Jobs · OTHR · South Carolina

Senior GRC Manager

Harris Computer · South Carolina, United States · 2 days ago
OTHR$130/hrFull-time
We need to output HTML fragment with sections: About the role? Actually the posting includes sections: "What You'll Own", "What We're Looking For", "Nice to Have", "Why ClearDATA", "About Us", "About Harris Computer", "What We Offer", "Salary Range". Also maybe "Governance, Risk & Compliance" etc. But we need to follow rules: use

for section headings (e.g. About the role, Responsibilities, Requirements, Qualifications, Skills, Benefits, Pay, Schedule). We should map content to appropriate headings. The posting includes many sections; we need to decide which headings to use based on content. The instruction: "Prefer a few substantive sections over many thin ones." So we can combine similar content. We must not repeat job title as heading. No Job ID etc. Remove boilerplate: cookie/navigation/legal/EEO etc. There's none. We need to preserve all substantive info. Use
  • for any list of duties/requirements/benefits. Use

    for prose. We need sections only when posting has real specific content. So we need sections like About the role (maybe summary), Responsibilities (What You'll Own), Requirements (What We're Looking For + Nice to Have?), Skills maybe, Benefits (What We Offer), Pay (Salary Range), Schedule maybe not present (so omit). Also maybe Qualifications. We need to avoid filler like "commensurate with experience". Not present. Let's extract content. Job description: "We're looking for a Senior GRC Manager to own our GRC program end to end and keep ClearDATA aligned with HIPAA, GDPR, HITRUST, SOC 2, etc. You'll maintain our Information Security Management Program, manage audit cycles, and work directly with auditors, including keeping policy and compliance documentation accurate as our systems and vendors evolve. We want someone who treats compliance as a way to help the business move with confidence, not a set of hoops for other teams to jump through. You'll look for the practical, risk-based path to "yes" whenever one exists, and reserve hard stops for when they're truly warranted. This is a hands-on, senior role on our IT/ITSec team. You won't have direct reports, but you won't be working alone either — you'll have security engineers, DevSecOps, and leadership alongside you. We're looking for someone who'd rather build the control mapping than write a memo about who should build it." That's a good intro; could be About the role. Then "What You'll Own" with bullet list: - Governance, Risk & Compliance - Maintain ClearDATA's Information Security Management Program: the policies, procedures, and standards behind our security and compliance posture. - Support audits, assessments, and certification renewals for HIPAA, GDPR, HITRUST, and SOC 2. - Maintain the risk register, including tracking third-party and vendor risk. - Keep control mapping and audit evidence current and organized. - Support incident response planning alongside the IT/ITSec Manager and security team. - Partner with security engineers and DevSecOps to translate control requirements into how systems are actually built and operated — and to turn what they've built into defensible audit evidence. - Documentation & Audit Liaison - Update policies and program documentation as systems, vendors, or ownership of shared responsibilities change. - Work directly with auditors to catch and close compliance gaps before they become findings. - Flag open risk or outstanding items that need attention. - Act as the go-to compliance resource across the company — engineering, DevSecOps, management, and executive leadership — helping teams find a workable path forward rather than just pointing at policy, and giving leadership a clear read on where the program stands. That's responsibilities. Then "What We're Looking For": - 5+ years in GRC, IT compliance, or information security compliance, ideally in a regulated industry, in hands-on roles rather than oversight or advisory. - Direct experience maintaining an Information Security Management Program or similar compliance program. - Working knowledge of HIPAA, SOC 2, HITRUST, or GDPR; healthcare experience strongly preferred. - Experience working directly with external auditors. - Proven ability to work across a technical organization and up to executive leadership — credible with security engineers and DevSecOps on the details, and able to give management and execs a straight answer on risk without burying it in framework language. - Strong writing skills. You should be comfortable turning operational and technical detail into clear policy language. - Organized and detail-oriented, able to manage several compliance workstreams at once. - A pragmatic approach to risk: you can tell the difference between a real compliance issue and a theoretical one, and you'd rather solve a problem than just document it. Then "Nice to Have": - CISA, HITRUST CCSFP, or CRISC certification — useful, but we care more about what you've actually run than what you've been certified in. - Experience with AWS, Azure, or GCP and related compliance considerations. - Experience with GRC tooling (e.g., Thoropass, OneTrust, or similar platforms). - A background that spans both compliance and a technical discipline (IT, security, or engineering), so you can speak both languages. Then "Why ClearDATA": description about owning GRC program that matters, security/compliance are product. Then "About Us": history. Then "About Harris Computer": description. Then "What We Offer": list: - Plenty of opportunities to grow your career - Full benefits package medical, dental, vision, STD, Life benefits - 3 weeks of vacation plus 5 personal days to recharge - Employee stock ownership and RRSP program - A chance to give back through community involvement - Flexible work arrangements to suit your lifestyle Then "Salary Range $130 - 150K" We need to output HTML fragment with headings

    . Use sections: About the role (intro), Responsibilities (What You'll Own), Requirements (What We're Looking For + Nice to Have maybe combined?), Benefits (What We Offer), Pay (Salary Range). Could also have Qualifications but we can merge. We must not create sections with filler. Ensure each heading has substantive content. We'll produce:

    About the role

    ... intro paragraph(s) ...

    Responsibilities

    • ... each bullet ...

