Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Governance, Risk, Compliance (GRC) Analyst

$161.6k - $202k

Headway - Design & Development

Senior Governance, Risk, Compliance (GRC) Analyst

New York, New York, United States; San Francisco, California, United States; Seattle, Washington, United States

1 in 4 people in the US have a treatable mental health condition, but most providers don't accept insurance, making therapy too expensive for most people. Headway's mission is to fix this by building a new mental healthcare system everyone can access. We started by solving the biggest barrier to care: insurance. The admin work - credentialing, claims, payment reconciliation - is a nightmare. We've automated that.

But we're going further. Over 75,000 providers across all 50 states run their practice on our software, serving over 1 million patients. We are building the best tools for therapists to run their entire practice, reimagining the experience of finding a therapist, and investing in the platform foundations to enable this at scale. We aren't just a billing layer; we are becoming the platform where care actually happens.

We're a Series D company with $325M+ in funding (a16z, Accel, Spark Capital, etc.), looking for exceptional people to help us achieve this mission. We want your time here to be the most meaningful experience of your career. Join us, and help change mental healthcare for the better.

About the Role

Headway handles sensitive health data for millions of patients — and that responsibility demands a security and compliance program that scales with the business. We're building out our dedicated GRC team to improve and mature our program!

You'll join the Security team and work across four pillars: security certifications (HITRUST, SOC 2, PCI-DSS, HIPAA), third-party risk management, security awareness training, and technical risk management. You won't be maintaining a stale compliance program — you'll be building a modern, AI-enabled one at a company that's transforming how mental healthcare is delivered in the United States.

This role reports to Blake Atkinson, Director of Security, and partners closely with Privacy and Engineering teams.

What You'll Own
  • Support HITRUST, SOC 2, PCI-DSS, and HIPAA audit readiness — collecting evidence, coordinating with assessors, tracking control gaps and remediation timelines.
  • Build and manage the vendor security assessment lifecycle — questionnaires, SOC 2/ISO reviews, risk scoring, and policy enforcement across procurement and renewals.
  • Stand up and run Headway's security awareness training program — onboarding modules, phishing simulations, annual compliance training, and completion tracking.
  • Operate the centralized risk register — identifying, assessing, and tracking technical security risks through mitigation, and surfacing risk-informed priorities to engineering and security leadership.
  • Partner cross-functionally with Privacy, Legal, IT, and Engineering to embed compliance into how Headway operates — not bolt it on after the fact.
You'd be a great fit if…
  • You have 5+ years of experience in a GRC, compliance, or security risk role.
  • You have working knowledge of at least two of: HITRUST, SOC 2, PCI-DSS, or HIPAA.
  • You've used a GRC platform like Vanta, Drata, OneTrust, or similar to automate evidence collection or manage controls.
  • You communicate compliance requirements clearly to both technical and non-technical audiences.
  • You default to building repeatable processes over one-off heroics.
  • You're excited about using AI and modern tooling to scale compliance operations.
  • Bonus: you've worked in healthcare or healthtech and understand what HIPAA means in practice, not just in theory.
Why Headway
  • Mission that matters — your work directly protects millions of patients accessing mental healthcare.
  • Real risk mitigation — this isn't checkbox compliance; the data you're protecting and the programs you're building have direct, tangible impact.
  • Forward-thinking healthtech — Headway is investing in AI-enabled security workflows and modern GRC tooling, not spreadsheet-driven compliance.
  • Build from scratch — you're standing up Headway's GRC function, not inheriting legacy processes.

Compensation and Benefits:

The expected base pay range for this position is $161,600 to 202,000 based on a variety of factors including qualifications, experience, and geographic location. In addition to base salary, this role may be eligible for an equity grant, depending on the position and level.

We are committed to offering a comprehensive and competitive total rewards package, including robust health and wellness benefits, retirement savings, and meaningful ownership opportunities through equity. Compensation decisions are made holistically, ensuring fairness and alignment with market benchmarks while recognizing individual contributions and potential.

