nabla - GRC Manager
Requirements
• 4+ years of experience in GRC, Information Security, or a closely related function — with meaningful time spent building or scaling programs, not just running them • Demonstrated hands-on experience in GRC program at scale — ideally in a high-growth SaaS or technology company • Experience working with GRC platforms and tooling to manage compliance activities, risk registers, policy lifecycle management, audit evidence collection, and workflow automation • Deep expertise across multiple compliance and security frameworks, including SOC 2 Type II, ISO 27001 • Healthcare experience preferred - HIPAA background and understanding of controls • Experience conducting and managing product & enterprise risk assessments, with a working knowledge of risk quantification methodologies • AI forward individual who will look to automate manual processes today • Relevant certifications strongly preferred: CISM, CRISC, CISA, CCSP, or comparable credentials
Responsibilities
• Reporting to the Head of Information Security & Compliance, you will work alongside Security, Engineering, Product and Legal teams to mature Nabla’s Governance, Risk & Compliance programs • Manage the GRC control evidence library including investigation of control flags and evidence collection • Manage the vendor risk program including intake of new vendor requests, security and risk assessments, periodic reviews and ongoing vendor monitoring • Review and interpret security assurance artifacts such as SOC 2 Type II reports, penetration test reports, CAIQ, SIG, ISO certifications, and other compliance attestations • Assist the Head of Information Security with the implementation and ongoing operation of security and risk management frameworks, including net new control additions (e.g., GDPR, ISO, SOC 2) • Assist the Head of Information Security with security questionnaires and client audits including management of knowledge base and tracking • Support cyber GRC activities, including tracking information security risks, risk exceptions, and remediation plans • Manage security/compliance onboarding requirements including security awareness training, access checklists, and quarterly access reviews • Assist with the administration and continuous improvement of the company’s security awareness and training program, including tracking completion metrics and updating training content as needed • Own the ongoing review and maintenance of organizational security policies, standards, and procedures. Assist in identifying policy gaps based on evolving regulatory requirements, business needs, and industry best practices
Benefits
• Just like we’re dedicated to supporting doctors’ well-being, ensuring yours is a top priority. We firmly believe that by prioritizing your well-being, we support you to excel in your work. • Here are the benefits you get when joining Nabla: • Compensation and Equity: Competitive salary and stock options • Comprehensive Health Plans: 100% individual coverage for Medical, Dental, and Vision insurance • Time Off: Unlimited paid time off and 11 national holidays • Health Comes First: Unlimited sick leave • Parental Leave: Paid leave for new parents • Remote-friendly: $1,000 to purchase home office equipment • Trust & accountability: Full ownership of your time and schedule • When you become a part of our company, you join a team of excellence-driven, curious, and genuinely kind individuals. Together, we're committed to making clinicians' lives easier and improving healthcare experiences for everyone. We believe in a world where clinicians can focus on what they were trained to do - caring for their patients, and where no patient feels their visit was rushed. • We come to work excited to leverage AI to do more for clinicians. We’re obsessed with our users’ satisfaction and we actively seek out opportunities to engage one-on-one with clinicians to understand how Nabla can better help. We consistently look for ways to improve and do not shy away from doing the work to excel. Whether it’s a feature our users asked for, or a new article for our blog, we prioritize collaboration to deliver exceptional outcomes. • We love having fun as much as we love work. Our #nablabla channel is as active as our #feature-show-off channel, we exercise during the work day at least 3 times a week (yoga, running, pilates, or HIIT, your choice!), enjoy regular off-sites to gather the team, and travel to see each other in places like NY, Paris, San Francisco, and many other vibrant cities. Oh, and we’re constantly snacking on chocolate or nuts! • If this sounds like an environment you’ll thrive in, we look forward to reading your application! • OUR VALUES AT NABLA • Every day is a new chance to excel • We aim for nothing less than the best and are willing to put in the effort and dedication required to exceed standards. We learn from yesterday’s failures and do better every day. • There’s no place for ego in our team. Our collective success is more important than individual achievements. We see humility as wisdom — keeping focus on the bigger picture. • Feedback is a gift • We embrace feedback and foster a culture of trust and respect that helps everyone grow. We communicate openly about both achievements and challenges, and we actively involve each other in finding solutions. • Committed to diversity • We recognize the ongoing challenge of diversity in tech. Our responsibility starts with fostering an inclusive environment where everyone feels empowered to be their authentic selves and do their best work. • DIVERSITY & INCLUSION • Diversity and inclusivity are fundamental values at Nabla. We embrace individuals from various backgrounds, including race, gender, educational history, sexual orientation, and beyond.
Apply in one click
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT