À propos de ce poste GRC Manager chez Nabla
About Nabla
We are a team of entrepreneurs, clinicians and engineers committed to bringing back joy to the practice of medicine.
Together with a community of clinician innovators, we’ve harnessed the best of machine learning science to develop Nabla: the leading AI assistant that’s restoring the human connection at the heart of healthcare. By streamlining clinical documentation, Nabla is helping clinicians focus on what matters most - patient care. Today, over 100,000+ clinicians across 130+ healthcare organizations trust Nabla to support how they deliver care every day.
We’re at the start of an ambitious journey: Ambient listening, dictation, coding, and command capabilities are all converging into a proactive assistant that intuitively streamlines clinical and financial workflows.
Backed by a recent $70M Series C, we’re hiring to build the next generation of clinical AI and improve the lives of clinicians and patients everywhere.
This is a great time to join us!
The Role
As our GRC Manager, you'll play a key role in scaling Nabla's security and compliance programs as we continue to grow. In this highly cross-functional role, you'll partner with Security, Engineering, Product, Legal, and customer-facing teams to build and mature our governance, risk, and compliance programs that enable the business to scale securely. This is an opportunity to shape foundational security processes, support enterprise growth, and help maintain the trust of clinicians, healthcare organizations, and partners.
Responsibilities
Reporting to the Head of Information Security & Compliance, you will work alongside Security, Engineering, Product and Legal teams to mature Nabla’s Governance, Risk & Compliance programs
Manage the GRC control evidence library including investigation of control flags and evidence collection
Manage the vendor risk program including intake of new vendor requests, security and risk assessments, periodic reviews and ongoing vendor monitoring
Review and interpret security assurance artifacts such as SOC 2 Type II reports, penetration test reports, CAIQ, SIG, ISO certifications, and other compliance attestations
Assist the Head of Information Security with the implementation and ongoing operation of security and risk management frameworks, including net new control additions (e.g., GDPR, ISO, SOC 2)
Assist the Head of Information Security with security questionnaires and client audits including management of knowledge base and tracking
Support cyber GRC activities, including tracking information security risks, risk exceptions, and remediation plans
Manage security/compliance onboarding requirements including security awareness training, access checklists, and quarterly access reviews
Assist with the administration and continuous improvement of the company’s security awareness and training program, including tracking completion metrics and updating training content as needed
Own the ongoing review and maintenance of organizational security policies, standards, and procedures. Assist in identifying policy gaps based on evolving regulatory requirements, business needs, and industry best practices
Qualifications
4+ years of experience in GRC, Information Security, or a closely related function — with meaningful time spent building or scaling programs, not just running them
Demonstrated hands-on experience in GRC program at scale — ideally in a high-growth SaaS or technology company
Experience working with GRC platforms and tooling to manage compliance activities, risk registers, policy lifecycle management, audit evidence collection, and workflow automation
Deep expertise across multiple compliance and security frameworks, including SOC 2 Type II, ISO 27001
Healthcare experience preferred - HIPAA background and understanding of controls
Experience conducting and managing product & enterprise risk assessments, with a working knowledge of risk quantification methodologies
AI forward individual who will look to automate manual processes today
Relevant certifications strongly preferred: CISM, CRISC, CISA, CCSP, or comparable credentials
Benefits
Just like we’re dedicated to supporting doctors’ well-being, ensuring yours is a top priority. We firmly believe that by prioritizing your well-being, we support you to excel in your work.
Here are the benefits you get when joining Nabla:
Compensation and Equity: Competitive salary and stock options
Comprehensive Health Plans: 100% individual coverage for Medical, Dental, and Vision insurance
Time Off: Unlimited paid time off and 11 national holidays
Health Comes First: Unlimited sick leave
Parental Leave: Paid leave for new parents
Remote-friendly: $1,000 to purchase home office equipment
Trust & accountability: Full ownership of your time and schedule
Life at Nabla
When you become a part of our company, you join a team of excellence-driven, curious, and genuinely kind individuals. Together, we're committed to making clinicians' lives easier and improving healthcare experiences for everyone. We believe in a world where clinicians can focus on what they were trained to do - caring for their patients, and where no patient feels their visit was rushed.
We come to work excited to leverage AI to do more for clinicians. We’re obsessed with our users’ satisfaction and we actively seek out opportunities to engage one-on-one with clinicians to understand how Nabla can better help. We consistently look for ways to improve and do not shy away from doing the work to excel. Whether it’s a feature our users asked for, or a new article for our blog, we prioritize collaboration to deliver exceptional outcomes.
We love having fun as much as we love work. Our #nablabla channel is as active as our #feature-show-off channel, we exercise during the work day at least 3 times a week (yoga, running, pilates, or HIIT, your choice!), enjoy regular off-sites to gather the team, and travel to see each other in places like NY, Paris, San Francisco, and many other vibrant cities. Oh, and we’re constantly snacking on chocolate or nuts!
If this sounds like an environment you’ll thrive in, we look forward to reading your application!
Our Values at Nabla
Joining Nabla means being part of a team that shares a commitment to excellence, humility, growth, and inclusion.
Every day is a new chance to excel
We aim for nothing less than the best and are willing to put in the effort and dedication required to exceed standards. We learn from yesterday’s failures and do better every day.
Stay humble
There’s no place for ego in our team. Our collective success is more important than individual achievements. We see humility as wisdom — keeping focus on the bigger picture.
Feedback is a gift
We embrace feedback and foster a culture of trust and respect that helps everyone grow. We communicate openly about both achievements and challenges, and we actively involve each other in finding solutions.
Committed to diversity
We recognize the ongoing challenge of diversity in tech. Our responsibility starts with fostering an inclusive environment where everyone feels empowered to be their authentic selves and do their best work.
Diversity & Inclusion
Diversity and inclusivity are fundamental values at Nabla. We embrace individuals from various backgrounds, including race, gender, educational history, sexual orientation, and beyond.
As an equal opportunity employer, we actively seek out and welcome applicants from diverse backgrounds, believing that a wide range of perspectives enriches our team and enhances our ability to innovate and thrive.
Avoid recruitment scams: Stay safe and informed
There is an active employment scam which is now using Nabla to collect personal information or financial scams. If you’re contacted by a Nabla recruiter, please ensure whomever is contacting you truly represents Nabla and is utilizing a nabla.com email address. We will never ask for the exchange of any money or credit card details during the recruitment process. Nabla utilizes a hiring platform for all applications; please be aware of any suspicious email activity from people who could be pretending to be recruiters or senior professionals at Nabla. You can find more information following this link.
Nabla does not accept unsolicited CVs from recruiters or employment agencies in response to the Nabla Careers page or a Nabla social media post. Any unsolicited CVs, including those submitted directly to hiring managers, are deemed to be the property of Nabla.