  • Benefits offered include:
    • Equity compensation
    • Medical, Dental, and Vision coverage
    • HSA / FSA
    • 401K
    • Work-from-Home Stipend
    • Therapy Reimbursement
    • 16-week parental leave for eligible employees
    • Carrot Fertility annual reimbursement and membership
    • 13 paid holidays each year as well as a Holiday Break during the week between December 25th and December 31st
    • Flexible PTO
    • Employee Assistance Program (EAP)
    • Training and professional development

Headway participates in E-Verify. To learn more, click here.

A notice to Headway applicants: To protect yourself against phishing and recruitment fraud, please note that Headway only accepts applications through our official careers page at Headway will never refer you to external websites, ask for payment or personal information, or conduct interviews via messaging apps. All official communication will come from a @findheadway.com email address. If you are contacted by someone claiming to be from Headway via an unofficial channel, please do not share any information and report it as spam.

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Senior Governance, Risk, Compliance (GRC) Analyst in Seattle, WA vacancy
  • $161.6k - $202k

     ...that responsibility demands a security and compliance program that scales with the business. We're building out our dedicated GRC team to improve and mature our program! You...  ...HITRUST, SOC 2, PCI-DSS, HIPAA), third-party risk management, security awareness training, and... 
    Senior
    Work from home
    Flexible hours

    Headway - Design & Development

    Seattle, WA
    1 day ago
  •  ...Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We're partnering with the world's leading AI research labs to build smarter, safer AI - and we need practitioners who know how compliance and risk management actually work inside real organizations... 
    Suggested
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Worldwide
    Flexible hours

    Alignerr

    Seattle, WA
    2 days ago
  • $74.58k - $120k

     ...GRC Analyst Apply Online Tyler Technologies is seeking a Governance, Risk, and Compliance (GRC) Analyst to support our Data & Insights (D&I) solutions within the Security team. This role offers a meaningful opportunity to own and evolve the compliance posture... 
    Suggested
    Local area
    Remote work
    Shift work

    Tyler Technologies

    Seattle, WA
    2 days ago
  • A prominent technology firm in Seattle is seeking a Governance, Risk, and Compliance (GRC) Analyst to enhance its data and insights solutions. The role emphasizes sustaining FedRAMP Moderate Authorization and requires strong organizational skills and collaboration across... 
    Suggested

    Tyler Technologies, Inc.

    Seattle, WA
    4 days ago
  • $145.19k - $203.26k

     ...Origin, providing oversight and governance to align technology and...  ...Use automation for various GRC tasks including scorecard creation, roadmap updates, and compliance evidence gathering. Use outcome...  ...actions. Generate reports on risk assessments, compliance status... 
    Senior
    Permanent employment
    Temporary work
    Local area

    Blue Origin

    Seattle, WA
    2 days ago
  • $120k - $165k

    True Anomaly is looking for a driven Enterprise Risk Analyst in Long Beach, CA, to enhance its risk management capabilities. This role...  ...managing vendor risks, and collaborating across teams to ensure compliance with standards like NIST. Applicants should have over 5 years... 
    Senior

    True Anomaly

    Seattle, WA
    19 hours ago
  • Affirm is seeking a Compliance Analyst II to support its compliance governance and oversight program in Seattle. The role involves challenging operations teams to...  ...Candidates should have 3-5+ years in compliance or risk within financial services, excellent communication... 
    Remote job
    Flexible hours

    Affirm

    Seattle, WA
    2 days ago
  •  ...Senior Vice President, Legal and Chief Compliance Officer (CCO) About the Company Nationally recognized healthcare services organization...  ...role that directly impacts organizational strategy, governance, and risk posture. The successful candidate will be a trusted... 
    Senior

    Confidential

    Seattle, WA
    2 days ago
  • $143k - $210k

     ...Senior Supply Chain Compliance Analyst (SOX) Livingston, NJ / Sunnyvale, CA / Bellevue, WA CoreWeave is The...  ...variances) and use them to surface risks and drive continuous improvement....  ...management). Familiarity with broader governance and compliance frameworks (e.g.,... 
    Senior
    Temporary work
    Work at office
    Flexible hours

