GRC Program Manager

Posted 2 months ago
$117.5K - $222.99K / year

Are you applying to the internship?

Job Description

Governance, Risk & Compliance (GRC) Manager | Milliman

The Tone:
This is a full-time role at Milliman, located remotely in the USA. Milliman delivers market-leading services and solutions globally, helping clients address critical and complex issues such as retirement funding, healthcare financing, risk management, and regulatory compliance through expertise in various fields. This role is crucial for managing Milliman’s corporate governance, risk, and compliance teams, ensuring practical guidance aligned with the company’s risk appetite across 60+ worldwide offices. The position directly supports program planning, staff supervision, and execution of GRC-related projects, working with IT leads, managers, and executives.

The TL;DR
• Role: Full Time
• Type: Full-time
• Location: Remote, USA
• Pay: $117500–$222985 yearly
• Team: Global GRC team, reporting to the CISO within Global Corporate Services (GCS).
• Mission: Manages corporate governance, risk, and compliance teams to assess risk and provide practical guidance aligned with Milliman’s risk appetite.
• Tech Stack: GRC/VRM tools and platforms, SharePoint administration, HIPAA, GDPR, CCPA, HIPAA/HITRUST, ISO 27001 /2.

What You’ll Actually Do
• Team Leadership: Manage the Global GRC team across regions, oversee the technical work of GRC personnel, set performance expectations, and serve as an escalation point for complex issues.
• Talent Development: Support talent management activities including hiring, performance reviews, compensation discussions, and staffing decisions for the team.
• Risk and Compliance Oversight: Oversee vendor security risk processes, monitor regulatory requirements like HIPAA, GDPR, and CCPA, and support internal and client compliance initiatives.
• Strategic Coordination: Coordinate with IT, Legal, Finance, and GCS leadership on risk and compliance priorities, ensuring alignment of GRC work with organizational objectives.
• Program Reporting & Communication: Provide regular program updates, track team performance against SLAs, and communicate risk and compliance information, supporting targeted security training as needed.

The Must-Haves
• Background: Bachelor’s degree in Risk Management, Information Systems, Computer Science, or Cybersecurity, or equivalent professional hands-on work experience, serving as a Manager.
• Experience: Minimum 7 years of hands-on IT Cybersecurity or Risk Management experience, with prior experience using GRC/VRM tools and platforms. Includes experience with HIPAA/HITRUST, GDPR, ISO 27001 /2, and other industry regulatory controls and compliance.
• Skills: Understanding of risk management methodologies and frameworks, clear communication with business and technical stakeholders, ability to manage multiple projects and prioritize work, and capacity for global and cross-functional engagement.
• Bonus: Certification in CRISC, CISA, CISM, or CISSP (or willingness to obtain), and experience within consulting or professional service organizations, including SharePoint administration.

Related Jobs