Senior GRC Manager
for section headings. Use - for any list of duties/requirements/benefits. Use
for prose. Do not repeat job title as heading. Do not put Job ID/requisition numbers as headings. Remove boilerplate: cookie/navigation/legal/EEO/equal-opportunity/scam-warning, duplicated lines, application instructions. Also remove social media follow us lines? That's likely boilerplate. Also remove "Follow us on social media..." lines. Also remove "We empower our employees..." maybe part of benefits? It's fluff but could be considered boilerplate. We need to preserve substantive information. So we need to extract meaningful content.
Let's parse the posting:
First paragraph: "We're looking for a Senior GRC Manager to own our GRC program end to end and keep ClearDATA aligned with HIPAA, GDPR, HITRUST, SOC 2, etc. You'll maintain our Information Security Management Program, manage audit cycles, and work directly with auditors, including keeping policy and compliance documentation accurate as our systems and vendors evolve. We want someone who treats compliance as a way to help the business move with confidence, not a set of hoops for other teams to jump through. You'll look for the practical, risk-based path to "yes" whenever one exists, and reserve hard stops for when they're truly warranted. This is a hands-on, senior role on our IT/ITSec team. You won't have direct reports, but you won't be working alone either — you'll have security engineers, DevSecOps, and leadership alongside you. We're looking for someone who'd rather build the control mapping than write a memo about who should build it."
That's the role description. Could be under "About the role" heading.
Then "What You'll Own" with bullet points (actually sentences separated by periods). We'll convert to list.
Then "Documentation & Audit Liaison" subheading? Actually after "What You'll Own" there is a paragraph: "Governance, Risk & Compliance Maintain ClearDATA's Information Security Management Program: the policies, procedures, and standards behind our security and compliance posture.Support audits, assessments, and certification renewals for HIPAA, GDPR, HITRUST, and SOC 2.Maintain the risk register, including tracking third-party and vendor risk.Keep control mapping and audit evidence current and organized.Support incident response planning alongside the IT/ITSec Manager and security team.Partner with security engineers and DevSecOps to translate control requirements into how systems are actually built and operated — and to turn what they've built into defensible audit evidence. Documentation & Audit Liaison Update policies and program documentation as systems, vendors, or ownership of shared responsibilities change.Work directly with auditors to catch and close compliance gaps before they become findings.Flag open risk or outstanding items that need attention.Act as the go-to compliance resource across the company — engineering, DevSecOps, management, and executive leadership — helping teams find a workable path forward rather than just pointing at policy, and giving leadership a clear read on where the program stands."
That seems like a continuation of "What You'll Own" but broken into two sub-sections: Governance, Risk & Compliance and Documentation & Audit Liaison. We could treat them as subheadings? But instruction: use
for section headings (e.g. About the role, Responsibilities, Requirements, Qualifications, Skills, Benefits, Pay, Schedule). So we should map content to those standard headings where applicable. However we can also create custom headings if they match the posting's sections? The instruction says use for section headings (e.g. About the role, Responsibilities, Requirements, Qualifications, Skills, Benefits, Pay, Schedule). It implies we should use those headings when appropriate, but we can also use other headings if they reflect real sections? It says "use for section headings (e.g. About the role, Responsibilities, Requirements, Qualifications, Skills, Benefits, Pay, Schedule)." Likely they want us to use those standard headings for sections we include. But we can also include other headings if they are present? The examples are just examples; they didn't forbid other headings. However they say "Prefer a few substantive sections over many thin ones." So we should combine.
Thus we can have sections: About the role (intro), Responsibilities (What You'll Own), Requirements (What We're Looking For), Nice to Have (maybe under Requirements or separate), Benefits (What We Offer), Pay (Salary Range). Also maybe About the company (About Us, About Harris Computer) could be under "About the company" but not in list. Could be omitted as not required? But we should preserve substantive information. Could include under "About the company" heading (not in list but okay). However they said use for section headings (e.g. About the role, Responsibilities, Requirements, Qualifications, Skills, Benefits, Pay, Schedule). They didn't forbid other headings like About the company. But to be safe, we could include "About the company" as an as it's substantive.
