Senior Governance, Risk, Compliance (GRC) Analyst
$161.6k - $202kHeadway
Headway's Mission
One in four people in the US have a treatable mental health condition, but most providers don't accept insurance, making therapy too expensive for most people. Headway's mission is to fix this by building a new mental healthcare system everyone can access. We started by solving the biggest barrier to care: insurance. The admin work - credentialing, claims, payment reconciliation - is a nightmare. We've automated that.
But we're going further. Over 75,000 providers across all 50 states run their practice on our software, serving over 1 million patients. We are building the best tools for therapists to run their entire practice, reimagining the experience of finding a therapist, and investing in the platform foundations to enable this at scale. We aren't just a billing layer; we are becoming the platform where care actually happens.
We're a Series D company with $325M+ in funding (a16z, Accel, Spark Capital, etc.), looking for exceptional people to help us achieve this mission. We want your time here to be the most meaningful experience of your career. Join us, and help change mental healthcare for the better.
About the Role
Headway handles sensitive health data for millions of patients and that responsibility demands a security and compliance program that scales with the business. We're building out our dedicated GRC team to improve and mature our program!
You'll join the Security team and work across four pillars: security certifications (HITRUST, SOC 2, PCI-DSS, HIPAA), third-party risk management, security awareness training, and technical risk management. You won't be maintaining a stale compliance program you'll be building a modern, AI-enabled one at a company that's transforming how mental healthcare is delivered in the United States.
This role reports to Blake Atkinson, Director of Security, and partners closely with Privacy and Engineering teams.
What You'll Own
Support HITRUST, SOC 2, PCI-DSS, and HIPAA audit readiness collecting evidence, coordinating with assessors, tracking control gaps and remediation timelines.
Build and manage the vendor security assessment lifecycle questionnaires, SOC 2/ISO reviews, risk scoring, and policy enforcement across procurement and renewals.
Stand up and run Headway's security awareness training program onboarding modules, phishing simulations, annual compliance training, and completion tracking.
Operate the centralized risk register identifying, assessing, and tracking technical security risks through mitigation, and surfacing risk-informed priorities to engineering and security leadership.
Partner cross-functionally with Privacy, Legal, IT, and Engineering to embed compliance into how Headway operates not bolt it on after the fact.
You'd Be a Great Fit If
You have 5+ years of experience in a GRC, compliance, or security risk role.
You have working knowledge of at least two of: HITRUST, SOC 2, PCI-DSS, or HIPAA.
You've used a GRC platform like Vanta, Drata, OneTrust, or similar to automate evidence collection or manage controls.
You communicate compliance requirements clearly to both technical and non-technical audiences.
You default to building repeatable processes over one-off heroics.
You're excited about using AI and modern tooling to scale compliance operations.
Bonus: you've worked in healthcare or healthtech and understand what HIPAA means in practice, not just in theory.
Why Headway
Mission That Matters your work directly protects millions of patients accessing mental healthcare.
Real Risk Mitigation this isn't checkbox compliance; the data you're protecting and the programs you're building have direct, tangible impact.
Forward-thinking Healthtech Headway is investing in AI-enabled security workflows and modern GRC tooling, not spreadsheet-driven compliance.
Build From Scratch you're standing up Headway's GRC function, not inheriting legacy processes.
Compensation and Benefits:
The expected base pay range for this position is $161,600 to 202,000 based on a variety of factors including qualifications, experience, and geographic location. In addition to base salary, this role may be eligible for an equity grant, depending on the position and level.
We are committed to offering a comprehensive and competitive total rewards package, including robust health and wellness benefits, retirement savings, and meaningful ownership opportunities through equity. Compensation decisions are made holistically, ensuring fairness and alignment with market benchmarks while recognizing individual contributions and potential.
Benefits offered include:
Equity compensation
Medical, Dental, and Vision coverage
HSA / FSA
401K
Work-from-Home Stipend
Therapy Reimbursement
16-week parental leave for eligible employees
Carrot Fertility annual reimbursement and membership
13 paid holidays each year as well as a Holiday Break during the week between December 25th and December 31st
Flexible PTO
Employee Assistance Program (EAP)
Training and professional development
Headway is committed to the full inclusion of all qualified individuals. As part of this commitment, Headway will ensure that persons with disabilities are provided with reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or receive other benefits and privileges of employment, please inform the recruiter when they contact you to schedule your interview.
Headway participates in E-Verify. To learn more, click here.
A notice to Headway applicants: To protect yourself against phishing and recruitment fraud, please note that Headway only accepts applications through our official careers page at . Headway will never refer you to external websites, ask for payment or personal information, or conduct interviews via messaging apps. All official communication will come from a @findheadway.com email address. If you are contacted by someone claiming to be from Headway via an unofficial channel, please do not share any information and report it as spam.
