Governance Risk and Complains Manager
GetixHealth · 22 hours ago
Job Title:
GRC Manager
Job Category:
Department/Group:
Information Technology
Job Code/ Req#:
Work Location:
Remote
Reports To:
Level/Salary Range:
Position Type:
Full Time
FLSA STATUS:
Travel:
10%, as needed
Date Posted:
Job Req. Category:
Job Description
About the role
This role will be responsible for ensuring the organization maintains strong controls across HIPAA, HITRUST, SOC 2, PCI-DSS, client contractual requirements, and emerging AI governance standards. The ideal candidate will have direct experience supporting healthcare organizations, healthcare technology companies, RCM providers, or business process outsourcing environments that handle protected health information (PHI), payment data, and other sensitive healthcare information. The GRC Manager will work closely with Information Security, IT, Operations, Legal, Privacy, Human Resources, Client Services, Engineering, and executive leadership to manage compliance obligations, reduce organizational risk, support customer audits, and enable responsible use of artificial intelligence across healthcare operations.
What you will do
Governance & Compliance
-
Develop, maintain, and continuously improve the organization’s enterprise GRC program.
-
Lead compliance activities related to:
-
HIPAA Privacy and Security Rules
-
HITRUST CSF
-
SOC 2 Type II
-
PCI-DSS
-
Ensure controls appropriately protect PHI, personally identifiable information (PII), payment card data, and other sensitive healthcare information.
-
Maintain policies, standards, procedures, risk methodologies, and control documentation.
-
Support compliance with Business Associate Agreements (BAAs), client security requirements, and healthcare customer contractual obligations.
-
Monitor changes in healthcare regulations, cybersecurity requirements, and industry standards.
-
Coordinate internal and external assessments, certifications, client audits, and regulatory reviews.
Risk Management
- Conduct enterprise risk assessments and maintain the organizational risk register.
- Perform third-party/vendor security risk assessments.
- Develop mitigation strategies and monitor remediation activities.
- Present risk metrics and executive reports to senior leadership.
- Support business continuity and disaster recovery governance.
AI Governance & Responsible AI
-
Develop and maintain an AI governance framework for the responsible use of artificial intelligence within healthcare RCM.
-
Establish policies and controls governing generative AI, machine learning, automation, and AI-enabled decision-support technologies.
-
Evaluate AI use cases involving:
-
Coding assistance
-
Denial prediction
-
Claims analytics
-
Prior authorization
-
Patient communication
-
Revenue forecasting
-
Assess AI solutions for privacy, security, accuracy, bias, transparency, explainability, and regulatory risk.
-
Ensure PHI is appropriately protected when using internally developed or third-party AI tools.
-
Establish approval and risk-review processes for new AI use cases and vendors.
-
Maintain an inventory of approved AI systems, use cases, owners, data sources, and associated risks.
-
Align AI governance practices with frameworks such as the NIST AI Risk Management Framework and ISO/IEC 42001 where appropriate.
Audit & Client Assurance
- Lead preparation for SOC 2, HITRUST, HIPAA, PCI DSS, and customer security assessments.
- Coordinate evidence collection and control testing across business and technology teams.
- Manage remediation plans for audit findings, control deficiencies, and client security observations.
- Respond to customer security questionnaires and due diligence requests.
- Participate in security and compliance discussions with healthcare providers, health systems, physician groups, payers, and other clients.
- Maintain a centralized repository of compliance evidence, audit documentation, and client assurance materials.
Third-Party Risk Management
- Lead or support vendor security and compliance assessments.
- Evaluate vendors that access, process, transmit, or store PHI, PII, payment information, or other sensitive data.
- Review security documentation including SOC reports, HITRUST certifications, penetration tests, and risk assessments.
- Ensure appropriate BAAs, data protection agreements, and security requirements are in place.
- Monitor critical vendors for changes in risk posture.
Security & Privacy Governance
- Partner with Information Security and Privacy teams to maintain administrative, technical, and physical safeguards required by HIPAA.
- Support identity and access management governance for systems containing healthcare information.
- Participate in incident response activities involving potential PHI exposure, security incidents, or compliance concerns.
- Support breach assessment and regulatory notification processes where required.
- Oversee security and compliance awareness programs for employees and contractors.
- Promote appropriate handling of healthcare data across operational teams.
Program Management & Reporting
- Develop GRC dashboards and executive reporting for risk, audit status, remediation, vendor risk, and compliance metrics.
- Track key risk indicators and key performance indicators for the compliance program.
- Manage compliance calendars and recurring control activities.
- Lead cross-functional remediation and compliance initiatives.
- Present significant risks, findings, and recommendations to senior leadership.
- Drive automation and continuous improvement within the GRC program.
Required Qualifications
-
Bachelor's degree in Information Security, Cybersecurity, Information Systems, Business, or related field or equivalent years of experience.
-
6–8+ years of experience in Governance, Risk, and Compliance.
-
Demonstrated experience managing:
-
SOC 2
-
HITRUST
-
PCI DSS
-
Experience leading external audits and remediation efforts.
-
Strong understanding of information security principles, risk management, and internal controls.
-
Experience implementing governance programs across multiple departments.
-
Excellent communication, documentation, and stakeholder management skills.
-
Experience using GRC platforms.
-
Project Management experience.
One or more of the following certifications is preferred:
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- Certified Information Systems Auditor (CISA)
- Certified in Risk and Information Systems Control (CRISC)
- HITRUST Certified CSF Practitioner (CCSFP)
- Certified HIPAA Professional (CHP)
- PCI Professional (PCIP)
- ISO 27001 Lead Implementer or Lead Auditor
- Certified in Governance, Risk and Compliance (CGRC)
- AI governance or risk certifications (e.g., ISO/IEC 42001 Lead Implementer, NIST AI RMF training, or equivalent).
You will be a good fit if:
- You are known for being thorough and crossing every “T”.
- You enjoy collaboration and building relationships at every level.
- Curiosity and willingness to learn new things.
- Excellent organization and planning skills, both technical and strategic.
- Stay updated with the latest in technology and cybersecurity trends to recommend improvements to our IT and security infrastructure.
- Ability to communicate regularly and have a desire to be a part of a team.
Additional Notes
· This role profile is not intended to be an exhaustive list of qualifications, skills, efforts, duties, responsibilities or working conditions associated with the position.
GetixHealth is an equal employment opportunity employer.