We must not include boilerplate like social media follow us, "We empower our employees..." maybe part of benefits but it's fluff. We'll keep benefits list: "Plenty of opportunities to grow your career", "Full benefits package medical, dental, vision, STD, Life benefits", "3 weeks of vacation plus 5 personal days to recharge", "Employee stock ownership and RRSP program", "A chance to give back through community involvement", "Flexible work arrangements to suit your lifestyle". Also maybe "We have an award-winning culture", "We offer opportunity to learn", "We are financially strong and we are owned by the largest software company in Canada (CSI)", "We have fun!" Those are also benefits/culture. Could include them.
We need to avoid duplication. Also remove "About Harris Computer" maybe part of about company.
Let's craft HTML:
About the role
We're looking for a Senior GRC Manager to own our GRC program end to end and keep ClearDATA aligned with HIPAA, GDPR, HITRUST, SOC 2, etc. You'll maintain our Information Security Management Program, manage audit cycles, and work directly with auditors, including keeping policy and compliance documentation accurate as our systems and vendors evolve. We want someone who treats compliance as a way to help the business move with confidence, not a set of hoops for other teams to jump through. You'll look for the practical, risk-based path to "yes" whenever one exists, and reserve hard stops for when they're truly warranted. This is a hands-on, senior role on our IT/ITSec team. You won't have direct reports, but you won't be working alone either — you'll have security engineers, DevSecOps, and leadership alongside you. We're looking for someone who'd rather build the control mapping than write a memo about who should build it.
Responsibilities
- Maintain ClearDATA's Information Security Management Program: the policies, procedures, and standards behind our security and compliance posture.
- Support audits, assessments, and certification renewals for HIPAA, GDPR, HITRUST, and SOC 2.
- Maintain the risk register, including tracking third-party and vendor risk.
- Keep control mapping and audit evidence current and organized.
- Support incident response planning alongside the IT/ITSec Manager and security team.
- Partner with security engineers and DevSecOps to translate control requirements into how systems are actually built and operated — and to turn what they've built into defensible audit evidence.
- Update policies and program documentation as systems, vendors, or ownership of shared responsibilities change.
- Work directly with auditors to catch and close compliance gaps before they become findings.
- Flag open risk or outstanding items that need attention.
- Act as the go-to compliance resource across the company — engineering, DevSecOps, management, and executive leadership — helping teams find a workable path forward rather than just pointing at policy, and giving leadership a clear read on where the program stands.
Requirements
- 5+ years in GRC, IT compliance, or information security compliance, ideally in a regulated industry, in hands-on roles rather than oversight or advisory.
- Direct experience maintaining an Information Security Management Program or similar compliance program.
- Working knowledge of HIPAA, SOC 2, HITRUST, or GDPR; healthcare experience strongly preferred.
- Experience working directly with external auditors.
- Proven ability to work across a technical organization and up to executive leadership — credible with security engineers and DevSecOps on the details, and able to give management and execs a straight answer on risk without burying it in framework language.
- Strong writing skills. You should be comfortable turning operational and technical detail into clear policy language.
- Organized and detail-oriented, able to manage several compliance workstreams at once.
- A pragmatic approach to risk: you can tell the difference between a real compliance issue and a theoretical one, and you'd rather solve a problem than just document it.
Nice to Have
- CISA, HITRUST CCSFP, or CRISC certification — useful, but we care more about what you've actually run than what you've been certified in.
- Experience with AWS, Azure, or GCP and related compliance considerations.
- Experience with GRC tooling (e.g., Thoropass, OneTrust, or similar platforms).
- A background that spans both compliance and a technical discipline (IT, security, or engineering), so you can speak both languages.
About the company
Established in 2009, ClearDATA was born out of a need to address significant inefficiencies within the U.S. healthcare system. From slow data processing to security concerns, these challenges often stood between patients and timely and effective care. As the healthcare industry began to embrace the public cloud, technology leaders faced a new set of challenges. Organizations found themselves navigating the fast-paced world of cloud innovations, regulatory compliance changes, and looming cyber threats. ClearDATA’s founders understood the complexities involved this highly-regulated industry and created the first cloud compliance and security solution exclusively for healthcare.