Headway$135k - $165k
...foundational to our platform and customer relationships. As we continue to scale, we are looking for a highly motivated Governance, Risk & Compliance (GRC) Analyst to support and mature Ivo's security compliance and risk management programs. Role Overview Ivo is seeking a...SuggestedContract workFlexible hours$130k - $150k
...at Crusoe. About This Role We’re seeking a GRC Analyst to support the day-to-day execution of our Governance, Risk, and Compliance program. Reporting to the Head of GRC, this... ...due diligence requests with guidance from senior team members Maintaining and updating audit...SeniorTemporary work$150k - $180k
...knowledge. The Role We're looking for a GRC Analyst to join our growing Security, IT, and Privacy... .... You'll be the backbone of all the compliance work at the intersection of Engineering,... ...right person translates security and risk into terms that the business and product...SuggestedFull timeImmediate startRemote workWork from homeFlexible hours$145k - $160k
...economy. About the Role: As a Senior Risk and Compliance Analyst at Mytra, you will join the Security... ...foundation for scalable security governance, SOC 2 and ISO 27001 readiness, customer... ...-admin / co-owner of Mytra's Vanta GRC platform, helping maintain system...SeniorWork at office$159k
...Operations / Strategy Job Level: Senior Manager Business Unit:... ...Department Overview: The Electric Risk & Compliance organization provides governance, oversight, and strategic direction... ..., and instruction to regulatory analysts in a work environment that fosters...SeniorContract workWork experience placementWork at officeFlexible hours2 days per week3 days per week$105k
Requisition ID# 172624 Job Category: Compliance / Risk / Quality Assurance Job Level: Individual... ...& Compliance organization provides governance, oversight, and strategic direction on... ...The Electric NERC Compliance Consultant, Senior core function is to assist/monitor the...SeniorFlexible hours2 days per week3 days per week$218k - $269k
...makes everything else feel small. Role Scope Run the day‑to‑day compliance program end to end across SOC 2 Type II, ISO 27001, NIST 800‑53... ...collection, control monitoring, and audit readiness held on GRC platforms (Vanta) and the tooling we build in‑house. Own the policy...Local area$95k - $150k
...Your Role The Security & Compliance team at Zip is committed to... ...customer requirements. As a GRC Analyst at Zip, you'll be a key... ...internal audits, and vendor risk assessments Lead conversations... ...' security, compliance, and governance teams in due diligence and...Home officeFlexible hours$134k - $202k
...community, or shaping our story, you’ll help define what comes next. About the role: We are looking for a GRC Analyst to join our Governance, Risk & Compliance (GRC) team. You will have the opportunity to manage and maintain ongoing compliance with security and privacy...Work at officeRemote workWork from homeWorldwideMonday to FridayFlexible hours$134.16k - $213.6k
...About The Team The Security Governance, Risk, and Compliance team is part of Plaid’s security organization, focused on enabling the business by proactively... ...6+ years of experience in security assurance, security GRC, security compliance, or a related information security...SeniorContract workLocal area- ...Founding Software Engineer (Mid–Senior Level) Why Zania Every enterprise spends millions of dollars on Governance, Risk, and Compliance (GRC). It's one of the most critical, yet universally painful, parts of running a business. For decades, this industry has been dominated...SeniorFull timeWork at officeRelocation packageFlexible hours
- ...Prosper seeks a Senior Credit Risk Analyst to join the Credit Risk team. The role focuses on building strategies to govern automated decisions in Prosper’s online marketplace and to manage credit and fraud risk using robust analytics. Ideal candidates have strong analytical...SeniorRemote work
- ...Senior Compliance Engineer, AI Governance True Anomaly seeks those with the talent and ambition to build the technology that secures space... ...export compliance background to join our Governance, Risk, and Compliance (GRC) team. This role is responsible for building,...SeniorPermanent employment
- ...information security weaknesses or non-compliance with industry standards. Produce... ...ensuring their understanding of associated risks and actions needed to remediate those... ...Ljbffr Create a job alert for this search Senior Risk Analyst • San Francisco, CA, US #J-18808-...SeniorRemote workFlexible hours
$77k - $202k
...Benefits Management Level Senior Associate Job Description &... ...Mathematics/Quantitative Finance, Government/Public Policy, Health... ...Organizational Management/Behavior, Risk Management/Insurance, Science... ...environments with Regulatory Compliance Consulting - Developing...SeniorH1b$137.34k - $207.81k
