in Washington is hiring a Risk Control consultant responsible for maintaining a consistent field presence, consulting clients on risk strategies, and analyzing loss trends. Candidates should possess a bachelor's degree and 7+ years in safety or risk management...Senior
$90.4k - $168.2k
...as passionate about your future as we are, join our team. KPMG is currently seeking a Sr. Associate, Security Governance, Risk and Compliance (Audit) to join our Enterprise Security Services organization. This is a remote work opportunity team. Responsibilities...SeniorH1bLocal areaRemote work$121.2k - $163.9k
...Join our global advertising measurement compliance program that ensures Amazon's advertising... ...people. The Internal Audit team is seeking a Senior Manager to support the Media Rating... ...compliance program deliverables and supporting risk assessments to prioritize the program...SeniorWork at officeWorldwideFlexible hours$87.8k - $160.9k
Broughton Group in Seattle, United States, seeks an IT Auditor to lead client engagements and conduct risk assessments. Candidates should possess a bachelor’s or master’s degree, with at least 2 years of experience in IT auditing or risk advisory roles. This position offers...SeniorFlexible hours$156.4k - $211.6k
...growth. Find your future with us. Boeing is looking for a Senior Compliance Analyst to join our dynamic team. The ideal candidate will have... ..., and analyze disparate information to identify compliance risks and communicate findings in a concise, actionable manner for...SeniorPermanent employmentWork experience placementRelocationVisa sponsorshipWork visaRelocation packageFlexible hoursShift workDay shift- ...Earned Value Compliance Analysts (Experienced and Senior) The Boeing Company is hiring Experienced and Senior Earned Value Compliance Analysts (Level... ...senior leaders and get everyone on the same page about risks, opportunities, and necessary changes Position Responsibilities...SeniorContract workWork experience placementRemote workRelocation packageFlexible hours
$117.1k - $165k
...please see The Manager, AI Governance & Policy defines and enforces... ...actionable policies, monitor compliance across use cases, and serve as... ...questions from the business Risk, Incident & Audit Management... ...Policy management platforms, GRC tools (ServiceNow GRC, Archer...Live inLocal areaWorldwide- A global consulting firm in Seattle is seeking a Senior Risk Consultant to perform IT audits and provide specialized services to clients... ...experience, including knowledge of internal controls and compliance regulations. This full-time position offers a competitive salary...SeniorFull timeFlexible hours
$87.8k - $160.9k
...exceptional experience for yourself, and a better working world for all. The opportunity The objective of our consulting risk services is to provide clients with a candid and reliable overview of their risk landscape. Our solutions can be used by our clients...SeniorContract workSummer holidayWork at officeFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Governance, Risk, Compliance (GRC) Analyst. Be the first to apply!
- transaction risk analyst Seattle, WA
- operational risk consultant Seattle, WA
- it risk analyst Seattle, WA
- operational risk specialist Seattle, WA
- risk analyst Seattle, WA
- senior quantitative risk analyst Seattle, WA
- risk officer Seattle, WA
- risk consultant Seattle, WA
- coding compliance specialist Seattle, WA
- regulatory affairs specialist Seattle, WA

