Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Governance, Risk, Compliance (GRC) Analyst

$161.6k - $202k

Headway - Design & Development

Headway's Mission

One in four people in the US have a treatable mental health condition, but most providers don't accept insurance, making therapy too expensive for most people. Headway's mission is to fix this by building a new mental healthcare system everyone can access. We started by solving the biggest barrier to care: insurance. The admin work - credentialing, claims, payment reconciliation - is a nightmare. We've automated that.

But we're going further. Over 75,000 providers across all 50 states run their practice on our software, serving over 1 million patients. We are building the best tools for therapists to run their entire practice, reimagining the experience of finding a therapist, and investing in the platform foundations to enable this at scale. We aren't just a billing layer; we are becoming the platform where care actually happens.

We're a Series D company with $325M+ in funding (a16z, Accel, Spark Capital, etc.), looking for exceptional people to help us achieve this mission. We want your time here to be the most meaningful experience of your career. Join us, and help change mental healthcare for the better.

About the Role

Headway handles sensitive health data for millions of patients — and that responsibility demands a security and compliance program that scales with the business. We're building out our dedicated GRC team to improve and mature our program!

You'll join the Security team and work across four pillars: security certifications (HITRUST, SOC 2, PCI-DSS, HIPAA), third-party risk management, security awareness training, and technical risk management. You won't be maintaining a stale compliance program — you'll be building a modern, AI-enabled one at a company that's transforming how mental healthcare is delivered in the United States.

This role reports to Blake Atkinson, Director of Security, and partners closely with Privacy and Engineering teams.

What You'll Own
  • Support HITRUST, SOC 2, PCI-DSS, and HIPAA audit readiness — collecting evidence, coordinating with assessors, tracking control gaps and remediation timelines.

  • Build and manage the vendor security assessment lifecycle — questionnaires, SOC 2/ISO reviews, risk scoring, and policy enforcement across procurement and renewals.

  • Stand up and run Headway's security awareness training program — onboarding modules, phishing simulations, annual compliance training, and completion tracking.

  • Operate the centralized risk register — identifying, assessing, and tracking technical security risks through mitigation, and surfacing risk-informed priorities to engineering and security leadership.

  • Partner cross-functionally with Privacy, Legal, IT, and Engineering to embed compliance into how Headway operates — not bolt it on after the fact.

You'd Be a Great Fit If…
  • You have 5+ years of experience in a GRC, compliance, or security risk role.

  • You have working knowledge of at least two of: HITRUST, SOC 2, PCI-DSS, or HIPAA.

  • You've used a GRC platform like Vanta, Drata, OneTrust, or similar to automate evidence collection or manage controls.

  • You communicate compliance requirements clearly to both technical and non-technical audiences.

  • You default to building repeatable processes over one-off heroics.

  • You're excited about using AI and modern tooling to scale compliance operations.

  • Bonus: you've worked in healthcare or healthtech and understand what HIPAA means in practice, not just in theory.

Why Headway
  • Mission That Matters — your work directly protects millions of patients accessing mental healthcare.

  • Real Risk Mitigation — this isn't checkbox compliance; the data you're protecting and the programs you're building have direct, tangible impact.

  • Forward-thinking Healthtech — Headway is investing in AI-enabled security workflows and modern GRC tooling, not spreadsheet-driven compliance.

  • Build From Scratch — you're standing up Headway's GRC function, not inheriting legacy processes.

Compensation and Benefits:

The expected base pay range for this position is $161,600 to 202,000 based on a variety of factors including qualifications, experience, and geographic location. In addition to base salary, this role may be eligible for an equity grant, depending on the position and level.

We are committed to offering a comprehensive and competitive total rewards package, including robust health and wellness benefits, retirement savings, and meaningful ownership opportunities through equity. Compensation decisions are made holistically, ensuring fairness and alignment with market benchmarks while recognizing individual contributions and potential.

