Senior GRC Manager
for section headings (e.g. About the role, Responsibilities, Requirements, Qualifications, Skills, Benefits, Pay, Schedule). Use - for any list of duties/requirements/benefits, and
for prose. Do NOT repeat the job title as a heading (the page already shows it) and do NOT put Job ID / requisition numbers as headings — fold minor metadata into a short
or drop it. Preserve ALL substantive information; do NOT invent or summarize away detail. Remove cookie/navigation/legal/EEO/equal-opportunity/scam-warning boilerplate, duplicated lines, and application instructions. IMPORTANT: include a section ONLY when the posting has real, specific content for it — never emit a heading followed by filler/placeholder text (e.g. "commensurate with experience", "not specified", "N/A", "varies", "TBD") and never create Pay/Schedule/Benefits sections unless the posting actually states them. Prefer a few substantive sections over many thin ones. Output ONLY the HTML fragment — no /, no markdown code fences.
Thus we need to decide which sections to include based on content.
We have:
- About the role: The posting starts with "We're looking for a Senior GRC Manager to own our GRC program end to end...". That's a description of role. Could be "About the role". We'll include that.
- Responsibilities: The "What You'll Own" section includes bullet points (actually paragraphs). Could be responsibilities.
- Requirements: "What We're Looking For" includes requirements.
- Qualifications: maybe "Nice to Have" could be qualifications? But we can treat "Nice to Have" as "Preferred Qualifications". However we need to avoid thin sections. Could combine "What We're Looking For" and "Nice to Have" into a single "Requirements" section? But we need to preserve all info. Could have separate sections: "Requirements" and "Preferred Qualifications". Both have content.
- Benefits: "What We Offer" includes benefits list.
- Pay: "Salary Range $130 - 150K". That's pay.
- Schedule: Not mentioned. So we should not create Schedule section.
- About Us: "About Us" and "About Harris Computer" could be combined into "About the Company". But we need to decide if we include a section for company overview. The allowed headings list includes About the role, Responsibilities, Requirements, Qualifications, Skills, Benefits, Pay, Schedule. It does not list About Us. However we can still include other headings? The instruction: "use
for section headings (e.g. About the role, Responsibilities, Requirements, Qualifications, Skills, Benefits, Pay, Schedule)." It says e.g., implying those are examples, not exclusive. But we should probably stick to those categories to be safe. However we need to preserve all substantive information. If we omit About Us, we lose info. But maybe we can fold About Us into "About the role" or "Qualifications"? Not ideal. The instruction says "Prefer a few substantive sections over many thin ones." It doesn't forbid other headings, but we should follow the pattern. Could we treat "About Us" as part of "About the role"? Probably not. Better to include a section like "About the Company". The instruction didn't forbid other headings; it just gave examples. So we can include additional headings as needed, as long as they are . We'll include sections: About the role, Responsibilities, Requirements, Preferred Qualifications, Benefits, Pay, About the Company (maybe combine About Us and About Harris Computer). Also maybe "What We Offer" is Benefits.
We need to use - for any list of duties/requirements/benefits. So for responsibilities we should convert each bullet into
- . The "What You'll Own" section includes multiple paragraphs each starting with a bold heading? Actually it's:
What You'll Own
Governance, Risk & Compliance
Maintain ClearDATA's Information Security Management Program: the policies, procedures, and standards behind our security and compliance posture.
Support audits, assessments, and certification renewals for HIPAA, GDPR, HITRUST, and SOC 2.
Maintain the risk register, including tracking third-party and vendor risk.
Keep control mapping and audit evidence current and organized.
Support incident response planning alongside the IT/ITSec Manager and security team.
Partner with security engineers and DevSecOps to translate control requirements into how systems are actually built and operated — and to turn what they've built into defensible audit evidence.
Documentation & Audit Liaison
Update policies and program documentation as systems, vendors, or ownership of shared responsibilities change.
Work directly with auditors to catch and close compliance gaps before they become findings.
Flag open risk or outstanding items that need attention.
Act as the go-to compliance resource across the company — engineering, DevSecOps, management, and executive leadership — helping teams find a workable path forward rather than just pointing at policy, and giving leadership a clear read on where the program stands.
We can treat each line as a duty. Could group under two subheadings but we don't need subheadings; just list.
