Director, Governance, Risk, and Compliance
VeracyteAbout the role
At Veracyte, we offer exciting career opportunities for those interested in joining a pioneering team that is committed to transforming cancer care for patients across the globe. Working at Veracyte – whether it be in one of our labs, corporate offices, the field – enables our employees to not only make a meaningful impact on the lives of patients, but to also learn and grow within a results-driven environment that values innovation, collaboration, and compassion.
The Position:
We are seeking a highly experienced and strategic Director of Governance, Risk, and Compliance (GRC) to lead and mature the organization's GRC program. This role will be responsible for building and overseeing the company’s governance frameworks, risk management processes, and compliance initiatives, including achieving and maintaining SOC 2 Type II and HITRUST certification. The ideal candidate will partner closely with Cybersecurity, Legal, IT, and business leadership to ensure ongoing compliance with regulatory requirements, while managing organizational risk and strengthening overall security posture.
Location: This is a hybrid/onsite position based in our San Diego location.
Based on candidate location, we may consider a remote candidate based in the U.S.
Key Responsibilities:
GRC Program Leadership:
- Design, implement, and lead the enterprise GRC program, aligning governance, risk, and compliance activities to business objectives.
- Develop and maintain internal policies, controls, and procedures to meet regulatory and industry standards including SOC 2 Type II, HITRUST, HIPAA, SOX, and applicable privacy regulations.
- Serve as the primary owner and project lead for SOC 2 Type II and HITRUST readiness, certification, and ongoing compliance maintenance.
- Act as a key advisor to executive leadership on enterprise risk and compliance posture.
Risk Management:
- Establish and maintain risk management frameworks to identify, assess, mitigate, and monitor enterprise risks.
- Oversee third-party/vendor risk management processes, ensuring proper due diligence and ongoing monitoring.
- Lead the risk assessment process, identifying emerging risks and control gaps while driving remediation plans.
Compliance Oversight:
- Oversee internal audit readiness, evidence collection, control testing, and issue remediation for external audits and certifications.
- Serve as primary liaison with internal and external auditors, certification bodies, and regulatory examiners.
- Ensure ongoing compliance with HIPAA, GDPR, SOX, and other applicable regulatory frameworks.
Collaboration & Communication:
- Partner with IT, Cybersecurity, Legal, HR, and business stakeholders to ensure cross-functional alignment on GRC objectives.
- Provide periodic GRC updates, metrics, and executive-level reporting to senior leadership and the Board as appropriate.
- Lead security awareness and compliance training programs across the organization.
Continuous Improvement:
- Continuously evaluate and improve GRC processes, tools, and metrics to increase efficiency, visibility, and organizational maturity.
- Stay current with evolving regulatory requirements, industry standards, and best practices to proactively adjust the GRC program.
Who You Are:
- Bachelor’s degree in Information Security, Risk Management, Business Administration, or related field; Master’s degree preferred.
- 8-10+ years of progressive experience in GRC, information security, compliance, or risk management, with at least 3+ years in a leadership role.
- Proven experience leading SOC 2 Type II and HITRUST certification efforts.
- In-depth knowledge of risk management frameworks (NIST, ISO 27001, COSO, etc.) and regulatory requirements (HIPAA, GDPR, SOX, etc.).
- Strong leadership, project management, and cross-functional collaboration skills.
- Excellent communication skills with ability to present to executive leadership and external auditors.
Preferred Certifications:
- Certified Information Systems Auditor (CISA)
- Certified Information Systems Security Professional (CISSP)
- Certified in Risk and Information Systems Control (CRISC)
- HITRUST Certified CSF Practitioner (CCSFP)
- Certified Information Privacy Professional (CIPP)
Work Environment:
- Hybrid, on-site, or possibly remote based on business needs.
#LI-Onsite, #LI-Hybrid, or
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s