    CoreWeave

    Bellevue, WA
    1 day ago
  • $77k - $202k

    PwC is seeking a Senior Associate in Cybersecurity & Privacy in Seattle. The role involves...  ...in cybersecurity or technology risk management. The position offers a salary...  ..., and more. Join PwC to impact regulatory compliance and risk management. #J-18808-Ljbffr PwC
    Senior

    PwC

    Seattle, WA
    3 days ago
  • $77k - $202k

     ...time Travel Requirements: Up to 60% At PwC, our people in risk and compliance focus on maintaining regulatory compliance and managing risks...  ...programs using industry frameworks and methodologies. As a Senior Associate you are expected to analyze complex problems, mentor... 
    Senior
    Full time

    PwC

    Seattle, WA
    4 days ago
  • $88k - $124k

     ...IG Compliance & Security Analyst Cooley is seeking an IG Compliance...  ...join the Information Governance & Data Privacy team....  ...requests. This role tracks risks, monitors adherence...  ..., and working in the GRC platform Conduct...  ...for consideration of Senior designation with 5+ years... 
    Full time
    Contract work
    Temporary work
    Work experience placement
    Work at office
    Flexible hours
    Weekend work

    Cooley

    Seattle, WA
    1 day ago
  • $153.6k - $192k

    Brex is seeking a Senior GRC Engineer in Seattle to drive critical Governance, Risk, and Compliance processes. This role involves automating security controls and building integrations to maintain compliance as Brex expands. Candidates should have over 5 years of experience... 
    Senior

    Brex

    Seattle, WA
    4 days ago
  • $88k - $124k

    IG Compliance & Security Analyst Cooley is seeking an IG Compliance & Security...  ...join the Information Governance & Data Privacy team....  .../support periodic risk assessments and...  ...risk and compliance (GRC) processes, solutions...  ...for consideration of Senior designation with 5+ years... 
    Full time
    Temporary work
    Work experience placement
    Flexible hours
    Weekend work

    Cooley LLP

    Seattle, WA
    19 hours ago
  • $88k - $124k

    Cooley LLP is seeking an IG Compliance & Security Analyst to join their Information Governance & Data Privacy team. The ideal candidate will conduct audits to ensure...  ...initiatives. They should have a background in governance, risk and compliance as well as experience with ISO 270... 

    Cooley LLP

    Seattle, WA
    19 hours ago
  •  ...GRC Business Analyst Lululemon is a yoga-inspired technical apparel company up to big things....  ...implementation of the ServiceNow Integrated Risk Management (IRM) modules. This is a...  ...of GRC processes including policy and compliance, and risk management. This role will... 

    Samprasoft

    Seattle, WA
    2 days ago
  •  ...DescriptionJob Description About the Role: Join CFM Partners GRC, Inc. as a Regulatory Compliance Specialist - Content & Product. In this dynamic role...  ...Partners GRC, Inc. helps organizations strengthen governance, manage risk, and build a lasting culture of compliance. Based in... 

    Energy Jobline ZR

    Seattle, WA
    2 days ago
  • $148.7k - $201.2k

     ...team at the forefront of global compliance innovation, where you'll...  ...compliance-orchestrating real-time risk detection to catch...  ...patterns, and creating adaptive governance frameworks that stay ahead of...  ...businesses and reporting to senior leadership Amazon is an equal... 
    Senior
    Flexible hours

    Amazon

    Seattle, WA
    3 days ago
  • KellyMitchell Group is seeking a Senior Analyst in Third Party Risk Management. This remote position involves assessing and managing third-party risk through enhancement of Vendor Risk Management practices, supporting security assessments, and improving processes. Ideal... 
    Senior
    Remote job

    KellyMitchell Group

    Bellevue, WA
    4 days ago
  • $119k - $193k

     ...Forrester is currently looking for a Senior Analyst to conduct research and deliver strategic advice for risk management leaders and their teams...  ...business strategy. Expertise in compliance management, internal or external audit, and GRC platforms is strongly desired.... 
    Senior
    For contractors

