Security GRC Lead
$180k - $258kCandid Health
About Candid Health In simple terms, healthcare in the U.S. has a massive, invisible problem behind the scenes: getting doctors paid by insurance companies is notoriously complicated. Insurance rules are constantly changing, and every bill (or "claim") requires mountains of paperwork. When mistakes happen, bills get rejected, patients end up with unexpected charges, and healthcare providers waste billions of dollars and countless hours on administrative bureaucracy instead of focusing on patient care. That is where Candid Health steps in. Founded by former Palantir leaders who experienced these pain points firsthand, we are building the modern financial backbone for American healthcare. Instead of relying on decades-old legacy software or attempting to patch broken systems with superficial tools, we've rebuilt the underlying infrastructure from the ground up. Our core product is an autonomous Revenue Cycle Management (RCM) platform . Powered by AI agents and a configurable rules engine, the platform unifies clinical, billing, and insurance data into a single smart system. It acts like an intelligent, automated back-office that handles complex medical claims from start to finish—submitting them accurately on the first pass, cutting down administrative costs, and dramatically increasing cash flow for healthcare providers. Today, we are trusted by over 200 fast-growing healthcare organizations—from digital health innovators to large enterprise medical groups—processing billions in claims annually. Backed by top investors like Sixth Street Growth, Oak HC/FT, 8VC, and Y Combinator, Candid Health recently raised a $120 million Series D to fuel the AI-driven transformation of healthcare payments and eliminate administrative friction for good. Role Overview We are seeking a Security GRC Lead to build our first in-house GRC program from the ground up. In this role, you won't just write policies or collect manual screenshots in spreadsheets; you will treat compliance as an engineering and data problem. You will build automated evidence pipelines, implement compliance-as-code, and establish continuous controls monitoring across our GCP infrastructure, identity systems, and CI/CD pipelines. You will turn point-in-time audits into a continuous compliance telemetry system that keeps our platform secure, resilient, and audit-ready at all times. Key Responsibilities 1) Compliance Automation & Engineering Develop automated scripts and API integrations to collect compliance evidence directly from system sources instead of collecting manual screenshots. Write and deploy infrastructure-as-code and policy enforcement rules to enforce security baselines automatically. Maintain live compliance dashboards and alerts that flag configuration drift or policy violations in real time. Partnering with Legal on Medicare and Medicaid compliance Partnering closely with legal and finance teams on future due diligence and compliance projects 2) Framework Mapping & Control Architecture Convert regulatory, security, and industry standards (SOC 2, HiTrust, PCI, HIPAA) into clear, testable technical controls. Map single technical controls across multiple overlapping frameworks to eliminate redundant work. Work alongside DevOps and Software Engineering teams to build compliance controls directly into CI/CD pipelines without slowing down delivery. 3) Risk Management & Audits Lead technical audit readiness and external audit engagements using programmatic evidence pipelines. Automate vendor risk management workflows and API-driven vendor evaluations. Build continuous risk tracking tools fed by live vulnerability telemetry and identity logs rather than static quarterly surveys. Required Qualifications 3+ years in a technical security role, such as Security Engineering, Cloud Security, or Technical GRC. Proficiency in Python, TypeScript, SQL and hands on experience interacting with APIs, parsing logs, and querying databases. Hands-on experience with at least one primary cloud platform, GCP Preferred and Infrastructure-as-Code tools such as Terraform Deep familiarity with core frameworks such as SOC 1/2, PCI, NIST, and/or HITRUST. Understanding of CI/CD pipelines, Git workflows, and container environments (Docker/Kubernetes). Preferred Qualifications Certifications such as CISSP, CISA, CRISC, AWS Certified Security – Specialty, or CCSP. Experience with Policy-as-Code engines HITRUST experience Background in software development, DevOps, or platform engineering. Experience with modern continuous compliance platforms (e.g., Vanta, Drata, Anecdotes). Our values We spend at least as much time with our coworkers as we do with our closest friends + family - if we intend to do the most important + challenging work of our lives, it’s important that these folks energize us, support us, inspire us, and push us to do our best work. This is what you can expect of your teammates at Candid (in no particular order): We put our customers first We take care of each other and ourselves We anchor