Proven experience (10+ years) as a program manager or analyst focused on governance, risk, or compliance—ideally in a regulated environment (healthcare, fintech, SaaS)
Capable of leading complex technical programs and driving projects through ambiguity to results
Understand security, data governance, and compliance requirements (including healthcare-adjacent risks), and comfortable translating technical and regulatory concepts into actionable operations
Responsibilities
Develop and own the GRC program roadmap: define goals, deliverables, success criteria, timelines, and key milestones aligned with Hippocratic AI’s strategic objectives (safety, regulatory readiness, trust frameworks)
Establish and refine frameworks, processes, and best practices for GRC within the company context (healthcare-AI domain)
Manage portfolio of GRC projects: from operational documentation to remediation items, audit readiness, risk assessments, vendor/third-party governance
Collaborate with other program/project managers in InfoSec, Product, and Clinical Ops to align on methodology, reporting, and metrics to prevent silos
Design and deliver regular reporting on program health, risk metrics, and compliance status to senior leadership and partner functions
Lead remediation tracking: identify, document, escalate, and monitor mitigation efforts across projects and operations
Maintain documentation management: templates, document structure, and content governance for GRC artifacts (policies, procedures, controls)
Support strategic planning for GRC: annual/quarterly planning cycles, resource alignment, cross-functional dependencies
Act as an ambassador of the GRC function across the organization: build stakeholder relationships and cultivate a risk-aware culture