GRC Manager
Our client is seeking an experienced GRC Manager to lead the next phase of growth and maturity for its cybersecurity governance, risk, and compliance program.
This individual will serve as the organization’s GRC subject matter expert, taking ownership of assessing the current environment, identifying opportunities for improvement, and building a more mature, proactive GRC program. The ideal candidate will have a strong background in developing and scaling GRC functions, especially within regulated environments, and will be comfortable working independently to provide strategic recommendations and implement best practices.
Healthcare industry experience is strongly preferred, and a solid understanding of HIPAA compliance is required. Experience with HITRUST is a plus.
***Role can be completely remote. Client is in Miami, FL
Key Responsibilities:
- Assess the current state of the organization’s GRC and cybersecurity compliance program and identify gaps, risks, and areas for improvement
- Design, build, and mature a scalable GRC program aligned to business and regulatory requirements
- Develop and enhance governance processes, risk management practices, controls, and compliance procedures
- Help transition the organization from a reactive compliance posture to a more proactive, risk-based approach
- Validate and strengthen the organization’s current alignment to the NIST 2.0 framework
- Partner with internal leadership and third-party assessors to support security maturity evaluations and compliance initiatives
- Formalize and improve manual risk assessment processes, tracking mechanisms, and reporting practices
- Review and strengthen existing policies and procedures that have been developed over time
- Provide expert guidance and recommendations to leadership on GRC strategy, priorities, and roadmap development
- Establish governance structures and repeatable processes to support long-term program sustainability
- Play a key role in building out the future state of the GRC function, with the opportunity to eventually hire and lead a team
Qualifications:
- 5+ years of experience in governance, risk, and compliance, information security, or cybersecurity program management
- Proven experience building a GRC program from scratch and/or significantly maturing an existing program
- Strong understanding of HIPAA compliance and experience supporting compliance efforts in regulated environments
- Experience conducting program assessments and translating findings into actionable improvements
- Hands-on experience developing controls, governance models, policies, procedures, and risk management processes
- Strong knowledge of cybersecurity frameworks, especially NIST 2.0
- Ability to work independently, assess needs, and make strategic recommendations with minimal oversight
Compensation
Based on experienceAbout Us
Technology Doesn't Change the World, People Do.®
Robert Half is the world’s first and largest specialized talent solutions firm that connects highly qualified job seekers to opportunities at great companies. We offer contract, temporary and permanent placement solutions for finance and accounting, technology, marketing and creative, legal, and administrative and customer support roles.
Robert Half works to put you in the best position to succeed. We provide access to top jobs, competitive compensation and benefits, and free online training. Stay on top of every opportunity - whenever you choose - even on the go. Download the Robert Half app and get 1-tap apply, notifications of AI-matched jobs, and much more.
All applicants applying for U.S. job openings must be legally authorized to work in the United States. Benefits are available to contract/temporary professionals, including medical, vision, dental, and life and disability insurance. Hired contract/temporary professionals are also eligible to enroll in our company 401(k) plan. Visit roberthalf.gobenefits.net for more information.
© 2025 Robert Half. An Equal Opportunity Employer. M/F/Disability/Veterans. By clicking “Apply Now,” you’re agreeing to Robert Half’s Terms of Use and Privacy Notice.