Harris provides mission critical software solutions for the Public Sector, Healthcare, Utilities and Private Sector verticals throughout North America, Europe, Asia and Australia. Working for Harris is the perfect opportunity to fulfill your professional goals as well as achieve your personal dreams! Our employees enjoy a casual work environment that offers comfort while providing superior service to our customers. We offer a comprehensive benefit package as well as other additional “Perks”! We empower our employees to make a difference, we have an award-winning culture, we offer opportunity to learn, we are financially strong and we are owned by the largest software company in Canada (CSI), we have fun!
Benefits
- Plenty of opportunities to grow your career
- Full benefits package medical, dental, vision, STD, Life benefits
- 3 weeks of vacation plus 5 personal days to recharge
- Employee stock ownership and RRSP program
- A chance to give back through community involvement
- Flexible work arrangements to suit your lifestyle
- Award-winning culture
- Opportunity to learn
- Financially strong, owned by the largest software company in Canada (CSI)
for prose. Do not repeat job title as heading. Do not put Job ID/requisition numbers as headings. Remove boilerplate: cookie/navigation/legal/EEO/equal-opportunity/scam-warning, duplicated lines, application instructions. Also remove social media follow us lines? That's likely boilerplate. Also remove "Follow us on social media..." lines. Also remove "We empower our employees..." maybe part of benefits? It's fluff but could be considered boilerplate. We need to preserve substantive information. So we need to extract meaningful content. Let's parse the posting: First paragraph: "We're looking for a Senior GRC Manager to own our GRC program end to end and keep ClearDATA aligned with HIPAA, GDPR, HITRUST, SOC 2, etc. You'll maintain our Information Security Management Program, manage audit cycles, and work directly with auditors, including keeping policy and compliance documentation accurate as our systems and vendors evolve. We want someone who treats compliance as a way to help the business move with confidence, not a set of hoops for other teams to jump through. You'll look for the practical, risk-based path to "yes" whenever one exists, and reserve hard stops for when they're truly warranted. This is a hands-on, senior role on our IT/ITSec team. You won't have direct reports, but you won't be working alone either — you'll have security engineers, DevSecOps, and leadership alongside you. We're looking for someone who'd rather build the control mapping than write a memo about who should build it." That's the role description. Could be under "About the role" heading. Then "What You'll Own" with bullet points (actually sentences separated by periods). We'll convert to list. Then "Documentation & Audit Liaison" subheading? Actually after "What You'll Own" there is a paragraph: "Governance, Risk & Compliance Maintain ClearDATA's Information Security Management Program: the policies, procedures, and standards behind our security and compliance posture.Support audits, assessments, and certification renewals for HIPAA, GDPR, HITRUST, and SOC 2.Maintain the risk register, including tracking third-party and vendor risk.Keep control mapping and audit evidence current and organized.Support incident response planning alongside the IT/ITSec Manager and security team.Partner with security engineers and DevSecOps to translate control requirements into how systems are actually built and operated — and to turn what they've built into defensible audit evidence. Documentation & Audit Liaison Update policies and program documentation as systems, vendors, or ownership of shared responsibilities change.Work directly with auditors to catch and close compliance gaps before they become findings.Flag open risk or outstanding items that need attention.Act as the go-to compliance resource across the company — engineering, DevSecOps, management, and executive leadership — helping teams find a workable path forward rather than just pointing at policy, and giving leadership a clear read on where the program stands." That seems like a continuation of "What You'll Own" but broken into two sub-sections: Governance, Risk & Compliance and Documentation & Audit Liaison. We could treat them as subheadings? But instruction: use
for section headings (e.g. About the role, Responsibilities, Requirements, Qualifications, Skills, Benefits, Pay, Schedule). So we should map content to those standard headings where applicable. However we can also create custom headings if they match the posting's sections? The instruction says use for section headings (e.g. About the role, Responsibilities, Requirements, Qualifications, Skills, Benefits, Pay, Schedule). It implies we should use those headings when appropriate, but we can also use other headings if they reflect real sections? It says "use for section headings (e.g. About the role, Responsibilities, Requirements, Qualifications, Skills, Benefits, Pay, Schedule)." Likely they want us to use those standard headings for sections we include. But we can also include other headings if they are present? The examples are just examples; they didn't forbid other headings. However they say "Prefer a few substantive sections over many thin ones." So we should combine.