  • Benefits offered include:

    • Equity compensation

    • Medical, Dental, and Vision coverage

    • HSA / FSA

    • 401K

    • Work-from-Home Stipend

    • Therapy Reimbursement

    • 16-week parental leave for eligible employees

    • Carrot Fertility annual reimbursement and membership

    • 13 paid holidays each year as well as a Holiday Break during the week between December 25th and December 31st

    • Flexible PTO

    • Employee Assistance Program (EAP)

    • Training and professional development

Headway is committed to the full inclusion of all qualified individuals. As part of this commitment, Headway will ensure that persons with disabilities are provided with reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or receive other benefits and privileges of employment, please inform the recruiter when they contact you to schedule your interview.

Headway participates in E-Verify. To learn more, click here.

A notice to Headway applicants: To protect yourself against phishing and recruitment fraud, please note that Headway only accepts applications through our official careers page at . Headway will never refer you to external websites, ask for payment or personal information, or conduct interviews via messaging apps. All official communication will come from a @findheadway.com email address. If you are contacted by someone claiming to be from Headway via an unofficial channel, please do not share any information and report it as spam.

Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Senior Governance, Risk, Compliance (GRC) Analyst in San Francisco, CA vacancy
  • $135k - $165k

     ...foundational to our platform and customer relationships. As we continue to scale, we are looking for a highly motivated Governance, Risk & Compliance (GRC) Analyst to support and mature Ivo's security compliance and risk management programs. Why Ivo? Every civilization runs on... 
    Suggested
    Contract work
    Flexible hours

    IVO Inc

    San Francisco, CA
    4 days ago
  • $125k - $200k

     ...GRC Role at Simile Simile is changing the way consequential decisions...  ...secure and compliant. You will connect governance, risk management, and compliance to protect our organization and our...  ...& Audits: Act as a Customer Trust Analyst to address security-related... 
    Suggested
    Flexible hours

    Simile

    San Francisco, CA
    2 days ago
  • $130k - $150k

     ...Crusoe. About This Role We're seeking a GRC Analyst to support the day-to-day execution of our Governance, Risk, and Compliance program. Reporting to the Head of GRC, this...  ...due diligence requests with guidance from senior team members Maintaining and updating... 
    Senior
    Temporary work

    Crusoe

    San Francisco, CA
    2 days ago
  • Simile in San Francisco is seeking a Governance, Risk, and Compliance (GRC) Analyst to ensure the integrity of our AI systems. The role revolves around developing security policies, managing compliance, and fostering a culture of security awareness across the company.... 
    Suggested

    Simile

    San Francisco, CA
    4 days ago
  •  ...Associate GRC Analyst The Associate GRC Analyst willsupport our Governance, Risk, and Compliance program. This role iswell-suitedfor anearly careerprofessional looking to gainhands...  ...Analyst will work closely with senior GRC, security, legal, and IT stakeholders to... 
    Suggested
    Internship

    Dormont Manufacturing Company

    San Francisco, CA
    5 days ago
  • $150k

    Crusoe Energy Systems LLC is looking for a GRC Analyst in San Francisco, CA to support their Governance, Risk, and Compliance program. The role includes managing user access reviews, supporting audits, and leveraging AI tools for process improvements. Ideal candidates... 
    Senior

    Crusoe Energy Systems LLC

    San Francisco, CA
    1 day ago
  • $193.8k - $228k

    Senior GRC Analyst II job at Carta. San Francisco, CA. The Problems You'll Solve As a Senior GRC Analyst II...  ...and accordingly establish and maintain governance and risk frameworks. You will build and run security compliance programs to measure and reduce risk, report... 
    Senior
    Full time

    Itlearn360

    San Francisco, CA
    3 days ago
  •  ...managing evidence collection, conducting risk assessments, maintaining policies and...  ...3-5 years of experience in Governance, Risk & Compliance (GRC), Information Security, IT Audit, or...  ...a detail-oriented and proactive GRC Analyst to support the company's compliance,... 

