Governance, Risk & Compliance (GRC) Senior Specialist
VeracyteAbout the role
At Veracyte, we offer exciting career opportunities for those interested in joining a pioneering team that is committed to transforming cancer care for patients across the globe. Working at Veracyte enables our employees to not only make a meaningful impact on the lives of patients, but to also learn and grow within a purpose driven environment. This is what we call the Veracyte way – it’s about how we work together, guided by our values, to give clinicians the insights they need to help patients make life-changing decisions.
Our Values:
- We Seek A Better Way: We innovate boldly, learn from our setbacks, and are resilient in our pursuit to transform cancer care
- We Make It Happen: We act with urgency, commit to quality, and bring fun to our hard work
- We Are Stronger Together: We collaborate openly, seek to understand, and celebrate our wins
- We Care Deeply: We embrace our differences, do the right thing, and encourage each other
The Position:
We are seeking a detail-oriented experienced Governance, Risk & Compliance (GRC) Senior Specialist to assist with leading and supporting the organization’s governance, risk, and compliance initiatives. Under the direction of Management the incumbent will perform IT risk assessments, ensure controls, policies and procedures and resources are in place for IT and Security teams to effectively manage risk. The GRC Specialist will articulate risk appetite and advocate risk culture; act as a challenge function by providing questions and feedback across multiple functions. In addition, the specialist will work to ensure that the company’s operations align with relevant regulations, internal policies, standards and risk management frameworks. The ideal candidate will have a strong understanding of risk management principles, compliance standards, and information security best practices. As the program evolves the role will be responsible for maturing the GRC operations.
Who You Are:
- Bachelor’s degree in Information Security, Risk Management, Business Administration, or a related field.
- 5+ years of experience in GRC, information security, risk management, or compliance.
- Experience with regulatory frameworks such as ISO 27001, NIST, SOX, PCI-DSS, GDPR, HIPAA, etc.
- Experience in risk assessments and compliance audits is preferred.
- Strong knowledge of risk management and compliance frameworks.
- Familiarity with third-party vendor risk management practices.
- Excellent communication and report-writing skills.
- Detail-oriented with the ability to analyze complex regulatory requirements.
- Proficient in using GRC tools and software for tracking and managing compliance/risk activities.
- Ability to manage multiple projects and take on other security tasks as needed
Certifications (Preferred):
- Certified Information Systems Auditor (CISA)
- Certified Information Security Manager (CISM)
- Certified Information Systems Security Professional (CISSP)
- Certified in Risk and Information Systems Control (CRISC)
- Certified Information Privacy Professional (CIPP)
#LI-Remote
The final salary offered to a successful candidate will be dependent on several factors that may include but are not limited to the type and length of experience within the job, type and length of experience within the industry, education, etc. Base pay is one part of the Total Package that is provided to compensate and recognize employees for their work, and this role may be eligible for additional discretionary bonuses/incentives, and restricted stock units. Veracyte is a multi-state employer, and
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s