Similarly "What We're Looking For" includes bullet-like sentences each starting with a bold? Actually it's:
What We're Looking For
5+ years in GRC, IT compliance, or information security compliance, ideally in a regulated industry, in hands-on roles rather than oversight or advisory.
Direct experience maintaining an Information Security Management Program or similar compliance program.
Working knowledge of HIPAA, SOC 2, HITRUST, or GDPR; healthcare experience strongly preferred.
Experience working directly with external auditors.
Proven ability to work across a technical organization and up to executive leadership — credible with security engineers and DevSecOps on the details, and able to give management and execs a straight answer on risk without burying it in framework language.
Strong writing skills. You should be comfortable turning operational and technical detail into clear policy language.
Organized and detail-oriented, able to manage several compliance workstreams at once.
A pragmatic approach to risk: you can tell the difference between a real compliance issue and a theoretical one, and you'd rather solve a problem than just document it.
We'll list each as
- .
"Nice to Have" includes:
Nice to Have
CISA, HITRUST CCSFP, or CRISC certification — useful, but we care more about what you've actually run than what you've been certified in.
Experience with AWS, Azure, or GCP and related compliance considerations.
Experience with GRC tooling (e.g., Thoropass, OneTrust, or similar platforms).
A background that spans both compliance and a technical discipline (IT, security, or engineering), so you can speak both languages.
We'll list as
- under Preferred Qualifications.
"What We Offer" includes:
What We Offer
Plenty of opportunities to grow your career
Full benefits package medical, dental, vision, STD, Life benefits
3 weeks of vacation plus 5 personal days to recharge
Employee stock ownership and RRSP program
A chance to give back through community involvement
Flexible work arrangements to suit your lifestyle
We'll list as
- under Benefits.
"Salary Range $130 - 150K" -> Pay section.
"About Us" and "About Harris Computer" paragraphs: we can combine into About the Company.
We need to ensure we don't include boilerplate like "Follow us on social media..." etc. That's in About Harris Computer section: "Working for Harris is the perfect opportunity to fulfill your professional goals as well as achieve your personal dreams! Our employees enjoy a casual work environment that offers comfort while providing superior service to our customers. We offer a comprehensive benefit package as well as other additional “Perks”! We empower our employees to make a differenceWe have an award-winning cultureWe offer opportunity to learnWe are financially strong and we are owned by the largest software company in Canada (CSI)We have fun! Follow us on social media to learn more about our company values, culture and initiatives! Instagram: @weareharrisLinkedIn: Harris Computer"
We need to remove cookie/navigation/legal/EEO/equal-opportunity/scam-warning boilerplate, duplicated lines, and application instructions. The social media links might be considered boilerplate? It's not explicitly listed but it's promotional. Might be okay to keep? The instruction says remove cookie/navigation/legal/EEO/equal-opportunity/scam-warning boilerplate, duplicated lines, and application instructions. Social media links are not those, but could be considered navigation? Probably safe to keep the descriptive parts but remove the actual social media handles? The instruction didn't forbid social media. However to be safe, we could keep the descriptive sentences but drop the "Follow us on social media..." line and the Instagram/LinkedIn lines. We'll keep the rest.
Thus About Harris Computer paragraph: "Working for Harris is the perfect opportunity to fulfill your professional goals as well as achieve your personal dreams! Our employees enjoy a casual work environment that offers comfort while providing superior service to our customers. We offer a comprehensive benefit package as well as other additional “Perks”! We empower our employees to make a differenceWe have an award-winning cultureWe offer opportunity to learnWe are financially strong and we are owned by the largest software company in Canada (CSI)We have fun!" Note there are missing spaces; we can keep as is.
Now we need to output HTML fragment.
Structure:
About the role
We're looking for a Senior GRC Manager to own our GRC program end to end and keep ClearDATA aligned with HIPAA, GDPR, HITRUST, SOC 2, etc. You'll maintain our Information Security Management Program, manage audit cycles, and work directly with auditors, including keeping policy and compliance documentation accurate as our systems and vendors evolve. We want someone who treats compliance as a way to help the business move with confidence, not a set of hoops for other teams to jump through. You'll look for the practical, risk-based path to "yes" whenever one exists, and reserve hard stops for when they're truly warranted. This is a hands-on, senior role on our IT/ITSec team. You won't have direct reports, but you won't be working alone either — you'll have security engineers, DevSecOps, and leadership alongside you. We're looking for someone who'd rather build the control mapping than write a memo about who should build it.