    Ivo

    San Francisco, CA
    5 days ago
  • Ivo is looking for a proactive GRC Analyst to enhance its compliance programs including SOC 2 Type II and ISO 27001. The role demands a detail-oriented...  ...responsible for managing compliance initiatives and risk assessments while ensuring close collaboration with teams... 

    Ivo

    San Francisco, CA
    4 days ago
  • Ivo Inc. is seeking a GRC Analyst to support compliance and risk management initiatives in their San Francisco office. This is a crucial role designed...  ...successful candidate will have 3-5 years of experience in Governance, Risk & Compliance, and be skilled in audits and... 
    Work at office

    Ivo Inc.

    San Francisco, CA
    4 days ago
  •  ...Senior Vice President, Legal and Chief Compliance Officer (CCO) About the Company Nationally recognized healthcare services organization Industry Hospital...  ...that directly impacts organizational strategy, governance, and risk posture. The successful candidate will be a... 
    Senior

    Confidential

    San Francisco, CA
    5 days ago
  • DocuSign, Inc. is seeking a Senior Director, Security Governance, Risk, and Compliance (GRC) to lead their global GRC team. This role requires over 15 years of experience in security leadership, focusing on innovative risk management strategies. The ideal candidate will... 
    Senior

    DocuSign, Inc.

    San Francisco, CA
    4 days ago
  • $70 - $80 per hour

     ...Title: GRC Analyst Location: San Francisco, CA (4 days onsite) Duration: 6+ months Key Responsibilities: • Conduct technical vendor risk assessments (security, privacy, architecture, data handling) for new and existing third parties • Review security... 
    Hourly pay
    Full time
    Local area

    Winmax Systems

    San Francisco, CA
    3 days ago
  • $65 - $85 per hour

     ...Senior GRC Analyst - Security & Compliance LHH Recruitment Solutions is partnering with a high-growth, cloud-native SaaS organization to identify...  ...a unique opportunity to take ownership of a growing governance, risk, and compliance program within an innovative... 
    Hourly pay
    Contract work
    Temporary work
    Work at office
    Local area

    LHH Recruitment Solutions

    San Francisco, CA
    1 day ago
  • Iris Energy is seeking a Regulatory Compliance Manager to oversee compliance frameworks, manage regulatory obligations, and partner with...  ...stakeholders. Candidates must possess over 10 years of experience in risk and compliance roles, preferably within large environments. The... 
    Senior

    Iris Energy

    San Francisco, CA
    2 days ago
  • Ivo is looking for a detail-oriented Governance, Risk & Compliance (GRC) Analyst in San Francisco. The ideal candidate will support compliance programs such as SOC 2 Type II and ISO 27001 while managing audits and risk assessments. This onsite role offers a competitive... 

    Ivo

    San Francisco, CA
    5 days ago
  • $135k - $165k

    Icehouseventures is seeking a proactive GRC Analyst to join our team in San Francisco. This role will support compliance and risk management initiatives essential for maintaining high security standards. The ideal candidate will have 3-5 years of experience in GRC and relevant... 
    Contract work

    Icehouseventures

    San Francisco, CA
    1 day ago
  •  ...Learning in San Francisco is looking for an Associate GRC Analyst to join our security team. In this role, you will support cybersecurity governance, compliance, and audit functions by gathering evidence, conducting vendor risk assessments, and maintaining documentation. This... 

