Senior Governance, Risk, Compliance (GRC) Analyst
$161.6k - $202kHeadway - Design & Development
Headway's Mission
One in four people in the US have a treatable mental health condition, but most providers don't accept insurance, making therapy too expensive for most people. Headway's mission is to fix this by building a new mental healthcare system everyone can access. We started by solving the biggest barrier to care: insurance. The admin work - credentialing, claims, payment reconciliation - is a nightmare. We've automated that.
But we're going further. Over 75,000 providers across all 50 states run their practice on our software, serving over 1 million patients. We are building the best tools for therapists to run their entire practice, reimagining the experience of finding a therapist, and investing in the platform foundations to enable this at scale. We aren't just a billing layer; we are becoming the platform where care actually happens.
We're a Series D company with $325M+ in funding (a16z, Accel, Spark Capital, etc.), looking for exceptional people to help us achieve this mission. We want your time here to be the most meaningful experience of your career. Join us, and help change mental healthcare for the better.
About the Role
Headway handles sensitive health data for millions of patients — and that responsibility demands a security and compliance program that scales with the business. We're building out our dedicated GRC team to improve and mature our program!
You'll join the Security team and work across four pillars: security certifications (HITRUST, SOC 2, PCI-DSS, HIPAA), third-party risk management, security awareness training, and technical risk management. You won't be maintaining a stale compliance program — you'll be building a modern, AI-enabled one at a company that's transforming how mental healthcare is delivered in the United States.
This role reports to Blake Atkinson, Director of Security, and partners closely with Privacy and Engineering teams.
What You'll Own
Support HITRUST, SOC 2, PCI-DSS, and HIPAA audit readiness — collecting evidence, coordinating with assessors, tracking control gaps and remediation timelines.
Build and manage the vendor security assessment lifecycle — questionnaires, SOC 2/ISO reviews, risk scoring, and policy enforcement across procurement and renewals.
Stand up and run Headway's security awareness training program — onboarding modules, phishing simulations, annual compliance training, and completion tracking.
Operate the centralized risk register — identifying, assessing, and tracking technical security risks through mitigation, and surfacing risk-informed priorities to engineering and security leadership.
Partner cross-functionally with Privacy, Legal, IT, and Engineering to embed compliance into how Headway operates — not bolt it on after the fact.
You'd Be a Great Fit If…
You have 5+ years of experience in a GRC, compliance, or security risk role.
You have working knowledge of at least two of: HITRUST, SOC 2, PCI-DSS, or HIPAA.
You've used a GRC platform like Vanta, Drata, OneTrust, or similar to automate evidence collection or manage controls.
You communicate compliance requirements clearly to both technical and non-technical audiences.
You default to building repeatable processes over one-off heroics.
You're excited about using AI and modern tooling to scale compliance operations.
Bonus: you've worked in healthcare or healthtech and understand what HIPAA means in practice, not just in theory.
Why Headway
Mission That Matters — your work directly protects millions of patients accessing mental healthcare.
Real Risk Mitigation — this isn't checkbox compliance; the data you're protecting and the programs you're building have direct, tangible impact.
Forward-thinking Healthtech — Headway is investing in AI-enabled security workflows and modern GRC tooling, not spreadsheet-driven compliance.
Build From Scratch — you're standing up Headway's GRC function, not inheriting legacy processes.
Compensation and Benefits:
The expected base pay range for this position is $161,600 to 202,000 based on a variety of factors including qualifications, experience, and geographic location. In addition to base salary, this role may be eligible for an equity grant, depending on the position and level.
We are committed to offering a comprehensive and competitive total rewards package, including robust health and wellness benefits, retirement savings, and meaningful ownership opportunities through equity. Compensation decisions are made holistically, ensuring fairness and alignment with market benchmarks while recognizing individual contributions and potential.
Benefits offered include:
Equity compensation
Medical, Dental, and Vision coverage
HSA / FSA
401K
Work-from-Home Stipend
Therapy Reimbursement
16-week parental leave for eligible employees
Carrot Fertility annual reimbursement and membership
13 paid holidays each year as well as a Holiday Break during the week between December 25th and December 31st
Flexible PTO
Employee Assistance Program (EAP)
Training and professional development
Headway is committed to the full inclusion of all qualified individuals. As part of this commitment, Headway will ensure that persons with disabilities are provided with reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or receive other benefits and privileges of employment, please inform the recruiter when they contact you to schedule your interview.
Headway participates in E-Verify. To learn more, click here.