Responsibilities
- Maintain ClearDATA's Information Security Management Program: the policies, procedures, and standards behind our security and compliance posture.
- Support audits, assessments, and certification renewals for HIPAA, GDPR, HITRUST, and SOC 2.
- Maintain the risk register, including tracking third-party and vendor risk.
- Keep control mapping and audit evidence current and organized.
- Support incident response planning alongside the IT/ITSec Manager and security team.
- Partner with security engineers and DevSecOps to translate control requirements into how systems are actually built and operated — and to turn what they've built into defensible audit evidence.
- Update policies and program documentation as systems, vendors, or ownership of shared responsibilities change.
- Work directly with auditors to catch and close compliance gaps before they become findings.
- Flag open risk or outstanding items that need attention.
- Act as the go-to compliance resource across the company — engineering, DevSecOps, management, and executive leadership — helping teams find a workable path forward rather than just pointing at policy, and giving leadership a clear read on where the program stands.
for prose. Do NOT repeat the job title as a heading (the page already shows it) and do NOT put Job ID / requisition numbers as headings — fold minor metadata into a short
or drop it. Preserve ALL substantive information; do NOT invent or summarize away detail. Remove cookie/navigation/legal/EEO/equal-opportunity/scam-warning boilerplate, duplicated lines, and application instructions. IMPORTANT: include a section ONLY when the posting has real, specific content for it — never emit a heading followed by filler/placeholder text (e.g. "commensurate with experience", "not specified", "N/A", "varies", "TBD") and never create Pay/Schedule/Benefits sections unless the posting actually states them. Prefer a few substantive sections over many thin ones. Output ONLY the HTML fragment — no /, no markdown code fences. Thus we need to decide which sections to include based on content. We have: - About the role: The posting starts with "We're looking for a Senior GRC Manager to own our GRC program end to end...". That's a description of role. Could be "About the role". We'll include that. - Responsibilities: The "What You'll Own" section includes bullet points (actually paragraphs). Could be responsibilities. - Requirements: "What We're Looking For" includes requirements. - Qualifications: maybe "Nice to Have" could be qualifications? But we can treat "Nice to Have" as "Preferred Qualifications". However we need to avoid thin sections. Could combine "What We're Looking For" and "Nice to Have" into a single "Requirements" section? But we need to preserve all info. Could have separate sections: "Requirements" and "Preferred Qualifications". Both have content. - Benefits: "What We Offer" includes benefits list. - Pay: "Salary Range $130 - 150K". That's pay. - Schedule: Not mentioned. So we should not create Schedule section. - About Us: "About Us" and "About Harris Computer" could be combined into "About the Company". But we need to decide if we include a section for company overview. The allowed headings list includes About the role, Responsibilities, Requirements, Qualifications, Skills, Benefits, Pay, Schedule. It does not list About Us. However we can still include other headings? The instruction: "use
for section headings (e.g. About the role, Responsibilities, Requirements, Qualifications, Skills, Benefits, Pay, Schedule)." It says e.g., implying those are examples, not exclusive. But we should probably stick to those categories to be safe. However we need to preserve all substantive information. If we omit About Us, we lose info. But maybe we can fold About Us into "About the role" or "Qualifications"? Not ideal. The instruction says "Prefer a few substantive sections over many thin ones." It doesn't forbid other headings, but we should follow the pattern. Could we treat "About Us" as part of "About the role"? Probably not. Better to include a section like "About the Company". The instruction didn't forbid other headings; it just gave examples. So we can include additional headings as needed, as long as they are . We'll include sections: About the role, Responsibilities, Requirements, Preferred Qualifications, Benefits, Pay, About the Company (maybe combine About Us and About Harris Computer). Also maybe "What We Offer" is Benefits.
We need to use - for any list of duties/requirements/benefits. So for responsibilities we should convert each bullet into
- . The "What You'll Own" section includes multiple paragraphs each starting with a bold heading? Actually it's:
What You'll Own
Governance, Risk & Compliance
Maintain ClearDATA's Information Security Management Program: the policies, procedures, and standards behind our security and compliance posture.
