Full-Time

Governance, Risk and Compliance Manager

Posted on 7/29/2026

Nabla

Nabla

51-200 employees

AI-powered clinical documentation assistant

Compensation Overview

$130k - $160k/yr

Remote in USA

Remote

Category
IT & Security (1)
Required Skills
Machine Learning
Penetration Testing
HIPAA

Get referred to Nabla

See people who can refer or advise you

Requirements
  • At least 4 years of experience in governance, risk and compliance, information security, or a closely related function, including meaningful experience building or scaling programs.
  • Hands-on experience in a governance, risk and compliance program at scale, ideally in a high-growth software-as-a-service or technology company.
  • Experience with governance, risk and compliance platforms and tooling for compliance activities, risk registers, policy lifecycle management, audit evidence collection, and workflow automation.
  • Expertise across multiple compliance and security frameworks, including Service Organization Control 2 Type II and ISO 27001.
  • Experience conducting and managing product and enterprise risk assessments, with working knowledge of risk quantification methodologies.
  • Ability to automate manual processes.
  • Experience with security assurance artifacts, including Service Organization Control 2 Type II reports, penetration test reports, Consensus Assessments Initiative Questionnaire, Standardized Information Gathering questionnaires, ISO certifications, and compliance attestations.
Responsibilities
  • Work with Security, Engineering, Product, and Legal teams to mature Nabla’s governance, risk, and compliance programs.
  • Manage the governance, risk, and compliance control evidence library, including investigating control flags and collecting evidence.
  • Manage the vendor risk program, including intake of new vendor requests, security and risk assessments, periodic reviews, and ongoing vendor monitoring.
  • Review and interpret security assurance artifacts such as Service Organization Control 2 Type II reports, penetration test reports, Consensus Assessments Initiative Questionnaire, Standardized Information Gathering questionnaires, ISO certifications, and other compliance attestations.
  • Assist with implementing and operating security and risk management frameworks, including adding new controls for the General Data Protection Regulation, ISO, and Service Organization Control 2.
  • Assist with security questionnaires and client audits, including managing the knowledge base and tracking activities.
  • Support cyber governance, risk, and compliance activities, including tracking information security risks, risk exceptions, and remediation plans.
  • Manage security and compliance onboarding requirements, including security awareness training, access checklists, and quarterly access reviews.
  • Assist with administering and continuously improving the security awareness and training program, including tracking completion metrics and updating training content.
  • Own the ongoing review and maintenance of organizational security policies, standards, and procedures, and assist in identifying policy gaps based on evolving regulatory requirements, business needs, and industry best practices.
Desired Qualifications
  • Healthcare experience, including a background in the Health Insurance Portability and Accountability Act and understanding of its controls.
  • Relevant certifications such as Certified Information Security Manager, Certified in Risk and Information Systems Control, Certified Information Systems Auditor, Certified Cloud Security Professional, or comparable credentials.

Nabla builds ambient AI for healthcare to streamline clinical documentation and workflows. Its flagship Nabla Copilot listens to doctor–patient conversations in real time and automatically creates structured notes that can be entered into Epic, Cerner, or athenahealth, across 55 specialties and 35 languages with customizable settings. It differentiates itself with deep EHR integration, real-time transcription and note generation, broad specialty/language coverage, and growing enterprise adoption as it expands into broader AI-assisted clinical tasks. The goal is to cut administrative time and clinician burnout by handling documentation and expanding AI-powered clinical support.

Company Size

51-200

Company Stage

Series C

Total Funding

$112.7M

Headquarters

Paris, France

Founded

2018

Get referred to Nabla

See people who can refer or advise you

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Unlimited Paid Time Off

Paid Sick Leave

Parental Leave

Stock Options

Home Office Stipend

Flexible Work Hours

Growth & Insights

Headcount

6 month growth

-1%

1 year growth

-1%

2 year growth

3%