    Requirements

    • ... required qualifications ...
    Maybe separate Nice to Have as a subsection? Could be under Requirements as a separate

    Preferred Qualifications

    . But instruction: prefer few substantive sections over many thin ones. Could combine required and nice-to-have into one Requirements section with subheadings? But we cannot use other headings besides

    . Could embed nice-to-have as a

    within Requirements? But they said use

    • for any list of duties/requirements/benefits. So we could have two lists: one for Required, one for Preferred. Could wrap each in its own

      maybe "Required Qualifications" and "Preferred Qualifications". That's two sections; still okay. But we also have Benefits and Pay. Thus sections: About the role, Responsibilities, Required Qualifications, Preferred Qualifications, Benefits, Pay. Check if any content for Schedule: none, omit. Now ensure we preserve all substantive info. Need to include details about ClearDATA, About Us, About Harris Computer. Those are substantive but maybe could be placed under About the role or a separate section "About the Company". The instruction: we can have sections like About the role, Responsibilities, Requirements, Qualifications, Skills, Benefits, Pay, Schedule. But we can also add other headings if they are substantive? The examples given are just examples; we can use other headings as long as they are

      . The rule: "use

      for section headings (e.g. About the role, Responsibilities, Requirements, Qualifications, Skills, Benefits, Pay, Schedule)." It suggests those are typical but not exclusive. We can add others like "About ClearDATA" etc. Probably okay. We need to preserve all substantive info: includes About Us, About Harris Computer, Why ClearDATA. We could combine them into a section "About the Company". Let's do that. Thus sections: - About the role (intro) - Responsibilities - Required Qualifications - Preferred Qualifications - Benefits - Pay - About the Company (combining Why ClearDATA, About Us, About Harris Computer) Check if any duplication: The intro already mentions some of that; but we keep. Now craft HTML. We need to ensure no markdown fences, just raw HTML. Let's write. First, About the role paragraph: combine the introductory paragraph(s). Might be two paragraphs: first sentence about looking for Senior GRC Manager, second about maintaining ISMP, etc. We'll combine into one

      maybe multiple

      allowed? The rule: use

      for prose. Could have multiple

      under same section. We'll do multiple

      if needed. But we can also put all in one

      with line breaks? Better to split logically. We'll do:

      About the role

      We're looking for a Senior GRC Manager to own our GRC program end to end and keep ClearDATA aligned with HIPAA, GDPR, HITRUST, SOC 2, etc. You'll maintain our Information Security Management Program, manage audit cycles, and work directly with auditors, including keeping policy and compliance documentation accurate as our systems and vendors evolve.

      We want someone who treats compliance as a way to help the business move with confidence, not a set of hoops for other teams to jump through. You'll look for the practical, risk-based path to "yes" whenever one exists, and reserve hard stops for when they're truly warranted. This is a hands-on, senior role on our IT/ITSec team. You won't have direct reports, but you won't be working alone either — you'll have security engineers, DevSecOps, and leadership alongside you. We're looking for someone who'd rather build the control mapping than write a memo about who should build it.

      Now Responsibilities: list each bullet. We need to capture all bullet points from "What You'll Own". Let's list them: - Governance, Risk & Compliance - Maintain ClearDATA's Information Security Management Program: the policies, procedures, and standards behind our security and compliance posture. - Support audits, assessments, and certification renewals for HIPAA, GDPR, HITRUST, and SOC 2. - Maintain the risk register, including tracking third-party and vendor risk. - Keep control mapping and audit evidence current and organized. - Support incident response planning alongside the IT/ITSec Manager and security team. - Partner with security engineers and DevSecOps to translate control requirements into how systems are actually built and operated — and to turn what they've built into defensible audit evidence. - Documentation & Audit Liaison - Update policies and program documentation as systems, vendors, or ownership of shared responsibilities change. - Work directly with auditors to catch and close compliance gaps before they become findings. - Flag open risk or outstanding items that need attention. - Act as the go-to compliance resource across the company — engineering, DevSecOps, management, and executive leadership — helping teams find a workable path forward rather than just pointing at policy, and giving leadership a clear read on where the program stands. Note that "Governance, Risk & Compliance" and "Documentation & Audit Liaison" are headings within the list; we can treat them as list items as well. We'll create
        with
      • for each. Now Required Qualifications: list from "What We're Looking For". Items: - 5+ years in GRC, IT compliance, or information security compliance, ideally in a regulated industry, in hands-on roles rather than oversight or advisory. - Direct experience maintaining an Information Security Management Program or similar compliance program. - Working knowledge of HIPAA, SOC 2, H

Similar jobs

Senior GRC Manager

Harris ComputerNebraska, United States· 2 days ago
OTHR$130/hrapply on harriscomputer.wd3.myworkdayjobs.com

Senior GRC Manager

Harris ComputerMinnesota, United States· 2 days ago
OTHR$130/hrapply on harriscomputer.wd3.myworkdayjobs.com

Senior GRC Manager

Harris ComputerNevada, United States· 2 days ago
OTHR$130/hrapply on harriscomputer.wd3.myworkdayjobs.com

Senior GRC Manager

Harris ComputerMassachusetts, United States· 2 days ago
OTHR$130/hrapply on harriscomputer.wd3.myworkdayjobs.com

Senior GRC Manager

Harris ComputerNew Hampshire, United States· 2 days ago
OTHR$130/hrapply on harriscomputer.wd3.myworkdayjobs.com

Senior GRC Manager

Harris ComputerMissouri, United States· 2 days ago
OTHR$130/hrapply on harriscomputer.wd3.myworkdayjobs.com