    IXL Learning

    San Francisco, CA
    3 days ago
  • $110k - $120k

     ...automates and simplifies doing business across borders, reducing risk and eliminating routine operational tasks. Offering global...  ...movement for over 25 years.Job DescriptionJob DescriptionThe Senior Compliance Associate contributes Compliance expertise to the Risk and... 
    Senior
    Contract work
    Work at office
    Flexible hours

    OFX

    San Francisco, CA
    5 days ago
  • $100k - $140k

     ...Affirm is looking for a Compliance Analyst II in San Francisco to enhance its compliance governance program. This role involves reviewing internal compliance processes, investigating consumer complaints, and collaborating with cross-functional teams to ensure adherence... 
    Remote work

    Affirm

    San Francisco, CA
    1 day ago
  •  ...information security weaknesses or non-compliance with industry standards. Produce...  ...ensuring their understanding of associated risks and actions needed to remediate those...  ...Ljbffr Create a job alert for this search Senior Risk Analyst • San Francisco, CA, US #J-18808-... 
    Senior
    Remote work
    Flexible hours

    Direct Staffing Inc

    San Francisco, CA
    5 hours ago
  • Morrison- is hiring a Senior Conflicts Resolution Analyst for our Conflicts/New Business team, based in San Francisco or New York. The analyst will support our attorneys by resolving conflicts of interest and ensuring high levels of client satisfaction. Candidates should... 
    Senior

    Morrison Inc

    San Francisco, CA
    4 days ago
  • $95k - $130k

     ...LiveRamp is seeking a Security GRC Analyst in San Francisco to support security risk management, compliance, and reporting efforts. You will collaborate closely with various teams to address and mitigate risks while maintaining high compliance standards. The ideal candidate... 
    Remote work

    Itlearn360

    San Francisco, CA
    1 day ago
  • $85k - $100k

    BDO is looking for a Senior Associate in Risk Advisory Services based in San Francisco, California. In this role, you will provide risk consulting to clients, focusing on compliance, audit processes, and fraud investigations, among other responsibilities. The ideal candidate... 
    Senior

    BDO

    San Francisco, CA
    4 days ago
  • $85k - $100k

    BDO USA, LLP is seeking a Senior, Risk Advisory Services professional to provide risk consulting to clients in areas such as compliance, internal audit, and fraud investigations. Responsibilities include engaging with clients, performing risk assessments, and supervising... 
    Senior

    BDO USA, LLP

    San Francisco, CA
    4 days ago
  • $99.75k - $161k

    JPMorgan Chase is seeking a Senior Associate in Asset Wealth Management Credit Risk based in San Francisco, CA, to support high-net-worth lending activities. You'll assess creditworthiness, structure risk-appropriate loan solutions, and manage ongoing portfolio risk. The... 
    Senior

    JPMorgan Chase

    San Francisco, CA
    3 days ago
  • A leading insurance company is seeking a Senior Risk Engineering Consultant to manage large construction accounts and provide expert consultative services. Responsibilities include adapting solutions, conducting loss investigations, and building relationships with clients... 
    Senior
    Remote job

    Zurich Insurance Group

    San Francisco, CA
    5 days ago
  • The Hanover Insurance Group is seeking a Senior Risk Solutions Consultant for their Pacific Northwest territory. This full-time role offers remote work with local travel. Responsibilities include conducting field surveys, creating loss analysis, and building relationships... 
    Senior
    Remote job
    Full time
    Local area

    The Hanover Insurance Group

    San Francisco, CA
    3 days ago
  • Ernst & Young Advisory Services Sdn Bhd is seeking a Senior Consultant based in San Francisco to support risk, compliance, and control activities in modern technology ecosystems. This role emphasizes cloud-native architectures and AI-enabled environments. The ideal candidate... 
    Senior
    Flexible hours

    Ernst & Young Advisory Services Sdn Bhd

    San Francisco, CA
    1 day ago
  • $137.34k - $207.81k

     ...mission. Checkr is recognized on Forbes Cloud 100 2025 List and is a Y Combinator 2024 Breakthrough Company. Checkr, Inc. seeks Senior Risk Analyst in San Francisco, CA Job Duties: Manage and mature Checkr's fraud and cybersecurity risk programs. Focus on product fraud... 
    Senior
    Part time
    Work at office
    Local area
    Remote work
    Relocation
    Flexible hours
    3 days per week

    Checkr

    San Francisco, CA
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Governance, Risk, Compliance (GRC) Analyst. Be the first to apply!