...recognized on Forbes Cloud 100 2025 List and is a Y Combinator 2024 Breakthrough Company. Position Location Checkr, Inc. seeks Senior Risk Analyst in San Francisco, CA. Parttime telecommuting is an option. Hybrid work from Checkr office in San Francisco, CA. Job Duties...SeniorPart timeWork at officeLocal areaRemote workRelocationMonday to FridayFlexible hours3 days per week- ...Senior Actuary San Francisco, California, United States Or refer someone Job Openings... ...) ~ CERA (Chartered Enterprise Risk Analyst) ~ MAAA (Member of the American Academy... ...ensuring profitability and regulatory compliance. Analyze complex datasets to forecast...Senior
- ...creates possibilities, and we need different perspectives to see them all. Bring yours to Block. The Role We're seeking a Senior Credit Risk Analyst to join our Enterprise Risk Management team. This role sits at the intersection of credit risk analytics, data science,...SeniorLocal area
$200k - $275k
...Director Of Governance, Risk, And Compliance (Grc) At EliseAI, we're improving the industries that matter most: housing and healthcare. Everyone needs a place to live and access to quality healthcare, yet both are often harder to secure than they should be. By integrating...Work at officeLocal areaRelocation$55 - $60 per hour
...Job Description Job Description Senior Compliance Consultant - Electric Compliance Controls... ...deep technical knowledge of compliance, risk management, and quality assurance to ensure... ...and lead implementation of compliance governance models that drive operational alignment...SeniorContract workWork at officeLocal areaWork visa$212k - $318k
...Partner, Senior Health Actuary We are seeking a Partner, Senior Health Actuary to join our Actuarial and Financial Group (AFG) in Mercer... ...Mercer is a business of Marsh (NYSE: MRSH), a global leader in risk, reinsurance and capital, people and investments, and management...SeniorMinimum wageWork at officeLocal areaRemote workFlexible hours3 days per week1 day per week- DoorDash is seeking a motivated and detail-oriented Senior Actuarial Analyst to join the Corporate Risk & Insurance function. This role involves supporting the actuarial core function and advancing analytical capabilities through data-informed insights. Responsibilities...Senior
- ...Senior Associate Credit Officer Bring your expertise to JPMorgan Chase. As part of Risk Management and Compliance, you are at the center of keeping JPMorgan Chase strong and resilient... ...prominent corporate, institutional and government clients under the J.P. Morgan and...Senior
- About the Team The Risk & Insurance team at DoorDash is responsible for all things... ...for a motivated and detail‑oriented Senior Actuarial Analyst who will be a member of DoorDash's Corporate... ...Paid time off and paid sick leave in compliance with applicable laws (e.g., Colorado...SeniorHourly payWork at officeLocal areaFlexible hours
$77k - $202k
...Health Actuary Consultant - Senior Associate, you will be part of... ...Mathematics/Quantitative Finance, Government/Public Policy, Health... ...Organizational Management/Behavior, Risk Management/Insurance, Science... ...environments with Regulatory Compliance Consulting Developing Reward...SeniorFull timeH1b- ...Okta, based in the San Francisco Bay Area, seeks a Senior Manager for M&A Integration & Strategic Programs to lead end-to-end deal integration... ...executives and diverse teams to drive strategic integrations, governance, and program outcomes. The role requires 8-12+ years in...Senior
- ...You will drive planning, execution, and alignment to ensure timely delivery of complex programs that modernize data platforms and governance across the organization. The role emphasizes stakeholder management, scalability, and collaboration across multiple teams in a...Senior
- ...Slope in San Francisco is seeking a Senior Manager for Financial Risk Management to shape and scale its risk and controls framework across critical business domains. This hybrid position focuses on assessing operational and financial risks, leading controls support, and...Senior
- ...Job Title Public Utilities Regulatory Analyst V Individuals interested in applying for this vacancy must have eligibility. If you are new to state service or need to gain eligibility to this classification, please follow the instructions on "How to apply". For...Senior
- ...experienced corporate paralegal to provide entity management and governance support for 400+ subsidiaries. You will work with the Legal... ...restructurings, and bank onboarding, while ensuring regulatory compliance and timely filings. A Notary license and Canadian entity...Senior
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Governance, Risk, Compliance (GRC) Analyst. Be the first to apply!
- risk analyst San Francisco, CA
- risk officer San Francisco, CA
- it risk analyst San Francisco, CA
- senior quantitative risk analyst San Francisco, CA
- third party risk analyst San Francisco, CA
- operational risk specialist San Francisco, CA
- risk consultant San Francisco, CA
- operational risk consultant San Francisco, CA
- compliance analyst San Francisco, CA
- regulatory compliance analyst San Francisco, CA



