Senior Governance, Risk, Compliance (GRC) Analyst
$161.6k - $202kHeadway - Design & Development
Headway's Mission
One in four people in the US have a treatable mental health condition, but most providers don't accept insurance, making therapy too expensive for most people. Headway's mission is to fix this by building a new mental healthcare system everyone can access. We started by solving the biggest barrier to care: insurance. The admin work - credentialing, claims, payment reconciliation - is a nightmare. We've automated that.
But we're going further. Over 75,000 providers across all 50 states run their practice on our software, serving over 1 million patients. We are building the best tools for therapists to run their entire practice, reimagining the experience of finding a therapist, and investing in the platform foundations to enable this at scale. We aren't just a billing layer; we are becoming the platform where care actually happens.
We're a Series D company with $325M+ in funding (a16z, Accel, Spark Capital, etc.), looking for exceptional people to help us achieve this mission. We want your time here to be the most meaningful experience of your career. Join us, and help change mental healthcare for the better.
About the Role
Headway handles sensitive health data for millions of patients — and that responsibility demands a security and compliance program that scales with the business. We're building out our dedicated GRC team to improve and mature our program!
You'll join the Security team and work across four pillars: security certifications (HITRUST, SOC 2, PCI-DSS, HIPAA), third-party risk management, security awareness training, and technical risk management. You won't be maintaining a stale compliance program — you'll be building a modern, AI-enabled one at a company that's transforming how mental healthcare is delivered in the United States.
This role reports to Blake Atkinson, Director of Security, and partners closely with Privacy and Engineering teams.
What You'll Own
Support HITRUST, SOC 2, PCI-DSS, and HIPAA audit readiness — collecting evidence, coordinating with assessors, tracking control gaps and remediation timelines.
Build and manage the vendor security assessment lifecycle — questionnaires, SOC 2/ISO reviews, risk scoring, and policy enforcement across procurement and renewals.
Stand up and run Headway's security awareness training program — onboarding modules, phishing simulations, annual compliance training, and completion tracking.
Operate the centralized risk register — identifying, assessing, and tracking technical security risks through mitigation, and surfacing risk-informed priorities to engineering and security leadership.
Partner cross-functionally with Privacy, Legal, IT, and Engineering to embed compliance into how Headway operates — not bolt it on after the fact.
You'd Be a Great Fit If…
You have 5+ years of experience in a GRC, compliance, or security risk role.
You have working knowledge of at least two of: HITRUST, SOC 2, PCI-DSS, or HIPAA.
You've used a GRC platform like Vanta, Drata, OneTrust, or similar to automate evidence collection or manage controls.
You communicate compliance requirements clearly to both technical and non-technical audiences.
You default to building repeatable processes over one-off heroics.
You're excited about using AI and modern tooling to scale compliance operations.
Bonus: you've worked in healthcare or healthtech and understand what HIPAA means in practice, not just in theory.
Why Headway
Mission That Matters — your work directly protects millions of patients accessing mental healthcare.
Real Risk Mitigation — this isn't checkbox compliance; the data you're protecting and the programs you're building have direct, tangible impact.
Forward-thinking Healthtech — Headway is investing in AI-enabled security workflows and modern GRC tooling, not spreadsheet-driven compliance.
Build From Scratch — you're standing up Headway's GRC function, not inheriting legacy processes.
Compensation and Benefits:
The expected base pay range for this position is $161,600 to 202,000 based on a variety of factors including qualifications, experience, and geographic location. In addition to base salary, this role may be eligible for an equity grant, depending on the position and level.
We are committed to offering a comprehensive and competitive total rewards package, including robust health and wellness benefits, retirement savings, and meaningful ownership opportunities through equity. Compensation decisions are made holistically, ensuring fairness and alignment with market benchmarks while recognizing individual contributions and potential.
Benefits offered include:
Equity compensation
Medical, Dental, and Vision coverage
HSA / FSA
401K
Work-from-Home Stipend
Therapy Reimbursement
16-week parental leave for eligible employees
Carrot Fertility annual reimbursement and membership
13 paid holidays each year as well as a Holiday Break during the week between December 25th and December 31st
Flexible PTO
Employee Assistance Program (EAP)
Training and professional development
Headway is committed to the full inclusion of all qualified individuals. As part of this commitment, Headway will ensure that persons with disabilities are provided with reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or receive other benefits and privileges of employment, please inform the recruiter when they contact you to schedule your interview.
Headway participates in E-Verify. To learn more, click here.