A notice to Headway applicants: To protect yourself against phishing and recruitment fraud, please note that Headway only accepts applications through our official careers page at . Headway will never refer you to external websites, ask for payment or personal information, or conduct interviews via messaging apps. All official communication will come from a @findheadway.com email address. If you are contacted by someone claiming to be from Headway via an unofficial channel, please do not share any information and report it as spam.
$135k - $165k
...foundational to our platform and customer relationships. As we continue to scale, we are looking for a highly motivated Governance, Risk & Compliance (GRC) Analyst to support and mature Ivo's security compliance and risk management programs. Why Ivo? Every civilization runs on...SuggestedContract workFlexible hours$125k - $200k
...GRC Role at Simile Simile is changing the way consequential decisions... ...secure and compliant. You will connect governance, risk management, and compliance to protect our organization and our... ...& Audits: Act as a Customer Trust Analyst to address security-related...SuggestedFlexible hours$130k - $150k
...Crusoe. About This Role We're seeking a GRC Analyst to support the day-to-day execution of our Governance, Risk, and Compliance program. Reporting to the Head of GRC, this... ...due diligence requests with guidance from senior team members Maintaining and updating...SeniorTemporary work- Simile in San Francisco is seeking a Governance, Risk, and Compliance (GRC) Analyst to ensure the integrity of our AI systems. The role revolves around developing security policies, managing compliance, and fostering a culture of security awareness across the company....Suggested
- ...Associate GRC Analyst The Associate GRC Analyst willsupport our Governance, Risk, and Compliance program. This role iswell-suitedfor anearly careerprofessional looking to gainhands... ...Analyst will work closely with senior GRC, security, legal, and IT stakeholders to...SuggestedInternship
$150k
Crusoe Energy Systems LLC is looking for a GRC Analyst in San Francisco, CA to support their Governance, Risk, and Compliance program. The role includes managing user access reviews, supporting audits, and leveraging AI tools for process improvements. Ideal candidates...Senior$193.8k - $228k
Senior GRC Analyst II job at Carta. San Francisco, CA. The Problems You'll Solve As a Senior GRC Analyst II... ...and accordingly establish and maintain governance and risk frameworks. You will build and run security compliance programs to measure and reduce risk, report...SeniorFull time- ...managing evidence collection, conducting risk assessments, maintaining policies and... ...3-5 years of experience in Governance, Risk & Compliance (GRC), Information Security, IT Audit, or... ...a detail-oriented and proactive GRC Analyst to support the company's compliance,...
- Ivo is looking for a proactive GRC Analyst to enhance its compliance programs including SOC 2 Type II and ISO 27001. The role demands a detail-oriented... ...responsible for managing compliance initiatives and risk assessments while ensuring close collaboration with teams...
- Ivo Inc. is seeking a GRC Analyst to support compliance and risk management initiatives in their San Francisco office. This is a crucial role designed... ...successful candidate will have 3-5 years of experience in Governance, Risk & Compliance, and be skilled in audits and...Work at office
- ...Senior Vice President, Legal and Chief Compliance Officer (CCO) About the Company Nationally recognized healthcare services organization Industry Hospital... ...that directly impacts organizational strategy, governance, and risk posture. The successful candidate will be a...Senior
- DocuSign, Inc. is seeking a Senior Director, Security Governance, Risk, and Compliance (GRC) to lead their global GRC team. This role requires over 15 years of experience in security leadership, focusing on innovative risk management strategies. The ideal candidate will...Senior
$70 - $80 per hour
...Title: GRC Analyst Location: San Francisco, CA (4 days onsite) Duration: 6+ months Key Responsibilities: • Conduct technical vendor risk assessments (security, privacy, architecture, data handling) for new and existing third parties • Review security...Hourly payFull timeLocal area$65 - $85 per hour
...Senior GRC Analyst - Security & Compliance LHH Recruitment Solutions is partnering with a high-growth, cloud-native SaaS organization to identify... ...a unique opportunity to take ownership of a growing governance, risk, and compliance program within an innovative...Hourly payContract workTemporary workWork at officeLocal area- Iris Energy is seeking a Regulatory Compliance Manager to oversee compliance frameworks, manage regulatory obligations, and partner with... ...stakeholders. Candidates must possess over 10 years of experience in risk and compliance roles, preferably within large environments. The...Senior
- Ivo is looking for a detail-oriented Governance, Risk & Compliance (GRC) Analyst in San Francisco. The ideal candidate will support compliance programs such as SOC 2 Type II and ISO 27001 while managing audits and risk assessments. This onsite role offers a competitive...