on outcomes and work relentlessly and creatively to achieve them We collectively prioritize building a diverse and inclusive workspace We believe humility is our greatest strength We are candid, kind, and committed We strive to be the most prepared person in the room We are truth seekers Pay Transparency The estimated starting annual salary range for this position is $180,000 - 258,000 USD. The listed range is a guideline from Pave data, and the actual base salary may be modified based on factors including job-related skills, experience/qualifications, interview performance, market data, etc. Total compensation for this position may also include equity, sales incentives (for sales roles), and employee benefits. Given Candid Health’s funding and size, we heavily value the potential upside from equity in our compensation package. Further note that Candid Health has minimal hierarchy and titles, but has broad ranges of experience represented within roles. #J-18808-Ljbffr Candid Health
- MSIG USA, the US-based subsidiary of MS&AD Insurance Group, is seeking a Lead, Governance, Risk & Compliance (GRC) to mature security governance, risk management, and compliance activities. This role focuses on hands-on execution, regulatory compliance, audits, and policy...Suggested
- ...Compliance Certifications Engineer to own end-to-end security certifications (ISO 27001, SOC 2, NIST). You will lead planning, execution, and improvements,... ...brand integrity. We value 8+ years of governance/ GRC experience, cloud security familiarity, and multiple...Suggested
$174.25k - $205k
...across the U.S., Australia, and France. About The Role As a Senior GRC Lead at Jasper, you will own our Governance, Risk, and Compliance... ...and maintain momentum on audits, risk management, and vendor security, partnering closely with Security, Legal, and Engineering to keep...SuggestedLocal areaRemote workWorldwideHome officeFlexible hours- ...deliver strategic technical consulting on security data correlation, platform design, and deployment... ...renewals. Responsibilities Autonomously lead the post-sale technical relationship for... ...the one place to go for Security, IT, and GRC teams to continuously drive actionability...SuggestedRemote job
- ...Plan, implement, and lead all aspects of Quality auditing and testing. This is a hands on-role requiring Fiberon Quality Systems knowledge... ...: Fortune Brands Innovations is an industry-leading home, security and digital products company. We’re advancing exciting innovations...SuggestedFlexible hours
- ...orchestrate agentic apps that take on real operational work, with the security and control large organizations need. We are a small,... ...their alliance managers. You will work closely with our Commercial Leads, who own the customer relationships, and with the engineers who...Full timeContract work
- ## Lead GRC AnalystApply: Hybrid: NJ-Warren: Full time: Posted Yesterday: JR-001021MSIG USA continues to grow!**Company Overview:**MSIG... ...Governance, Risk & Compliance (GRC)** to help run and mature core security governance, risk management, and compliance activities. This...Full time
$143.17k
...appropriate resolutions in a timely and effective manner. Preserve the security and safety of all clients, animals, team members, client... ...adequate levels of inventory for current and anticipated needs. Lead continuous staff development through professional and clinical training...Full timeWork experience placementWork at officeHome office$25 - $50 per hour
...Role Overview TSA is accepting applications for Lead and Supervisory Transportation Security Officers at airports in Eastern. These roles are ideal for individuals looking to step into leadership positions within airport security operations. TSA provides training to...Shift workNight shiftWeekend work- ...Intuition, you will: Manage on-site services such as utilities, safety zones, communication systems, and fleet access/security protocols to enable testing. Lead daily field operations at our customer deployments, ensuring teams, vehicles, and equipment are ready to support...Full timeFor contractorsFor subcontractorCasual workWork at officeRemote workDay shift
- Cloudflare, Inc. is seeking a Senior Technical Program Manager to lead governance, risk, and compliance programs, starting with IL4. This role demands a process-oriented, agile approach, capable of coordinating multiple teams across time zones and regulatory frameworks...
- DSV - Global Transport and Logistics is seeking a Senior Freight Security Specialist in Lancaster, TX. You will monitor high-value shipments, assess security risks, and coordinate responses to alerts using GPS, telematics, and geofencing. The role requires 3-5 years in...Monday to FridayNight shiftAfternoon shift
- OpenAI is seeking a Senior Technical Program Manager for Security to lead cross-functional programs spanning infrastructure, privacy, IT, and compliance. You will drive security initiatives, coordinate across engineering, legal, and product teams, and scale governance...