Thus we can have sections: About the role (intro), Responsibilities (What You'll Own), Requirements (What We're Looking For), Nice to Have (maybe under Requirements or separate), Benefits (What We Offer), Pay (Salary Range). Also maybe About the company (About Us, About Harris Computer) could be under "About the company" but not in list. Could be omitted as not required? But we should preserve substantive information. Could include under "About the company" heading (not in list but okay). However they said use for section headings (e.g. About the role, Responsibilities, Requirements, Qualifications, Skills, Benefits, Pay, Schedule). They didn't forbid other headings like About the company. But to be safe, we could include "About the company" as an as it's substantive.
We must not include boilerplate like social media follow us, "We empower our employees..." maybe part of benefits but it's fluff. We'll keep benefits list: "Plenty of opportunities to grow your career", "Full benefits package medical, dental, vision, STD, Life benefits", "3 weeks of vacation plus 5 personal days to recharge", "Employee stock ownership and RRSP program", "A chance to give back through community involvement", "Flexible work arrangements to suit your lifestyle". Also maybe "We have an award-winning culture", "We offer opportunity to learn", "We are financially strong and we are owned by the largest software company in Canada (CSI)", "We have fun!" Those are also benefits/culture. Could include them.
We need to avoid duplication. Also remove "About Harris Computer" maybe part of about company.
Let's craft HTML:
About the role
for section headings (e.g. About the role, Responsibilities, Requirements, Qualifications, Skills, Benefits, Pay, Schedule)." Likely they want us to use those standard headings for sections we include. But we can also include other headings if they are present? The examples are just examples; they didn't forbid other headings. However they say "Prefer a few substantive sections over many thin ones." So we should combine.
Thus we can have sections: About the role (intro), Responsibilities (What You'll Own), Requirements (What We're Looking For), Nice to Have (maybe under Requirements or separate), Benefits (What We Offer), Pay (Salary Range). Also maybe About the company (About Us, About Harris Computer) could be under "About the company" but not in list. Could be omitted as not required? But we should preserve substantive information. Could include under "About the company" heading (not in list but okay). However they said use for section headings (e.g. About the role, Responsibilities, Requirements, Qualifications, Skills, Benefits, Pay, Schedule). They didn't forbid other headings like About the company. But to be safe, we could include "About the company" as an as it's substantive.
We must not include boilerplate like social media follow us, "We empower our employees..." maybe part of benefits but it's fluff. We'll keep benefits list: "Plenty of opportunities to grow your career", "Full benefits package medical, dental, vision, STD, Life benefits", "3 weeks of vacation plus 5 personal days to recharge", "Employee stock ownership and RRSP program", "A chance to give back through community involvement", "Flexible work arrangements to suit your lifestyle". Also maybe "We have an award-winning culture", "We offer opportunity to learn", "We are financially strong and we are owned by the largest software company in Canada (CSI)", "We have fun!" Those are also benefits/culture. Could include them.
We need to avoid duplication. Also remove "About Harris Computer" maybe part of about company.
Let's craft HTML:
About the role
as it's substantive.
We must not include boilerplate like social media follow us, "We empower our employees..." maybe part of benefits but it's fluff. We'll keep benefits list: "Plenty of opportunities to grow your career", "Full benefits package medical, dental, vision, STD, Life benefits", "3 weeks of vacation plus 5 personal days to recharge", "Employee stock ownership and RRSP program", "A chance to give back through community involvement", "Flexible work arrangements to suit your lifestyle". Also maybe "We have an award-winning culture", "We offer opportunity to learn", "We are financially strong and we are owned by the largest software company in Canada (CSI)", "We have fun!" Those are also benefits/culture. Could include them.
We need to avoid duplication. Also remove "About Harris Computer" maybe part of about company.