Support audits, assessments, and certification renewals for HIPAA, GDPR, HITRUST, and SOC 2.
Maintain the risk register, including tracking third-party and vendor risk.
Keep control mapping and audit evidence current and organized.
Support incident response planning alongside the IT/ITSec Manager and security team.
Partner with security engineers and DevSecOps to translate control requirements into how systems are actually built and operated — and to turn what they've built into defensible audit evidence.
Documentation & Audit Liaison
Update policies and program documentation as systems, vendors, or ownership of shared responsibilities change.
Work directly with auditors to catch and close compliance gaps before they become findings.
Flag open risk or outstanding items that need attention.
Act as the go-to compliance resource across the company — engineering, DevSecOps, management, and executive leadership — helping teams find a workable path forward rather than just pointing at policy, and giving leadership a clear read on where the program stands.
We can treat each line as a duty. Could group under two subheadings but we don't need subheadings; just list.
Similarly "What We're Looking For" includes bullet-like sentences each starting with a bold? Actually it's:
What We're Looking For
5+ years in GRC, IT compliance, or information security compliance, ideally in a regulated industry, in hands-on roles rather than oversight or advisory.
Direct experience maintaining an Information Security Management Program or similar compliance program.
Working knowledge of HIPAA, SOC 2, HITRUST, or GDPR; healthcare experience strongly preferred.
Experience working directly with external auditors.
Proven ability to work across a technical organization and up to executive leadership — credible with security engineers and DevSecOps on the details, and able to give management and execs a straight answer on risk without burying it in framework language.
Strong writing skills. You should be comfortable turning operational and technical detail into clear policy language.
Organized and detail-oriented, able to manage several compliance workstreams at once.
A pragmatic approach to risk: you can tell the difference between a real compliance issue and a theoretical one, and you'd rather solve a problem than just document it.
We'll list each as
- .
"Nice to Have" includes:
Nice to Have
CISA, HITRUST CCSFP, or CRISC certification — useful, but we care more about what you've actually run than what you've been certified in.
Experience with AWS, Azure, or GCP and related compliance considerations.
Experience with GRC tooling (e.g., Thoropass, OneTrust, or similar platforms).
A background that spans both compliance and a technical discipline (IT, security, or engineering), so you can speak both languages.
We'll list as
- under Preferred Qualifications.
"What We Offer" includes:
What We Offer
Plenty of opportunities to grow your career
Full benefits package medical, dental, vision, STD, Life benefits
3 weeks of vacation plus 5 personal days to recharge
Employee stock ownership and RRSP program
A chance to give back through community involvement
Flexible work arrangements to suit your lifestyle
We'll list as
- under Benefits.
"Salary Range $130 - 150K" -> Pay section.
"About Us" and "About Harris Computer" paragraphs: we can combine into About the Company.
We need to ensure we don't include boilerplate like "Follow us on social media..." etc. That's in About Harris Computer section: "Working for Harris is the perfect opportunity to fulfill your professional goals as well as achieve your personal dreams! Our employees enjoy a casual work environment that offers comfort while providing superior service to our customers. We offer a comprehensive benefit package as well as other additional “Perks”! We empower our employees to make a differenceWe have an award-winning cultureWe offer opportunity to learnWe are financially strong and we are owned by the largest software company in Canada (CSI)We have fun! Follow us on social media to learn more about our company values, culture and initiatives! Instagram: @weareharrisLinkedIn: Harris Computer"
We need to remove cookie/navigation/legal/EEO/equal-opportunity/scam-warning boilerplate, duplicated lines, and application instructions. The social media links might be considered boilerplate? It's not explicitly listed but it's promotional. Might be okay to keep? The instruction says remove cookie/navigation/legal/EEO/equal-opportunity/scam-warning boilerplate, duplicated lines, and application instructions. Social media links are not those, but could be considered navigation? Probably safe to keep the descriptive parts but remove the actual social media handles? The instruction didn't forbid social media. However to be safe, we could keep the descriptive sentences but drop the "Follow us on social media..." line and the Instagram/LinkedIn lines. We'll keep the rest.
Thus About Harris Computer paragraph: "Working for Harris is the perfect opportunity to fulfill your professional goals as well as achieve your personal dreams! Our employees enjoy a casual work environment that offers comfort while providing superior service to our customers. We offer a comprehensive benefit package as well as other additional “Perks”! We empower our employees to make a differenceWe have an award-winning cultureWe offer opportunity to learnWe are financially strong and we are owned by the largest software company in Canada (CSI)We have fun!" Note there are missing spaces; we can keep as is.