    Forrester

    Seattle, WA
    1 day ago
  • An international consulting firm seeks a Senior Consultant for Risk Technology in Seattle. This role involves designing and implementing risk management solutions using ServiceNow IRM and leading cross-disciplinary projects. Ideal candidates have a relevant educational... 
    Senior

    Ernst & Young Oman

    Seattle, WA
    2 days ago
  • Travelers Canada in Washington is hiring a Risk Control consultant responsible for maintaining a consistent field presence, consulting clients on risk strategies, and analyzing loss trends. Candidates should possess a bachelor's degree and 7+ years in safety or risk management... 
    Senior

    Travelers Canada

    Seattle, WA
    2 days ago
  • $90.4k - $168.2k

     ...as passionate about your future as we are, join our team. KPMG is currently seeking a Sr. Associate, Security Governance, Risk and Compliance (Audit) to join our Enterprise Security Services organization. This is a remote work opportunity team. Responsibilities... 
    Senior
    H1b
    Local area
    Remote work

    KPMG

    Seattle, WA
    4 days ago
  • $121.2k - $163.9k

     ...Join our global advertising measurement compliance program that ensures Amazon's advertising...  ...people. The Internal Audit team is seeking a Senior Manager to support the Media Rating...  ...compliance program deliverables and supporting risk assessments to prioritize the program... 
    Senior
    Work at office
    Worldwide
    Flexible hours

    Amazon

    Seattle, WA
    5 days ago
  • $87.8k - $160.9k

    Broughton Group in Seattle, United States, seeks an IT Auditor to lead client engagements and conduct risk assessments. Candidates should possess a bachelor’s or master’s degree, with at least 2 years of experience in IT auditing or risk advisory roles. This position offers... 
    Senior
    Flexible hours

    Broughton Group

    Seattle, WA
    2 days ago
  • $156.4k - $211.6k

     ...growth. Find your future with us. Boeing is looking for a Senior Compliance Analyst to join our dynamic team. The ideal candidate will have...  ..., and analyze disparate information to identify compliance risks and communicate findings in a concise, actionable manner for... 
    Senior
    Permanent employment
    Work experience placement
    Relocation
    Visa sponsorship
    Work visa
    Relocation package
    Flexible hours
    Shift work
    Day shift

    The Boeing Company

    Seattle, WA
    9 days ago
  •  ...Earned Value Compliance Analysts (Experienced and Senior) The Boeing Company is hiring Experienced and Senior Earned Value Compliance Analysts (Level...  ...senior leaders and get everyone on the same page about risks, opportunities, and necessary changes Position Responsibilities... 
    Senior
    Contract work
    Work experience placement
    Remote work
    Relocation package
    Flexible hours

    Boeing

    Seattle, WA
    19 hours ago
  • $117.1k - $165k

     ...please see The Manager, AI Governance & Policy defines and enforces...  ...actionable policies, monitor compliance across use cases, and serve as...  ...questions from the business Risk, Incident & Audit Management...  ...Policy management platforms, GRC tools (ServiceNow GRC, Archer... 
    Live in
    Local area
    Worldwide

    Cengage Group

    Seattle, WA
    2 days ago
  • A global consulting firm in Seattle is seeking a Senior Risk Consultant to perform IT audits and provide specialized services to clients...  ...experience, including knowledge of internal controls and compliance regulations. This full-time position offers a competitive salary... 
    Senior
    Full time
    Flexible hours

    Ernst & Young Oman

    Seattle, WA
    2 days ago
  • $87.8k - $160.9k

     ...exceptional experience for yourself, and a better working world for all. The opportunity   The objective of our consulting risk services is to provide clients with a candid and reliable overview of their risk landscape.  Our solutions can be used by our clients... 
    Senior
    Contract work
    Summer holiday
    Work at office
    Flexible hours

    EY

    Seattle, WA
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Governance, Risk, Compliance (GRC) Analyst. Be the first to apply!