Full-Time

Director of GRC & EPMO

Finance

Posted on 10/7/2025

Softheon

Softheon

201-500 employees

Healthcare tech platform for insurance enrollment

Compensation Overview

$180k - $200k/yr

+ Equity + Variable Compensation + Incentive Compensation

No H1B Sponsorship

Remote in USA

Remote

Candidates must reside within the United States.

Category
Consulting (1)
Required Skills
Agile
Requirements
  • Bachelor’s degree in Business, Law, Risk Management, Healthcare Administration, Computer Science, or related field.
  • 10+ years of progressively responsible experience in governance, risk, compliance, and audit leadership, ideally within healthcare or health tech.
  • 7+ years of experience of general project management experience such as leading compliance audits, vendor reviews, BCP Plans, etc.
  • Experience developing and administering GRC technology platforms (preferably AuditBoard) and enterprise project management tools (e.g., PPM, MS Project, SharePoint).
  • Management experience in regulated industries, collaborating with senior leadership and Boards on risk and project oversight.
  • Certified Governance, Risk and Compliance Professional (GRCP)
  • Demonstrated success leading regulatory and client audits, business continuity/disaster recovery programs, and large-scale governance initiatives.
  • Advanced knowledge of major healthcare regulatory frameworks (HIPAA, HITRUST, CMS, ACA, PCI-DSS, SOC 2, NIST, MARS-E).
Responsibilities
  • Lead the GRC function, developing and implementing enterprise-wide governance, risk management, and compliance frameworks that align with healthcare regulations (HIPAA, HITRUST, CMS, ACA, Medicare, Medicaid, PCI-DSS, SOC, NIST, MARS-E, and others).
  • Maintain oversight and optimization of GRC platforms and tools (e.g., AuditBoard), driving automation and workflow improvement.
  • Serve as the subject-matter authority for evolving regulatory requirements, business continuity planning, enterprise risk management, and third-party/vendor risk.
  • Oversee internal and external audits, responding to client, regulatory, and operational reviews, ensuring timely and effective resolution and communication.
  • Translate compliance requirements into organizational policies, reporting structures, and training programs that foster a culture of risk awareness and accountability.
  • Establish and manage the Project Management Office as a center of excellence, developing scalable frameworks, standards, and tools supporting a hybrid (Agile, Waterfall, Lean/Six Sigma) methodology environment.
  • Oversee intake, prioritization, resource allocation, and delivery of the enterprise project portfolio—ensuring projects meet timelines, budgets, and business objectives.
  • Apply risk-based thinking and GRC insight to project selection, resource planning, and execution, ensuring alignment with overall business strategy.
  • Mentor and lead project management staff, coach on effective project lifecycle management, risk tracking, and successful delivery practices.
  • Collaborate with executive sponsors and cross-functional stakeholders to communicate project status, risk mitigation measures, and value delivery transparently and persuasively.
  • Champion process improvement and innovation leveraging industry best practices and new technologies.
  • Build and lead high-performing, multidisciplinary GRC and PMO teams—providing direct mentorship, fostering talent development, and succession planning.
  • Promote an inclusive, collaborative, and high-accountability culture that values compliance excellence, continuous learning, and operational agility.
  • Advise and present to executive leadership and the Board on GRC and project management trends, risk analysis, KPIs, and strategic initiatives.
  • Engage in recruiting, hiring, and developing staff whose skills align with the company’s mission and values.
Desired Qualifications
  • Certified Information Systems Auditor (CISA)
  • Certified in Risk and Information Systems Control (CRISC)
  • Agile Certified Practitioner (PMI-ACP) or Certified ScrumMaster (CSM)
  • Lean Six Sigma Green Belt (or higher)
  • Project Management Professional (PMP)
  • Portfolio Management Professional (PfMP) or Program Management Professional (PgMP)
  • Certified SAFe® Agilist or equivalent Agile framework certification
  • ITIL Foundation (for significant IT project environments)
  • Prosci Certified Change Practitioner (or similar change management credential)

Softheon provides healthcare technology solutions for health insurers, government programs, state exchanges, and associations. Its platform includes eCommerce, eligibility checks, and enrollment tools designed to support the distribution and management of health plans such as ACA, Medicare, and Medicaid. The product helps insurers and government programs transform digital operations by automating and streamlining how plans are offered, enrolled, and paid for. Unlike narrower software providers, Softheon serves a broad base that includes health plans, government programs, brokers, and consumers, and it charges through subscriptions, transaction fees, and service agreements. The company is trusted by more than 60 health organizations and has managed millions of lives and processed billions of payments. The goal is to make healthcare more affordable, accessible, and plentiful by enabling efficient, scalable administration of health insurance.