Now we need to output HTML fragment.
Structure:
About the role
We're looking for a Senior GRC Manager to own our GRC program end to end and keep ClearDATA aligned with HIPAA, GDPR, HITRUST, SOC 2, etc. You'll maintain our Information Security Management Program, manage audit cycles, and work directly with auditors, including keeping policy and compliance documentation accurate as our systems and vendors evolve. We want someone who treats compliance as a way to help the business move with confidence, not a set of hoops for other teams to jump through. You'll look for the practical, risk-based path to "yes" whenever one exists, and reserve hard stops for when they're truly warranted. This is a hands-on, senior role on our IT/ITSec team. You won't have direct reports, but you won't be working alone either — you'll have security engineers, DevSecOps, and leadership alongside you. We're looking for someone who'd rather build the control mapping than write a memo about who should build it.
Responsibilities
- Maintain ClearDATA's Information Security Management Program: the policies, procedures, and standards behind our security and compliance posture.
- Support audits, assessments, and certification renewals for HIPAA, GDPR, HITRUST, and SOC 2.
- Maintain the risk register, including tracking third-party and vendor risk.
- Keep control mapping and audit evidence current and organized.
- Support incident response planning alongside the IT/ITSec Manager and security team.
- Partner with security engineers and DevSecOps to translate control requirements into how systems are actually built and operated — and to turn what they've built into defensible audit evidence.
- Update policies and program documentation as systems, vendors, or ownership of shared responsibilities change.
- Work directly with auditors to catch and close compliance gaps before they become findings.
- Flag open risk or outstanding items that need attention.
- Act as the go-to compliance resource across the company — engineering, DevSecOps, management, and executive leadership — helping teams find a workable path forward rather than just pointing at policy, and giving leadership a clear read on where the program stands.
- for any list of duties/requirements/benefits. So for responsibilities we should convert each bullet into
- . The "What You'll Own" section includes multiple paragraphs each starting with a bold heading? Actually it's: What You'll Own Governance, Risk & Compliance Maintain ClearDATA's Information Security Management Program: the policies, procedures, and standards behind our security and compliance posture. Support audits, assessments, and certification renewals for HIPAA, GDPR, HITRUST, and SOC 2. Maintain the risk register, including tracking third-party and vendor risk. Keep control mapping and audit evidence current and organized. Support incident response planning alongside the IT/ITSec Manager and security team. Partner with security engineers and DevSecOps to translate control requirements into how systems are actually built and operated — and to turn what they've built into defensible audit evidence. Documentation & Audit Liaison Update policies and program documentation as systems, vendors, or ownership of shared responsibilities change. Work directly with auditors to catch and close compliance gaps before they become findings. Flag open risk or outstanding items that need attention. Act as the go-to compliance resource across the company — engineering, DevSecOps, management, and executive leadership — helping teams find a workable path forward rather than just pointing at policy, and giving leadership a clear read on where the program stands. We can treat each line as a duty. Could group under two subheadings but we don't need subheadings; just list. Similarly "What We're Looking For" includes bullet-like sentences each starting with a bold? Actually it's: What We're Looking For 5+ years in GRC, IT compliance, or information security compliance, ideally in a regulated industry, in hands-on roles rather than oversight or advisory. Direct experience maintaining an Information Security Management Program or similar compliance program. Working knowledge of HIPAA, SOC 2, HITRUST, or GDPR; healthcare experience strongly preferred. Experience working directly with external auditors. Proven ability to work across a technical organization and up to executive leadership — credible with security engineers and DevSecOps on the details, and able to give management and execs a straight answer on risk without burying it in framework language. Strong writing skills. You should be comfortable turning operational and technical detail into clear policy language. Organized and detail-oriented, able to manage several compliance workstreams at once. A pragmatic approach to risk: you can tell the difference between a real compliance issue and a theoretical one, and you'd rather solve a problem than just document it. We'll list each as
- . "Nice to Have" includes: Nice to Have CISA, HITRUST CCSFP, or CRISC certification — useful, but we care more about what you've actually run than what you've been certified in. Experience with AWS, Azure, or GCP and related compliance considerations. Experience with GRC tooling (e.g., Thoropass, OneTrust, or similar platforms). A background that spans both compliance and a technical discipline (IT, security, or engineering), so you can speak both languages. We'll list as
- under Preferred Qualifications. "What We Offer" includes: What We Offer Plenty of opportunities to grow your career Full benefits package medical, dental, vision, STD, Life benefits 3 weeks of vacation plus 5 personal days to recharge Employee stock ownership and RRSP program A chance to give back through community involvement Flexible work arrangements to suit your lifestyle We'll list as
- under Benefits.
