Headway
Healthcare
SeniorGovernance,Risk,Compliance(GRC)Analyst
Neural analysis suggests this role is
optimal for Senior candidates.
“Senior Governance, Risk, Compliance (GRC) Analyst at Headway. Skills: GRC, Compliance, Risk management, Security certifications. Support HITRUST audit readiness. Support SOC 2 audit readiness”
Industry & Context.
Root cause analysis; Troubleshooting
What They're Looking For.
Must Have
5+ years GRC experience, Working knowledge HITRUST, Working knowledge SOC 2, Working knowledge PCI-DSS, Working knowledge HIPAA
Nice to Have
Experience in healthcare, Experience in healthtech
What You'll Do.
Support HITRUST audit readiness
Support SOC 2 audit readiness
Support PCI-DSS audit readiness
Support HIPAA audit readiness
Collect audit evidence
Coordinate with assessors
Track remediation timelines
Build vendor assessment lifecycle
Manage vendor assessments
Enforce policy across procurement
Enforce policy across renewals
Stand up training program
Run security awareness training
Create onboarding modules
Run phishing simulations
Track training completion
Operate risk register
Identify technical risks
Assess technical risks
Track technical risks
Mitigate technical risks
Surface risk priorities
Partner with Engineering
Embed compliance into operations
How You'll Work.
Team & Collaboration
Partner with Privacy; Partner with Legal; Partner with IT; Partner with Engineering; Partner with Security leadership
Communication Scope
Communicate requirements clearly
Process & Methodology
Process building, Repeatable processes
Full Job Description
1 in 4 people in the US have a treatable mental health condition, but most providers don't accept insurance, making therapy too expensive for most people. Headway’s mission is to fix this by building a new mental healthcare system everyone can access. We started by solving the biggest barrier to care: insurance. The admin work - credentialing, claims, payment reconciliation - is a nightmare. We've automated that. But we're going further. Over 75,000 providers across all 50 states run their practice on our software, serving over 1 million patients. We are building the best tools for therapists to run their entire practice, reimagining the experience of finding a therapist, and investing in the platform foundations to enable this at scale. We aren't just a billing layer; we are becoming the platform where care actually happens. We're a Series D company with $325M+ in funding (a16z, Accel, Spark Capital, etc.), looking for exceptional people to help us achieve this mission. We want your time here to be the most meaningful experience of your career. Join us, and help change mental healthcare for the better. ABOUT THE ROLE Headway handles sensitive health data for millions of patients — and that responsibility demands a security and compliance program that scales with the business. We're building out our dedicated GRC team to improve and mature our program! You'll join the Security team and work across four pillars: security certifications (HITRUST, SOC 2, PCI-DSS, HIPAA), third-party risk management, security awareness training, and technical risk management. You won't be maintaining a stale compliance program — you'll be building a modern, AI-enabled one at a company that's transforming how mental healthcare is delivered in the United States. This role reports to Blake Atkinson, Director of Security, and partners closely with Privacy and Engineering teams. WHAT YOU'LL OWN - Support HITRUST, SOC 2, PCI-DSS, and HIPAA audit readiness — collecting evidence, coordinating w
Applying for this Senior Governance, Risk, Compliance (GRC) Analyst role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Ashby
- Ashby is a fast modern ATS — most applications take under 3 minutes.
- The resume parser is strong; verify parsed experience dates and job titles.
- Custom screening questions are often scored algorithmically — answer completely.
- Location field affects geo-based screening; use your actual metro area.
ANONYMOUS · UNFILTERED
What do employees actually say about Headway?
Real rants from real employees. Read before you apply.