Job Closed
This listing is no longer active.
No-code automation for security teams
Director, GRC
Location
United States
Posted
131 days ago
Salary
$250K - $265K / year
Seniority
Lead
Job Description
Director, GRC
Tines
• Define and execute Tines' multi-year GRC strategy aligned with business objectives and market expansion goals • Own the compliance roadmap, prioritizing certifications and frameworks based on customer needs and revenue impact (FedRAMP, ISO 27001, SOC 2, GDPR, CCPA, etc.) • Serve as executive sponsor for all compliance programs, providing visibility and reporting to C-suite and Board of Directors • Build business cases for compliance investments, demonstrating ROI and competitive advantage • Monitor evolving compliance landscape, anticipating regulatory changes and translating requirements into actionable programs • Lead, mentor, and grow a team of GRC professionals, establishing career development paths and performance metrics • Drive Tines' FedRAMP authorization to successful completion, overseeing gap remediation, documentation, and 3PAO engagement • Maintain and optimize SOC 2 Type II compliance, ensuring efficient audit cycles and continuous control effectiveness • Own the information security policy framework, ensuring alignment with regulatory requirements and business needs • Own the customer security assurance experience, including questionnaire responses, audit coordination, and Trust Center management.
Job Requirements
- 12+ years of progressive experience in GRC, information security, or risk management, with at least 5 years in a leadership role
- Proven track record leading FedRAMP authorization efforts from planning through ATO (Authority to Operate)
- Deep expertise in multiple compliance frameworks: SOC 2, ISO 27001, FedRAMP, NIST 800-53
- Experience building and scaling GRC teams and programs in high-growth SaaS or technology companies
- Strong executive presence with ability to influence C-suite and Board-level stakeholders
- Demonstrated success managing complex, multi-workstream compliance programs with competing priorities
- Exceptional communication skills with the ability to translate technical compliance requirements into business value for diverse audiences
- Strategic mindset with hands-on execution capability; comfortable rolling up sleeves while setting long-term vision
- Experience partnering with Sales, Engineering, Product, and Legal teams to operationalize compliance.
Benefits
- Applicants for this opportunity must be authorized to work for any employer in the U.S. We are unable to sponsor or take over sponsorship of an employment Visa at this time.
Related Guides
Related Categories
Related Job Pages
More Compliance Jobs
• Develop, implement, and maintain detailed compliance management procedures consistent with applicable laws and regulations. • Oversee the CMS framework, including risk and control identification, reporting, monitoring, testing, change management, training, complaint management, governance, and regulatory relations. • Serve as the designated Director of Compliance, authorized to engage with all departments and effect corrective action as necessary. • Ensure compliance responsibilities are communicated and incorporated into business processes across the organization. • Lead the development and maintenance of risk assessments for various processes and programs to identify risks, create internal controls, and implement mitigation factors. • Review and update policies and procedures to ensure alignment with legal requirements and Connexus standards. • Coordinate and deliver comprehensive compliance training for all employees, tailored to job functions. • Oversee the process for receiving, recording, investigating, and resolving consumer complaints. • Conduct regular compliance quality assurance testing to evaluate adherence to laws, regulations, and internal policies. • Maintain proactive monitoring systems to identify procedural or training weaknesses.
Director, Healthcare Compliance
Mirum Pharmaceuticals, Inc.Creating transformative medicine for people with rare liver disease.
• Lead and manage all aspects of federal and state transparency (Sunshine Act/Open Payments and similar state requirements) and aggregate spend reporting requirements. • Monitor and analyze data for trends, anomalies and compliance gaps. • Manage ongoing development and execution of Mirum’s risk-based auditing and monitoring program to ensure compliance with applicable laws, regulations and company policies. • Work with third-party vendors and internal stakeholders to ensure compliance with state licensing, registration and renewal requirements. • Manage continual development and implementation of Mirum’s compliance policies. • Champion Company culture in which employees view compliance as aligned with core values and regard it as a key objective in business decisions and process development. • Partner with legal, regulatory, finance, quality and other departments to support compliance-related initiatives and resolve operational compliance issues. • Assist with ongoing management of training curriculum and healthcare compliance training as needed. • Assist with investigations regarding matters of observed, reported or suspected non-compliance and collaborate with functional heads as needed toward implementing necessary corrective actions. • Support Privacy initiatives for HIPAA and GDPR compliance as needed. • Represent Mirum in industry compliance forums. • Participate in ride-long monitoring activities as needed.
• Work with the CO and MLRO on internal compliance policy review, including ongoing assessments, assisting with compliance review, internal audit reviews and ongoing or ad hoc reviews; • Tracking new product/service launch compliance items; • Handle, review and verify all applications for client on-boarding within available SLAs; • Proficiency in compliance applications and programs such as Thomson Reuters, Worldcheck, KYC vendors, Chainalysis, etc.; • Work closely with checker to ensure an effective 2 eye, 4 eye customer due diligence process; • Good knowledge on provisions of local and AIFC laws, guidance, regulations and otherwise standards applicable to subject persons and knowledge of upcoming regulation of virtual currency policies is a strong plus; • Good proficiency in conducting risk assessments, periodic/trigger reviews and enhanced due diligence; • Monitoring and documentation of unusual activity or AML flags; • Participate in internal and external training programs related to AML/CFT and other subjects that may form part of the day to day work requirements; • Any general administration and ancillary activities as may be required and related to the above functions in accordance with the business requirements of the Company.
• The Compliance Manager is responsible for ensuring that audit and corrective action processes are efficient, operationally sound, and proactively managed. • This role requires frequent collaboration with stakeholders at all levels of the organization to identify risks, resolve issues, and support a culture of compliance. • Provide guidance and training to audit staff, and ensuring compliance with auditing standards. • Lead and oversee a team on execution of all aspects of regulatory and client audits, including: Pre-site deliverables, Mock audits, On-site logistics, Written responses to audit findings and corrective action plans. • Interface with external clients and regulatory bodies to address inquiries, and support audit or examination activities. • Prepare and assist with monthly metrics reporting, including reporting to oversight committees and boards. • Monitor team performance, provide regular feedback, and support continuous improvement initiatives. • Research, interpret, and communicate applicable regulatory and contractual requirements.