$135k - $165k
Icehouseventures is seeking a proactive GRC Analyst to join our team in San Francisco. This role will support compliance and risk management initiatives essential for maintaining high security standards. The ideal candidate will have 3-5 years of experience in GRC and relevant...Contract work- ...Learning in San Francisco is looking for an Associate GRC Analyst to join our security team. In this role, you will support cybersecurity governance, compliance, and audit functions by gathering evidence, conducting vendor risk assessments, and maintaining documentation. This...
$110k - $120k
...automates and simplifies doing business across borders, reducing risk and eliminating routine operational tasks. Offering global... ...movement for over 25 years.Job DescriptionJob DescriptionThe Senior Compliance Associate contributes Compliance expertise to the Risk and...SeniorContract workWork at officeFlexible hours$100k - $140k
...Affirm is looking for a Compliance Analyst II in San Francisco to enhance its compliance governance program. This role involves reviewing internal compliance processes, investigating consumer complaints, and collaborating with cross-functional teams to ensure adherence...Remote work- ...information security weaknesses or non-compliance with industry standards. Produce... ...ensuring their understanding of associated risks and actions needed to remediate those... ...Ljbffr Create a job alert for this search Senior Risk Analyst • San Francisco, CA, US #J-18808-...SeniorRemote workFlexible hours
- Morrison- is hiring a Senior Conflicts Resolution Analyst for our Conflicts/New Business team, based in San Francisco or New York. The analyst will support our attorneys by resolving conflicts of interest and ensuring high levels of client satisfaction. Candidates should...Senior
$95k - $130k
...LiveRamp is seeking a Security GRC Analyst in San Francisco to support security risk management, compliance, and reporting efforts. You will collaborate closely with various teams to address and mitigate risks while maintaining high compliance standards. The ideal candidate...Remote work$85k - $100k
BDO is looking for a Senior Associate in Risk Advisory Services based in San Francisco, California. In this role, you will provide risk consulting to clients, focusing on compliance, audit processes, and fraud investigations, among other responsibilities. The ideal candidate...Senior$85k - $100k
BDO USA, LLP is seeking a Senior, Risk Advisory Services professional to provide risk consulting to clients in areas such as compliance, internal audit, and fraud investigations. Responsibilities include engaging with clients, performing risk assessments, and supervising...Senior$99.75k - $161k
JPMorgan Chase is seeking a Senior Associate in Asset Wealth Management Credit Risk based in San Francisco, CA, to support high-net-worth lending activities. You'll assess creditworthiness, structure risk-appropriate loan solutions, and manage ongoing portfolio risk. The...Senior- A leading insurance company is seeking a Senior Risk Engineering Consultant to manage large construction accounts and provide expert consultative services. Responsibilities include adapting solutions, conducting loss investigations, and building relationships with clients...SeniorRemote job
- The Hanover Insurance Group is seeking a Senior Risk Solutions Consultant for their Pacific Northwest territory. This full-time role offers remote work with local travel. Responsibilities include conducting field surveys, creating loss analysis, and building relationships...SeniorRemote jobFull timeLocal area
- Ernst & Young Advisory Services Sdn Bhd is seeking a Senior Consultant based in San Francisco to support risk, compliance, and control activities in modern technology ecosystems. This role emphasizes cloud-native architectures and AI-enabled environments. The ideal candidate...SeniorFlexible hours
$137.34k - $207.81k
...mission. Checkr is recognized on Forbes Cloud 100 2025 List and is a Y Combinator 2024 Breakthrough Company. Checkr, Inc. seeks Senior Risk Analyst in San Francisco, CA Job Duties: Manage and mature Checkr's fraud and cybersecurity risk programs. Focus on product fraud...SeniorPart timeWork at officeLocal areaRemote workRelocationFlexible hours3 days per week
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Governance, Risk, Compliance (GRC) Analyst. Be the first to apply!
- governance risk & compliance analyst San Francisco, CA
- senior quantitative risk analyst San Francisco, CA
- risk analyst San Francisco, CA
- it risk analyst San Francisco, CA
- transaction risk analyst San Francisco, CA
- operational risk consultant San Francisco, CA
- risk officer San Francisco, CA
- risk consultant San Francisco, CA
- risk compliance officer San Francisco, CA
- third party risk analyst San Francisco, CA

