At OnePlan, we specialize in creating AI-enabled solutions that make strategic portfolio, financial, resource, and work management seamless. We help businesses bridge the gap between strategy and execution by offering solutions that boost business agility, streamline project management, and optimize resources. What truly makes OnePlan stand out is our commitment to delivering powerful solutions and fostering a culture of collaboration. We combine robust analytics with a platform that integrates seamlessly into the tools businesses already know and trust. Our high-trust, team-focused environment allows us to innovate quickly and deliver solutions that drive meaningful results for our clients. We're passionate about exceeding expectations, working together to empower organizations to succeed in a rapidly changing business landscape.
Senior Governance, Risk & Compliance Lead
Location
United States
Posted
3 days ago
Salary
Not specified
No structured requirement data.
Job Description
Senior Governance, Risk & Compliance Lead
Department: Product
Employment Type: Permanent - Full Time
Location: United States (Remote)
Reporting To: Matthew Willey
Description
OnePlan is looking for a Senior Governance, Risk & Compliance Lead to own and operate our security, privacy, and compliance programs. This role is responsible for maintaining OnePlan’s existing certifications including SOC 2 Type II, ISO 27001, and ISO 27701, while leading our FedRAMP Moderate readiness initiative as we expand into public sector markets.
What You’ll Do at OnePlan
- Own and manage OnePlan’s governance, risk, and compliance program across security and privacy frameworks
- Maintain the company’s compliance certifications including SOC 2 Type II, ISO 27001, and ISO 27701, ensuring ongoing audit readiness and successful surveillance audits and recertifications
- Coordinate with external auditors and manage evidence collection, control validation, and supporting documentation
- Maintain and update security policies, procedures, and internal documentation supporting compliance frameworks
- Maintain the company risk register and drive risk identification, assessment, and remediation activities across the organization
- Partner closely with Engineering and IT teams to implement and document security controls across the platform
- Lead OnePlan’s FedRAMP Moderate readiness initiative, including NIST 800-53 gap assessments and remediation planning
- Develop and maintain the System Security Plan (SSP) and associated FedRAMP documentation
- Prepare the organization for 3PAO assessment and establish processes for ongoing continuous monitoring
- Manage vendor risk assessments and third party security reviews
- Support enterprise and public sector security questionnaires, compliance reviews, and due diligence requests
- Ensure privacy and data protection practices align with GDPR and global privacy frameworks
- Support the ongoing operation of OnePlan’s ISO 27701 privacy program
Our Ideal Fit
- 6+ years of experience in governance, risk and compliance, information security, or security compliance roles
- Direct experience managing SOC 2 Type II and ISO 27001 audits and maintaining ongoing compliance programs
- Strong understanding of NIST 800-53 and FedRAMP security requirements
- Experience using compliance automation platforms such as Vanta or similar tools
- Experience working in a cloud native SaaS environment, ideally within Azure
- Strong documentation, audit management, and cross functional coordination skills
- Ability to translate security and compliance requirements into practical operational processes
- Experience leading or supporting FedRAMP readiness or authorization programs
- Professional certifications such as CISSP, CISM, CISA, CRISC, ISO 27001 Lead Implementer/Auditor, or CIPP
- Experience supporting enterprise security reviews and government compliance requirements
- Experience working in high growth SaaS or enterprise software companies
More Reasons Why You Should Apply!
- We’re a remote-first company with team members across the USA, Canada, UK, and India!
- OnePlan has been recognized as the Global Microsoft Partner of the Year in Project Portfolio Management in 2019, 2020, 2021, 2022 and 2023.
- We’ve been named a "Strong Performer" in the latest Forrester Strategic Portfolio Management WAVE report.
- We offer comprehensive health, dental, and vision benefits, with additional insurance options.
- Employer RRSP and 401K matching programs.
- A fun, collaborative, and diverse environment with regular health and team challenges to keep things light and enjoyable!
Disclaimer: We’ll only contact candidates who have applied directly through our official channels. Any communication about job offers will always come from an email address linked to OnePlan Solutions, and we’ll follow our standard hiring process every time. You’ll never be asked for money or personal information during the interview process. If something feels off, don’t hesitate to reach out to us to confirm.
Ready to Apply?
Check out what it’s like to work at OnePlan and learn more about us at https://oneplan.ai/
Related Guides
Related Categories
Related Job Pages
More Risk Jobs
Risk Manager
EmpiRx Health, LLCEmpiRx Health is the leading clinically-driven pharmacy benefits management company, focusing on health outcomes first and enabling clients to take control of their pharmacy benefits.
EmpiRx Health is seeking a highly skilled and experienced Risk Manager. In this critical role, the Risk Manager plays a key role in supporting and ensuring the achievement of enterprise goals. The Risk Manager works closely with key departments to proactively identify and address...
Director, Risk Management
CenterWellCenterWell Pharmacy provides convenient, safe, reliable pharmacy services and is committed to excellence and quality. Through our home delivery and over-the-counter fulfillment services, specialty, and retail pharmacy locations, we provide customers simple, integrated solutions every time. Cares for patients with chronic and complex illnesses. Offers personalized clinical and educational services to improve health outcomes and drive superior medication adherence. CenterWell, a Humana company, creates experiences that put patients at the center. As the nation’s largest provider of senior-focused primary care, one of the largest providers of home health services, and the fourth largest pharmacy benefit manager, CenterWell is focused on whole-person health by addressing the physical, emotional, and social wellness of our patients. Part of Humana Inc. (NYSE: HUM). Offers stability, industry-leading benefits, and opportunities to grow yourself and your career. Employs more than 30,000 clinicians committed to putting health first. Provides flexible scheduling options, clinical certifications, leadership development programs, and career coaching.
This role involves identifying and analyzing potential sources of risk within the Home Health segment, proactively ensuring controls and processes are in place to minimize organizational risk. Key duties include developing and implementing cost-effective risk minimization approaches, assessing business risks, and leading risk assessments, issue management, auditing, and monitoring for Company Home Health and OneHome.
Senior Director, Data Governance
InovalonEmpowering data-driven healthcare for payers, providers, pharmacies, and life sciences organizations.
Senior Director leading data governance programs in healthcare data analytics
Clinical Risk Manager, Cost Containment, C&F Stop Loss
Crum & ForsterCrum & Forster (C&F), with a proud history dating to 1822, provides specialty and standard commercial lines insurance products through our admitted and surplus lines insurance companies. C&F enjoys a financial strength rating of "A+" (Superior) by AM Best and is proud of our superior customer service platform. Our claims and risk engineering services are recognized as among the best in the industry. Our most valuable asset is our people: more than 2000 employees in locations throughout the United States. The company is increasingly winning recognition as a great place to work, earning several workplace and wellness awards, including the 2024 Great Place to Work® Award for our employee-first focus and our steadfast commitment to diversity, equity and Inclusion. C&F is part of Fairfax Financial Holdings, a global, billion dollar organization. For more information about Crum & Forster, please visit our website: www.cfins.com .
Clinical Risk Manager overseeing high-cost claims and implementing risk management strategies