Find Your Dream Job in Women's Health

A collection of 100+ women's health companies looking to hire today
In Women's Health
companies
Jobs

Sr. Cybersecurity GRC Lead

Natera

Natera

San Carlos, CA, USA
USD 135,800-169,800 / year
Posted on Aug 21, 2025

POSITION SUMMARY:

We are building a cybersecurity team for the future, seeking an exceptional, business- and technology-savvy Senior Cybersecurity Governance, Risk, and Compliance (GRC) Lead to join our high-performing cybersecurity team in a fast-paced environment. The successful candidate must have a strong passion and experience to support business success in the GRC field. Candidates should bring 8+ years of hands-on GRC experience and a demonstrated ability to align risk management strategies with overarching business objectives. This pivotal role demands expertise in developing and executing GRC policies, SOPs, best practices, conducting risk assessments, and ensuring compliance with a broad spectrum of regulations, including SOC2, ISO 2700x, HIPAA, GDPR, FDA, PCI-DSS, PMDA, and NIST. The role requires close collaboration with cross-functional teams to support business success.

The Senior GRC Analyst will be a linchpin in advancing Natera’s GRC programs, driving third-party risk management (TPRM), leading compliance audits, enforcing policy frameworks, delivering security training, and spearheading AI-powered automation to revolutionize our security posture. We require a bold innovator with deep AI proficiency and hands-on coding expertise to design and deploy cutting-edge GRC automation solutions.

PRIMARY RESPONSIBILITIES:

  • Third-Party Risk Management (TPRM) & Vendor Governance: Partner closely with business and legal teams to enforce security standards across vendor engagements. You will own, author, and elevate the TPRM policy, playbook, integrating processes, technology, and stakeholder collaboration to maximize efficiency, scalability, and risk reduction. Conduct thorough third-party security risk assessments and ensure unwavering vendor compliance.

  • Regulatory Compliance Governance & Audit Support: Act as a relentless advocate for compliance with SOC2, PCI-DSS, HIPAA, FDA, and ISO 27001 frameworks through proactive monitoring, process enhancements, and consistent updates. Maintain defensible audit documentation, coordinate with auditors, and stay ahead of regulatory changes to safeguard internal controls.

  • Policy Management & Process Improvement: Take charge of the security policy portfolio, driving an annual refresh process that ensures timely updates, compliance alignment, and robust stakeholder buy-in. Track exceptions and enforce corrective actions to optimize policy impact.

  • Security Awareness & Training: Design and roll out compelling quarterly cybersecurity training for all employees, lead phishing simulations to harden resilience, and develop targeted compliance education materials. Track and report metrics.

  • GRC Technology & Automation: Harness your advanced programming and security automation skills to build AI-driven solutions that transform compliance processes. You must demonstrate a deep understanding of AI applications in GRC, develop deployment strategies, and integrate security tools to fortify our framework.

QUALIFICATIONS:

  • Experience: Candidates must have 10+ years of direct experience in GRC, cybersecurity risk management, or regulatory compliance, with a proven track record of engaging vendors, regulators, auditors, and engineers. Legal experience is a plus but not required.

  • Skills:

    • Expert knowledge in compliance frameworks (SOC2, FDA, PCI-DSS, HIPAA, ISO 27001, NIST) and third-party risk management.

    • GRC platforms, security awareness tools, and automation technologies.

    • Exceptional business communication and influence to drive stakeholder alignment.

    • Result driven. Exceptional analytical and problem-solving skills to evaluate risk and control effectiveness.

    • Good to Have: an out of the box thinker and innovator. AI savvy and hands-on coding ability to innovate and build next-generation GRC automation—passion for disruption is a must.

  • Education & Certifications: A Bachelor’s degree in Information Security, Risk Management, Computer Science, or Business Administration is mandatory; a Master’s degree in IT, Cybersecurity, or Business is required. Professional certifications such as CISA, CISM, CISSP, or CRISC are strongly preferred.

  • Excellent organizational and communication skills (written and verbal) with demonstrated ability to effectively present to both internal and external customers.

  • Effective time management skills required with a demonstrated ability to assess and prioritize opportunity required.

  • Must act with a sense of urgency, with a focus on closing business.

  • Have the ability to assess the needs of medical professionals and staff members with a focus on consultative sales, coordination of logistics, and problem solving.

  • Have a strong desire to work in a startup-like environment and must work independently with an internal drive to be successful.

The pay range is listed and actual compensation packages are based on a wide array of factors unique to each candidate, including but not limited to skill set, years & depth of experience, certifications and specific office location. This may differ in other locations due to cost of labor considerations.
Remote USA
$135,800$169,800 USD

OUR OPPORTUNITY

Natera™ is a global leader in cell-free DNA (cfDNA) testing, dedicated to oncology, women’s health, and organ health. Our aim is to make personalized genetic testing and diagnostics part of the standard of care to protect health and enable earlier and more targeted interventions that lead to longer, healthier lives.

The Natera team consists of highly dedicated statisticians, geneticists, doctors, laboratory scientists, business professionals, software engineers and many other professionals from world-class institutions, who care deeply for our work and each other. When you join Natera, you’ll work hard and grow quickly. Working alongside the elite of the industry, you’ll be stretched and challenged, and take pride in being part of a company that is changing the landscape of genetic disease management.

WHAT WE OFFER

Competitive Benefits - Employee benefits include comprehensive medical, dental, vision, life and disability plans for eligible employees and their dependents. Additionally, Natera employees and their immediate families receive free testing in addition to fertility care benefits. Other benefits include pregnancy and baby bonding leave, 401k benefits, commuter benefits and much more. We also offer a generous employee referral program!

For more information, visit www.natera.com.

Natera is proud to be an Equal Opportunity Employer. We are committed to ensuring a diverse and inclusive workplace environment, and welcome people of different backgrounds, experiences, abilities and perspectives. Inclusive collaboration benefits our employees, our community and our patients, and is critical to our mission of changing the management of disease worldwide.

All qualified applicants are encouraged to apply, and will be considered without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, age, veteran status, disability or any other legally protected status. We also consider qualified applicants regardless of criminal histories, consistent with applicable laws.

If you are based in California, we encourage you to read this important information for California residents.

Link: https://www.natera.com/notice-of-data-collection-california-residents/

Please be advised that Natera will reach out to candidates with a @natera.com email domain ONLY. Email communications from all other domain names are not from Natera or its employees and are fraudulent. Natera does not request interviews via text messages and does not ask for personal information until a candidate has engaged with the company and has spoken to a recruiter and the hiring team. Natera takes cyber crimes seriously, and will collaborate with law enforcement authorities to prosecute any related cyber crimes.

For more information:
- BBB announcement on job scams
- FBI Cyber Crime resource page