- Forrester Research, Inc. is seeking a Senior Analyst to research and advise on risk management, including cyber risk quantification and governance. You will develop artifacts, write reports, and present guidance to risk leaders across industries. You will collaborate with...
- Kaiser Permanente seeks a Threat Hunting Lead to serve as the technical lead for the Threat Hunting function within the TIDE team. You... .... The role requires leadership, collaboration with multiple security functions, and a passion for data-driven threat analysis to continuously...
$150k - $205k
Celestar, a B&A Company, seeks a Senior Program Security Representative to support the DARPA PSS task order in Arlington, VA. Salary range $150,000-$205,000 annually with a TS/SCI clearance requirement and contingent upon contract award. Anticipated award March 2027 and...Contract work- ...Government Affairs Manager to drive federal lobbying and policy development on national security, defense, and intelligence matters. You will build relationships with federal officials and lead efforts with SpaceX and Starlink on policy issues. Based in Washington, DC, this...
$128k - $177k
Job Description: Cydecor is seeking a Cloud & Security Architecture Lead to design and sustain secure, scalable cloud environments supporting ONR’s Data & Analytics ecosystem. This role leads cloud architecture strategy, DevSecOps integration, and compliance with IL5,...Temporary work- ...the Austin campus seeks a Manager, Applications & Data Systems to lead the technical direction for CCCSE’s web applications, surveys,... ...Python/Django platform, APIs, and integrations with emphasis on security and scalable data access. Responsibilities include designing and...
- Select how often (in days) to receive an alert: Applied AI Lead - Evaluation & Measurement Location: Frederick, MD, US, 21703 Fort Walton... ...life-cycle defense and intelligence products that protect the security of our nation and our allies. From air combat training to state-...Local areaFlexible hours
- Chubb Ltd. in Philadelphia, PA seeks a Sr. Technical Security Lead to shape secure technology solutions from design to production. You will guide application security reviews, drive secure coding and SDLC practices, and apply broad cyber knowledge across testing, IAM, and...
- The Salvation Army Ray and Joan Kroc Corps Community Center - Phoenix is seeking a Building & Security Lead to supervise Attendants, coordinate shifts, and support the Facilities Director with hiring and evaluations. You will oversee daily security operations, review timesheets...Part timeShift workNight shift
- Crane Worldwide Logistics LLC is seeking a Global Security Intelligence Manager to lead the enterprise intelligence program, producing actionable threat assessments and risk analyses to protect personnel, facilities, shipments, and operations. The role partners with Global...Worldwide
- OpenAI is seeking a GRC Program Manager to lead US government compliance initiatives, drive FedRAMP ATOs, and coordinate with engineers and assessors... ..., DC with hybrid work. You will design and implement security controls, produce SSPs and risk assessments, and represent...
- Vosper Thornycroft Group is seeking a Program Security Officer to oversee and manage personnel security programs, ensuring compliance with federal and company security policies. The role is based in the National Capital Region and 100% onsite. Responsibilities include...
- ...the New York Stock Exchange under the symbol, WES. Job Summary Western Midstream is seeking a Texas Air Permitting Lead to join the Health, Safety, Security, and Environmental (HSSE) team in The Woodlands, TX. This senior-level position serves as the technical lead for...Work at officeRemote work
- CPB Group Pty is seeking an experienced Application Security Program Manager I-II for an on-site role in Honolulu. You will lead the bank’s application security program, identity governance, and fraud-related tech risk, shaping strategy, standards, and a multi-year roadmap...
- CampusIQ in North Austin, TX is seeking a Senior Security & Compliance Platform Engineer to own the security program from end to end. You’ll implement SOC 2 Type 2 and GovRAMP Core controls, automate evidence collection, and work with auditors. This role focuses on agentic...
- Motion Recruitment's client, a technology company modernizing physical security through software, seeks an IT Specialist to own corporate IT operations and deliver responsive support across the organization. This hands-on role is the sole IT resource, handling employee...
- Leidos in Virginia is seeking an Information System Security Manager (ISSM) to oversee the cybersecurity posture of DoD information systems... ...or active clearance, DoD policy experience, and the ability to lead cross‑functional teams while delivering continuous monitoring,...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security GRC Lead. Be the first to apply!


