Headway
Headway4h ago
New

Senior Governance, Risk, Compliance (GRC) Analyst

Grc AnalystCybersecurity
0 views0 saves0 applied

Quick Summary

Key Responsibilities

HITRUST, SOC 2, PCI-DSS, or HIPAA. You've used a GRC platform like Vanta, Drata, OneTrust, or similar to automate evidence collection or manage controls. You communicate compliance

Requirements Summary

you've worked in healthcare or healthtech and understand what HIPAA means in practice, not just in theory.

Technical Tools
Grc AnalystCybersecurity

1 in 4 people in the US have a treatable mental health condition, but most providers don't accept insurance, making therapy too expensive for most people. Headway’s mission is to fix this by building a new mental healthcare system everyone can access. We started by solving the biggest barrier to care: insurance. The admin work - credentialing, claims, payment reconciliation - is a nightmare. We've automated that.

But we're going further. Over 70,000 providers across all 50 states run their practice on our software, serving over 1 million patients. We are building the best tools for therapists to run their entire practice, reimagining the experience of finding a therapist, and investing in the platform foundations to enable this at scale. We aren't just a billing layer; we are becoming the platform where care actually happens.

We're a Series D company with $325M+ in funding (a16z, Accel, GV, etc.), looking for exceptional people to help us achieve this mission. We want your time here to be the most meaningful experience of your career. Join us, and help change mental healthcare for the better.

About the Role

~1 min read

Headway handles sensitive health data for millions of patients — and that responsibility demands a security and compliance program that scales with the business. We're building out our dedicated GRC team to improve and mature our program!

You'll join the Security team and work across four pillars: security certifications (HITRUST, SOC 2, PCI-DSS, HIPAA), third-party risk management, security awareness training, and technical risk management. You won't be maintaining a stale compliance program — you'll be building a modern, AI-enabled one at a company that's transforming how mental healthcare is delivered in the United States.

This role reports to Blake Atkinson, Director of Security, and partners closely with Privacy and Engineering teams.

  • Support HITRUST, SOC 2, PCI-DSS, and HIPAA audit readiness — collecting evidence, coordinating with assessors, tracking control gaps and remediation timelines.
  • Build and manage the vendor security assessment lifecycle — questionnaires, SOC 2/ISO reviews, risk scoring, and policy enforcement across procurement and renewals.
  • Stand up and run Headway's security awareness training program — onboarding modules, phishing simulations, annual compliance training, and completion tracking.
  • Operate the centralized risk register — identifying, assessing, and tracking technical security risks through mitigation, and surfacing risk-informed priorities to engineering and security leadership.
  • Partner cross-functionally with Privacy, Legal, IT, and Engineering to embed compliance into how Headway operates — not bolt it on after the fact.
  • You have 5+ years of experience in a GRC, compliance, or security risk role.
  • You have working knowledge of at least two of: HITRUST, SOC 2, PCI-DSS, or HIPAA.
  • You've used a GRC platform like Vanta, Drata, OneTrust, or similar to automate evidence collection or manage controls.
  • You communicate compliance requirements clearly to both technical and non-technical audiences.
  • You default to building repeatable processes over one-off heroics.
  • You're excited about using AI and modern tooling to scale compliance operations.
  • Bonus: you've worked in healthcare or healthtech and understand what HIPAA means in practice, not just in theory.
  • Mission that matters — your work directly protects millions of patients accessing mental healthcare.
  • Real risk mitigation — this isn't checkbox compliance; the data you're protecting and the programs you're building have direct, tangible impact.
  • Forward-thinking healthtech — Headway is investing in AI-enabled security workflows and modern GRC tooling, not spreadsheet-driven compliance.
  • Build from scratch — you're standing up Headway's GRC function, not inheriting legacy processes.

What We Offer

~2 min read
Benefits offered include:
Equity compensation
Medical, Dental, and Vision coverage
HSA / FSA
401K
Work-from-Home Stipend
Therapy Reimbursement
16-week parental leave for eligible employees
Carrot Fertility annual reimbursement and membership
13 paid holidays each year as well as a Holiday Break during the week between December 25th and December 31st
Flexible PTO
Employee Assistance Program (EAP)
Training and professional development

Location & Eligibility

Where is the job
New York, United States
On-site at the office
Who can apply
US

Listing Details

Posted
May 14, 2026
First seen
May 15, 2026
Last seen
May 15, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
67%
Scored at
May 15, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Headway
Headway
greenhouse

We're building a new mental healthcare system. Tens of millions of Americans seek mental health care every day, but the vast majority never get the care they need. Headway is solving this, and we’re doing it all through software.

Employees
750
Founded
2017
View company profile
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

Headway Senior Governance, Risk, Compliance (GRC) Analyst