A notice to Headway applicants: To protect yourself against phishing and recruitment fraud, please note that Headway only accepts applications through our official careers page at . Headway will never refer you to external websites, ask for payment or personal information, or conduct interviews via messaging apps. All official communication will come from a @findheadway.com email address. If you are contacted by someone claiming to be from Headway via an unofficial channel, please do not share any information and report it as spam.
- Senior Governance, Risk, Compliance (GRC) Analyst job at Oura. New York, NY. At Oura, our mission is to empower every person to own their inner potential. With our award-winning Oura Ring and app, we help over 2.5 million people turn insights about sleep, activity, and...SeniorWork at officeLocal areaRemote workFlexible hours
- ...Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We're looking for experienced GRC professionals to help evaluate and improve AI systems being trained on real-world security, compliance, and risk scenarios. Your practitioner knowledge will...SuggestedHourly payOngoing contractContract workFreelanceRemote workFlexible hours
- ...Oura is seeking a Senior Governance, Risk, Compliance (GRC) Analyst to join the Security Team in New York City. This role involves leading GRC initiatives, managing compliance policies, and performing risk assessments. Candidates should have over 6 years of experience...SeniorRemote workFlexible hours
- Governance, Risk & Compliance (GRC) Analyst (AI Training) About The Role We partner with the world's leading AI research teams and labs to build and train cutting-edge AI models. Right now, we're looking for experienced GRC professionals to help us shape how AI reasons...SuggestedHourly payOngoing contractContract workFreelanceRemote workFlexible hours
- Summary Prestige Staffing is seeking a highly motivated GRC Analyst to support governance, risk, and compliance activities within a Microsoft-centric environment. The successful candidate will play a pivotal role in maintaining NIST-aligned security frameworks, controls...SuggestedHourly payContract work3 days per week
- Responsibilities Manage and support our compliance certifications, including SOC 2,... ...Privacy trust center Maintain the risk register and drive risk identification... ...Report on our compliance posture to senior leadership Scale our GRC function with AI and automation,...Senior
- Senior GRC Analyst job at Quantexa. New York, NY. What we’re all about. We find,... ...demonstrable experience in both US Government and non-government security and compliance, applying deep knowledge... ...the maturity of our Governance, Risk, and Compliance (GRC) function....SeniorContract workTemporary workWork experience placementImmediate start
$132.6k - $195k
...marketplace of consumers, merchants, and drivers.About the RoleThe Global Governance, Risk, and Compliance (GRC) team is looking for a technical, security-focused Third-Party Risk Management (TPRM) Sr. Analyst. If you are comfortable and have experience working in a fast-paced...SeniorHourly payContract workWork at officeLocal areaRemote workFlexible hours$100k - $125k
...Risk And Compliance Analyst The Risk And Compliance Analyst will play a key role in supporting and executing the Firm's governance, risk and compliance (GRC) program. Reporting to the Compliance Manager, this role will independently manage components of the Firm's risk...- ...leading utility provider in Pennsylvania seeks a GRC Cybersecurity Senior Analyst to ensure compliance with regulatory obligations. This role involves collaboration... ...with various departments to implement governance and risk management processes. The ideal candidate has a...Senior
$95k - $115k
...diverse businesses. Job Description Brookfield's Data Governance Program was established to create a high-quality, trusted... ...investments, properties, underwriting metrics, and capital pools. The Senior Analyst will play a critical role in supporting this program by...SeniorTemporary workWork at officeLocal area- ...Senior Business Analyst – Data Sharing Contracts Ascension Technologies is seeking a detail‑oriented and technically... .... You will collaborate with legal, compliance, IT, and data governance teams to ensure contract visibility, risk management, and regulatory compliance—...SeniorContract workRemote work
$90k - $200k
...Kroll’s North American Investigations, Diligence and Compliance practice is seeking a Senior Manager based in the U.S. This is a wide-ranging role in the... ...intelligence, internal (client) investigations, insider risk compliance assessments, consulting projects and forensic...SeniorTemporary workFlexible hours$175k
Reference: 13578Senior Compliance Officer, Investec USAInvestec - Where... ....Act as a trusted advisor to senior stakeholders, delivering... ...prioritise regulatory and compliance risks across covered business lines... ..., ensuring appropriate governance and documentation.Deliver management...SeniorFull timeWork at officeRemote work$104k - $177k