Company Size

201-500

Company Stage

Seed

Total Funding

$200K

Headquarters

Town of Brookhaven, New York

Founded

2000

Simplify Jobs

Simplify's Take

What believers are saying

  • 22 Health launched Florida ACA marketplace using Softheon's enrollment platform in 2025.
  • HealthPartners adopted Phase III EDE solution to enhance Wisconsin ACA shopping experiences.
  • Community First selected ICHRA Connector Cloud December 2, 2025, expanding San Antonio access.

What critics are saying

  • Optum captures 60-80% ACA tech share from Softheon's clients within 12-24 months.
  • CMS 2026 EDE rules force Softheon's platform rebuilds, causing client loss in 3-6 months.
  • HealthSherpa v2.0 AI launch obsoletes Softheon's eligibility, driving churn in 6-12 months.

What makes Softheon unique

  • CITIZ3N subsidiary launched April 3, 2024, targets government ACA and Medicaid solutions.
  • Agentic AI automates 90% of workflows with human-in-the-loop compliance for health plans.
  • Named to TIME's Top HealthTech Companies of 2025 for ACA and ICHRA innovations.

Help us improve and share your feedback! Did you find this helpful?

Your Connections

People at Softheon who can refer or advise you

Benefits

Health Insurance

Vision Insurance

Dental Insurance

401(k) Retirement Plan

401(k) Company Match

Home Office Stipend

Phone/Internet Stipend

Wellness Program

Unlimited Paid Time Off

Parental Leave

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

2%

2 year growth

3%
PR Newswire
Feb 19th, 2026
22 Health launches ACA marketplace in Florida with Softheon technology support

22 Health, a provider-sponsored health plan serving Broward County, Florida, has launched its first Affordable Care Act marketplace plans using Softheon's technology platform. The launch marks 22 Health's entry into the health insurance marketplace following its first open enrolment period. 22 Health is a division of Community Care Plan, owned by Broward Health and Memorial Healthcare System, which has provided healthcare coverage to Florida families for 25 years through state-sponsored programmes. Softheon provided comprehensive support for the marketplace launch, including shopping and enrolment processes, payment and billing support, premium reconciliation, and compliance assistance. The healthcare technology company, founded in 2000, has 25 years of experience providing ACA marketplace solutions and currently serves over 100 health plans.

PR Newswire
Sep 26th, 2025
Softheon Named to TIME's World's Top HealthTech Companies of 2025

Softheon is recognized as one of the World's Top HealthTech Companies of 2025 by TIME.

PR Newswire
Sep 12th, 2024
Softheon Recognized in Multiple Gartner(R) Reports

Softheon has been named as a Sample Vendor in the Hype Cycle for Healthcare Data, Analytics and AI, 2024.

StreetInsider
Apr 27th, 2024
Human Augmentation Market to Cross USD 873.51 billion by 2031 | Ekso Bionics, Garmin, Vuzix, Google, B-Temia

Industry titans are actively patenting technologies, investing in promising startups, and engaging in strategic mergers and acquisitions like Softheon's acquisition of NextHealth technologies - underscoring the segments growth potential.

PR Newswire
Apr 3rd, 2024
Softheon Launches CITIZ3N, New Subsidiary Dedicated to Government Solutions in Healthcare

STONY BROOK, N.Y., April 3, 2024 /PRNewswire/ - Softheon, a leading cloud-based eligibility, enrollment, and billing provider for health plans and government agencies, today announces the launch of CITIZ3N, a subsidiary dedicated to revolutionizing government solutions in healthcare.

INACTIVE