← Back to job listings
HE
Senior Governance, Risk, Compliance Analyst
Headway · United States
About The Role
Join Headway, a company transforming mental healthcare in the United States. As a Senior Governance, Risk, Compliance Analyst, you will be part of the Security team and work across four key areas: security certifications, third-party risk management, security awareness training, and technical risk management. You will support audit readiness for HITRUST, SOC 2, PCI-DSS, and HIPAA, manage the vendor security assessment lifecycle, run the security awareness training program, and operate the centralized risk register. You will partner with various teams to embed compliance into Headway's operations.
- Support HITRUST, SOC 2, PCI-DSS, and HIPAA audit readiness by collecting evidence, coordinating with assessors, and tracking control gaps.
- Build and manage the vendor security assessment lifecycle, including questionnaires, SOC 2/ISO reviews, risk scoring, and policy enforcement.
- Stand up and run Headway's security awareness training program, including onboarding modules, phishing simulations, and annual compliance training.
- You communicate compliance requirements clearly to both technical and non-technical audiences
- You default to building repeatable processes over one-off heroics
- You have working knowledge of at least two of: HITRUST, SOC 2, PCI-DSS, or HIPAA
- You have 5+ years of experience in a GRC, compliance, or security risk role
- You've used a GRC platform like Vanta, Drata, OneTrust, or similar to automate evidence collection or manage controls
- Bonus: you've worked in healthcare or healthtech and understand what HIPAA means in practice, not just in theory
- You're excited about using AI and modern tooling to scale compliance operations
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring