Headway

Healthcare

SeniorGovernance,Risk,Compliance(GRC)Analyst

$162–202k San Francisco, California, United States FULL TIME
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Senior candidates.

The Brief

“Senior Governance, Risk, Compliance (GRC) Analyst at Headway. Skills: GRC, Compliance, Risk management, Security certifications. Support HITRUST audit readiness. Support SOC 2 audit readiness”

Industry & Context.

Healthcare
Problems you'll solve

Root cause analysis; Troubleshooting

What They're Looking For.

Must Have

5+ years GRC experience, Working knowledge HITRUST, Working knowledge SOC 2, Working knowledge PCI-DSS, Working knowledge HIPAA

Nice to Have

Experience in healthcare, Experience in healthtech

What You'll Do.

Support HITRUST audit readiness

Support SOC 2 audit readiness

Support PCI-DSS audit readiness

Support HIPAA audit readiness

Collect audit evidence

Coordinate with assessors

Track remediation timelines

Build vendor assessment lifecycle

Manage vendor assessments

Enforce policy across procurement

Enforce policy across renewals

Stand up training program

Run security awareness training

Create onboarding modules

Run phishing simulations

Track training completion

Operate risk register

Identify technical risks

Assess technical risks

Track technical risks

Mitigate technical risks

Surface risk priorities

Partner with Engineering

Embed compliance into operations

How You'll Work.

Team & Collaboration

Partner with Privacy; Partner with Legal; Partner with IT; Partner with Engineering; Partner with Security leadership

Communication Scope

Communicate requirements clearly

Process & Methodology

Process building, Repeatable processes

Full Job Description

1 in 4 people in the US have a treatable mental health condition, but most providers don't accept insurance, making therapy too expensive for most people. Headway’s mission is to fix this by building a new mental healthcare system everyone can access. We started by solving the biggest barrier to care: insurance. The admin work - credentialing, claims, payment reconciliation - is a nightmare. We've automated that. But we're going further. Over 75,000 providers across all 50 states run their practice on our software, serving over 1 million patients. We are building the best tools for therapists to run their entire practice, reimagining the experience of finding a therapist, and investing in the platform foundations to enable this at scale. We aren't just a billing layer; we are becoming the platform where care actually happens. We're a Series D company with $325M+ in funding (a16z, Accel, Spark Capital, etc.), looking for exceptional people to help us achieve this mission. We want your time here to be the most meaningful experience of your career. Join us, and help change mental healthcare for the better. ABOUT THE ROLE Headway handles sensitive health data for millions of patients — and that responsibility demands a security and compliance program that scales with the business. We're building out our dedicated GRC team to improve and mature our program! You'll join the Security team and work across four pillars: security certifications (HITRUST, SOC 2, PCI-DSS, HIPAA), third-party risk management, security awareness training, and technical risk management. You won't be maintaining a stale compliance program — you'll be building a modern, AI-enabled one at a company that's transforming how mental healthcare is delivered in the United States. This role reports to Blake Atkinson, Director of Security, and partners closely with Privacy and Engineering teams. WHAT YOU'LL OWN - Support HITRUST, SOC 2, PCI-DSS, and HIPAA audit readiness — collecting evidence, coordinating w

Free ATS check

Applying for this Senior Governance, Risk, Compliance (GRC) Analyst role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on Ashby

  • Ashby is a fast modern ATS — most applications take under 3 minutes.
  • The resume parser is strong; verify parsed experience dates and job titles.
  • Custom screening questions are often scored algorithmically — answer completely.
  • Location field affects geo-based screening; use your actual metro area.

ANONYMOUS · UNFILTERED

What do employees actually say about Headway?

Real rants from real employees. Read before you apply.

Read Company Rants →