"Salary Range $130 - 150K" -> Pay section.
"About Us" and "About Harris Computer" paragraphs: we can combine into About the Company.
We need to ensure we don't include boilerplate like "Follow us on social media..." etc. That's in About Harris Computer section: "Working for Harris is the perfect opportunity to fulfill your professional goals as well as achieve your personal dreams! Our employees enjoy a casual work environment that offers comfort while providing superior service to our customers. We offer a comprehensive benefit package as well as other additional “Perks”! We empower our employees to make a differenceWe have an award-winning cultureWe offer opportunity to learnWe are financially strong and we are owned by the largest software company in Canada (CSI)We have fun! Follow us on social media to learn more about our company values, culture and initiatives! Instagram: @weareharrisLinkedIn: Harris Computer"
We need to remove cookie/navigation/legal/EEO/equal-opportunity/scam-warning boilerplate, duplicated lines, and application instructions. The social media links might be considered boilerplate? It's not explicitly listed but it's promotional. Might be okay to keep? The instruction says remove cookie/navigation/legal/EEO/equal-opportunity/scam-warning boilerplate, duplicated lines, and application instructions. Social media links are not those, but could be considered navigation? Probably safe to keep the descriptive parts but remove the actual social media handles? The instruction didn't forbid social media. However to be safe, we could keep the descriptive sentences but drop the "Follow us on social media..." line and the Instagram/LinkedIn lines. We'll keep the rest.
Thus About Harris Computer paragraph: "Working for Harris is the perfect opportunity to fulfill your professional goals as well as achieve your personal dreams! Our employees enjoy a casual work environment that offers comfort while providing superior service to our customers. We offer a comprehensive benefit package as well as other additional “Perks”! We empower our employees to make a differenceWe have an award-winning cultureWe offer opportunity to learnWe are financially strong and we are owned by the largest software company in Canada (CSI)We have fun!" Note there are missing spaces; we can keep as is.
Now we need to output HTML fragment.
Structure:
About the role
We're looking for a Senior GRC Manager to own our GRC program end to end and keep ClearDATA aligned with HIPAA, GDPR, HITRUST, SOC 2, etc. You'll maintain our Information Security Management Program, manage audit cycles, and work directly with auditors, including keeping policy and compliance documentation accurate as our systems and vendors evolve. We want someone who treats compliance as a way to help the business move with confidence, not a set of hoops for other teams to jump through. You'll look for the practical, risk-based path to "yes" whenever one exists, and reserve hard stops for when they're truly warranted. This is a hands-on, senior role on our IT/ITSec team. You won't have direct reports, but you won't be working alone either — you'll have security engineers, DevSecOps, and leadership alongside you. We're looking for someone who'd rather build the control mapping than write a memo about who should build it.
Responsibilities
- Maintain ClearDATA's Information Security Management Program: the policies, procedures, and standards behind our security and compliance posture.
- Support audits, assessments, and certification renewals for HIPAA, GDPR, HITRUST, and SOC 2.
- Maintain the risk register, including tracking third-party and vendor risk.
- Keep control mapping and audit evidence current and organized.
- Support incident response planning alongside the IT/ITSec Manager and security team.
- Partner with security engineers and DevSecOps to translate control requirements into how systems are actually built and operated — and to turn what they've built into defensible audit evidence.
- Update policies and program documentation as systems, vendors, or ownership of shared responsibilities change.
- Work directly with auditors to catch and close compliance gaps before they become findings.
- Flag open risk or outstanding items that need attention.
- Act as the go-to compliance resource across the company — engineering, DevSecOps, management, and executive leadership — helping teams find a workable path forward rather than just pointing at policy, and giving leadership a clear read on where the program stands.