Let's craft HTML:
About the role
We're looking for a Senior GRC Manager to own our GRC program end to end and keep ClearDATA aligned with HIPAA, GDPR, HITRUST, SOC 2, etc. You'll maintain our Information Security Management Program, manage audit cycles, and work directly with auditors, including keeping policy and compliance documentation accurate as our systems and vendors evolve. We want someone who treats compliance as a way to help the business move with confidence, not a set of hoops for other teams to jump through. You'll look for the practical, risk-based path to "yes" whenever one exists, and reserve hard stops for when they're truly warranted. This is a hands-on, senior role on our IT/ITSec team. You won't have direct reports, but you won't be working alone either — you'll have security engineers, DevSecOps, and leadership alongside you. We're looking for someone who'd rather build the control mapping than write a memo about who should build it.
Responsibilities
- Maintain ClearDATA's Information Security Management Program: the policies, procedures, and standards behind our security and compliance posture.
- Support audits, assessments, and certification renewals for HIPAA, GDPR, HITRUST, and SOC 2.
- Maintain the risk register, including tracking third-party and vendor risk.
- Keep control mapping and audit evidence current and organized.
- Support incident response planning alongside the IT/ITSec Manager and security team.
- Partner with security engineers and DevSecOps to translate control requirements into how systems are actually built and operated — and to turn what they've built into defensible audit evidence.
- Update policies and program documentation as systems, vendors, or ownership of shared responsibilities change.
- Work directly with auditors to catch and close compliance gaps before they become findings.
- Flag open risk or outstanding items that need attention.
- Act as the go-to compliance resource across the company — engineering, DevSecOps, management, and executive leadership — helping teams find a workable path forward rather than just pointing at policy, and giving leadership a clear read on where the program stands.
Requirements
- 5+ years in GRC, IT compliance, or information security compliance, ideally in a regulated industry, in hands-on roles rather than oversight or advisory.
- Direct experience maintaining an Information Security Management Program or similar compliance program.
- Working knowledge of HIPAA, SOC 2, HITRUST, or GDPR; healthcare experience strongly preferred.
- Experience working directly with external auditors.
- Proven ability to work across a technical organization and up to executive leadership — credible with security engineers and DevSecOps on the details, and able to give management and execs a straight answer on risk without burying it in framework language.
- Strong writing skills. You should be comfortable turning operational and technical detail into clear policy language.
- Organized and detail-oriented, able to manage several compliance workstreams at once.
- A pragmatic approach to risk: you can tell the difference between a real compliance issue and a theoretical one, and you'd rather solve a problem than just document it.
Nice to Have
- CISA, HITRUST CCSFP, or CRISC certification — useful, but we care more about what you've actually run than what you've been certified in.
- Experience with AWS, Azure, or GCP and related compliance considerations.
- Experience with GRC tooling (e.g., Thoropass, OneTrust, or similar platforms).
- A background that spans both compliance and a technical discipline (IT, security, or engineering), so you can speak both languages.
About the company
Established in 2009, ClearDATA was born out of a need to address significant inefficiencies within the U.S. healthcare system. From slow data processing to security concerns, these challenges often stood between patients and timely and effective care. As the healthcare industry began to embrace the public cloud, technology leaders faced a new set of challenges. Organizations found themselves navigating the fast-paced world of cloud innovations, regulatory compliance changes, and looming cyber threats. ClearDATA’s founders understood the complexities involved this highly-regulated industry and created the first cloud compliance and security solution exclusively for healthcare.
Harris provides mission critical software solutions for the Public Sector, Healthcare, Utilities and Private Sector verticals throughout North America, Europe, Asia and Australia. Working for Harris is the perfect opportunity to fulfill your professional goals as well as achieve your personal dreams! Our employees enjoy a casual work environment that offers comfort while providing superior service to our customers. We offer a comprehensive benefit package as well as other additional “Perks”! We empower our employees to make a difference, we have an award-winning culture, we offer opportunity to learn, we are financially strong and we are owned by the largest software company in Canada (CSI), we have fun!
Benefits
- Plenty of opportunities to grow your career
- Full benefits package medical, dental, vision, STD, Life benefits
- 3 weeks of vacation plus 5 personal days to recharge
- Employee stock ownership and RRSP program
- A chance to give back through community involvement
- Flexible work arrangements to suit your lifestyle
- Award-winning culture
- Opportunity to learn
- Financially strong, owned by the largest software company in Canada (CSI)