We’re seeking a future team member for the role of Senior Vice President, Consumer Compliance Officer - Global Payments & Trade. to join our Risk & Compliance team. This role is located in Pittsburgh, PA or Lake Mary, FL In this role, you’ll make an impact in the following...SeniorTemporary workWorldwideFlexible hours- ...Advisory compliance — primary owner, all regions Real-time trading guidance across all asset... ...out a comprehensive algo trading governance framework covering the full lifecycle —... ...compliance in cross-functional discussions with risk, development, and front office...Senior
$77k - $202k
...ApplicableSpecialismCybersecurity & PrivacyManagement LevelSenior AssociateJob Description & SummaryThe OpportunityAs a Security Risk & Engineering - Tech and Cyber Risk & Compliance - Senior Associate, you will focus on maintaining regulatory compliance and managing risks for clients,...SeniorFull timeH1b- ...A leading consulting firm seeks a Governance, Risk, and Compliance (GRC) leader to advance their programs. This remote role requires 5–7 years of experience in GRC with relevant certifications like CISSP or CISM. The successful candidate will lead policy development, perform...SeniorRemote work
$119k - $218.3k
Position Summary Senior Consultant - Risk, Regulatory, & Licensing - Digital Assets Regulatory & Financial Risk Ready for a fast-paced... ...developments to provide clients with up-to-date perspectives on compliance obligations and industry best practices.Collaborate with...SeniorWork at office- ...Senior GRC Consultant E*Pro Consulting service offerings include contingent Staff Augmentation of IT professionals, Permanent... .../ Full Time Description: At least 8+ years of governance, risk and compliance experience, - Experience should be hands on such that...SeniorPermanent employmentFull timeTemporary workFor contractors
$160k - $212k
.... FEC Counsel Our fast-paced FEC Governance Team (part of the wider AML Compliance Team) is looking for a FEC Counsel... ...conducting the enterprise‑wide integrity risk assessment across the Adyen Group.... ...collaborating across levels of seniority, cultures, and backgrounds; and,...SeniorFull timeRelocation$125k - $175k
Purpose of Role Marex is recruiting a Surveillance Compliance Officer to join the team at our New York office. The role focuses on Trade... ...CFTC and other applicable exchanges. Adhere to the operational risk framework and company policies, model highest standards of integrity...SeniorWork at office$10k
We’re seeking a Senior Regulatory Compliance Specialist for a 6‑month temporary assignment to lead high‑impact regulatory projects in connection with... ..., defensible, regulator‑ready written materials—including risk assessments, compliance narratives, and formal responses to...SeniorTemporary work$85k - $110k
...AI And Technology Risk Governance Specialist Execute day-to-day operations of AI and Technology... ...AI / Technology teams Risk and Compliance teams Qualifications: ~3+ years... ...~ Experience with TPRM and GRC tools (like Archer, ServiceNow, OneTrust...Temporary workWork at officeRemote workHome officeFlexible hours$125k - $175k
...visit Purpose of Role: Marex is recruiting for a Surveillance Compliance officer to join the team our at our New York office. The role... ...and implement policies and procedures to minimize non-compliance risks. Compliance efforts are instrumental in fostering a compliant...SeniorWork at officeImmediate start- ...JPMorgan Chase and play a pivotal role in Risk Management and Compliance, ensuring the firm's strength and... ...the management of model risk, governance activities are conducted to identify... ...confirmations, CCAR etc. Engage with senior leaders, development and model review...Senior
- Build the career you want and make a powerful impact.NursingAs a professional and skilled home care nurse with VNS Health, you will flourish in an environment which encourages growth and provides opportunities to advance your nursing career. While using your expertise to...SeniorLive in3 days per week
$192k - $279k
Identify emerging trends, risks, and opportunities in privacy, data governance, and compliance, translating them into actionable product strategies and requirements.... ...technical details to various audiences, including senior executives (e.g., VPs), effectively gaining buy-...Senior$134k - $202k
...our community, or shaping our story, you’ll help define what comes next. About the role: We are looking for a GRC Analyst to join our Governance, Risk & Compliance (GRC) team. You will have the opportunity to manage and maintain ongoing compliance with security and...Work at officeRemote workWorldwideMonday to Friday- Alignerr is seeking a GRC Analyst for AI training. The role focuses on reviewing security policies, controls, and procedures, and assessing compliance across SOC 2, ISO 27001, NIST, and related standards. You will generate training data to teach AI systems GRC reasoning...Remote job
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Governance, Risk, Compliance (GRC) Analyst. Be the first to apply!
- quantitative risk analyst New York, NY
- risk analyst New York, NY
- risk officer New York, NY
- it risk analyst New York, NY
- senior quantitative risk analyst New York, NY
- third party risk analyst New York, NY
- operational risk specialist New York, NY
- governance risk & compliance analyst New York, NY
- risk consultant New York, NY
- operational risk consultant New York, NY

