Maven Clinic

Senior Manager, GRC

Maven Clinic · New York, New York, United States; New York, NY; Remote, US (Hub cities)

Posted 8 days ago · $170,000 - $201,000

or apply directly on Maven Clinic's site. We never take the application ourselves.

Is this posting real?

This role has been open
8 days
Maven Clinic's roles stay open a median of 45 days
Reposted
No
Salary listed
Yes
84% of Maven Clinic's roles list one
Ghost-job risk at Maven Clinic
high
20 stale, 1 reposted of 37 open
Hiring momentum
52 roles opened in the last 90 days
↑ up vs. the prior 90 days
Last confirmed on the employer's board
2026-09-17

Measured from postings appearing on and disappearing from Maven Clinic's own greenhouse board since 2026-08-03. Full hiring picture for Maven Clinic.

About this role

As a Senior Manager of Governance, Risk, and Compliance (GRC) at Maven Clinic, you will lead the GRC function for the company's B2B health benefits platform. Your responsibilities will include managing audits, writing policies, and ensuring compliance with various frameworks like SOC 2 and HITRUST. You will collaborate with multiple teams, engage with customers on compliance matters, and oversee the internal audit program to maintain operational integrity.

Our read on this posting4.4out of 5
benefits
4/5
freshness
5/5
career value
4/5
role clarity
4/5
pay transparency
5/5

Scored from the posting itself — how clearly the role is described, how much it says about pay and benefits, and how recently it was listed. Not a judgement of Maven Clinic as an employer.

What you need

  • 6+ years of experience in GRC, information security compliance, or IT audit
  • Direct ownership of at least one SOC 2 or similar audit cycle from start to finish
  • Working knowledge of SOC 2, HITRUST, and ISO 27001 frameworks
  • Experience responding to customer security questionnaires/RFIs in a B2B SaaS or healthcare-adjacent environment
  • Strong cross-team collaboration skills
  • Solid project management instincts

Nice to have

  • Direct experience standing up a new certification (SOC2, HITRUST, ISO 27001 and/or ISO 42001)
  • Experience with GRC/compliance automation tooling
  • Background in health tech, digital health, or another regulated B2B vertical
  • A relevant certification such as CISA, CRISC, CISSP, PMP or CAPM, CISM, CTRC/CAP
  • Exposure to vulnerability management or IT operations

What you get

  • Employer-covered health, dental, and insurance plan options
  • Access to the full platform and specialists through Maven for Mavens
  • Whole-self care through wellness partnerships
  • Hybrid work, in office meals, and work together days
  • 16 weeks 100% paid parental leave and new parent stipend
  • Annual professional development stipend and access to a personal career coach

Worth weighing

  • No specific mention of a technology stack or tools used in the GRC function
  • The role requires significant cross-team collaboration, which may vary in complexity
  • The position reports directly to the CISO, indicating a high level of responsibility and visibility

Summarised from Maven Clinic's posting. Read the full original.

Listed by Maven Clinic on their greenhouse job board, last confirmed open on 2026-09-17. PitchMeAI is not the employer.

More roles at Maven Clinic

All 37 open roles at Maven Clinic