Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Governance, Risk & Compliance Lead  image - Rise Careers
Job details

Governance, Risk & Compliance Lead - job 1 of 2

Company Description

Guardant Health is a leading precision oncology company focused on guarding wellness and giving every person more time free from cancer. Founded in 2012, Guardant is transforming patient care and accelerating new cancer therapies by providing critical insights into what drives disease through its advanced blood and tissue tests, real-world data and AI analytics. Guardant tests help improve outcomes across all stages of care, including screening to find cancer early, monitoring for recurrence in early-stage cancer, and treatment selection for patients with advanced cancer. For more information, visit guardanthealth.com and follow the company on LinkedInX (Twitter) and Facebook.

Job Description

About the Role:

Guardant is seeking a Governance, Risk & Compliance (GRC) Lead with 5-10 years of experience to drive the evolution of our Information Security Governance, Risk, and Compliance program. At Guardant, we value innovation over rigid adherence to traditional compliance methods—our ideal candidate is a forward-thinking, non-dogmatic,  new leader who sees compliance as a business enabler rather than a bottleneck. After gaining experience supporting  GRC programs designed or led by others, you are eager to build one that challenges the status quo.  This role is designed for someone who is willing to leverage native workplace technology to eliminate manual, repetitive, and performative tasks, allowing the organization to focus on our core mission.

The ideal candidate will have a mastery of compliance frameworks and a passion for streamlining governance processes through automation, modern risk management techniques, and proactive controls. At Guardant, we believe in staying "Connected to the Work," meaning that even in leadership roles, team members are expected to stay hands-on—contributing as engineers or analysts in their field. If you're looking to redefine GRC, drive efficiency, and integrate security seamlessly into business operations, we’d love to hear from you.

Essential Duties and Responsibilities:

  • Develop, maintain, and enhance the security governance, risk, and compliance program, emphasizing automation, right-sized controls, and proactive compliance monitoring, ensuring alignment with business objectives and regulatory requirements (e.g., HIPAA Security Rule, ISO 27001, GDPR,SOX-404).
  • Lead the organization’s pursuit of ISO 27001 certification, ensuring compliance and continuous improvement of best practices.
  • Drive a culture of accountability through success metrics and goals through continuous monitoring.
  • Develop and maintain security policies, standards, and procedures that align with business goals and regulatory requirements.
  • Identify and address governance gaps, ensuring timely implementation of recommendations across business units.
  • Implement automated compliance and security controls to continuously monitor security risks, exceptions, testing, and overall compliance.
  • Conduct and oversee internal assessments and security control testing, ensuring compliance with regulations and protecting sensitive data.
  • Prepare and present risk assessments, and remediation plans to leadership, tracking progress toward resolution.
  • Partner with Privacy, Compliance and Regulatory teams to ensure security operations meet regulatory and business needs.
  • Establish and maintain a Security Trust Program to support customer engagements, audits, and assessments.
  • Act as a trusted advisor to both business and technical teams, ensuring GRC goals align with the overall security strategy.
  • Provide insights and recommendations to the CISO on regulatory changes and emerging risks.
  • Restructure and streamline the third-party risk management program, ensuring vendors meet security and compliance requirements.

Qualifications

Essential Qualifications:

  • 5+ years of experience in Governance, Risk, and Compliance (GRC) or a related field, with at least 2 years in a leadership or program management role.
  • Experience in healthcare settings preferred but not required.
  • Experience with qualitative risk approaches or the ambition to fast ramp on such approaches.
  • Strong knowledge of information security management, governance, and compliance principles, including laws, regulations, and industry standards.
  • Deep understanding of regulatory frameworks and industry standards, including:
    • Required: ISO 27001, HIPAA, GDPR, 21 CFR Part 11.
    • Preferred: NIST CSF, NIST SP 800-53 r5, NIST SP 800-30 r1, Secure Controls Framework (SCF).
  • Strong familiarity with cybersecurity and cloud security frameworks, experience with the Secure Controls Framework desired but not required.
  • Experience with risk management, compliance, resilience, security policy and standards, vendor risk management, security metrics, and security training & awareness.
  • Proficiency with Atlassian tools (JIRA, Confluence) for designing projects, dashboards, and dynamic documentation.
  • Conceptual understanding of security technologies across both on-premises and cloud infrastructures.
  • Certifications (Preferred, but Not Required): CISSP, CISA, CRISC
  • Exceptional ability to convey technical and security concepts to diverse stakeholders, including non-technical audiences.
  • Skilled in tackling compliance challenges and making informed risk-based decisions.
  • Proven ability to establish credibility and build trust across the organization, particularly with engineers, researchers, and G&A functions.
  • Sustained capability to stay updated with evolving regulations, industry best practices, and emerging risks.

Additional Information

Hybrid Work Model: At Guardant Health, we have defined days for in-person/onsite collaboration and work-from-home days for individual-focused time. All U.S. employees who live within 50 miles of a Guardant facility will be required to be onsite on Mondays, Tuesdays, and Thursdays. We have found aligning our scheduled in-office days allows our teams to do the best work and creates the focused thinking time our innovative work requires. At Guardant, our work model has created flexibility for better work-life balance while keeping teams connected to advance our science for our patients.

The US base salary range for this full-time position is $108.800 to $149,600. The range does not include benefits, and if applicable, bonus, commission, or equity. The range displayed reflects the minimum and maximum target for new hire salaries across all US locations for the posted role with the exception of any locations specifically referenced below. 

For positions based in Palo Alto, CA, the base salary range for this full-time position is $128,000 to $176,000. The range does not include benefits, and if applicable, bonus, commission, or equity.

Within the range, individual pay is determined by work location and additional factors, including, but not limited to, job-related skills, experience, and relevant education or training. If you are selected to move forward, the recruiting team will provide details specific to the factors above.

Employee may be required to lift routine office supplies and use office equipment. Majority of the work is performed in a desk/office environment; however, there may be exposure to high noise levels, fumes, and biohazard material in the laboratory environment. Ability to sit for extended periods of time.

Guardant Health is committed to providing reasonable accommodations in our hiring processes for candidates with disabilities, long-term conditions, mental health conditions, or sincerely held religious beliefs. If you need support, please reach out to [email protected]

Guardant Health is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status and will not be discriminated against on the basis of disability.

All your information will be kept confidential according to EEO guidelines.

To learn more about the information collected when you apply for a position at Guardant Health, Inc. and how it is used, please review our Privacy Notice for Job Applicants.

Please visit our career page at: http://www.guardanthealth.com/jobs/

Guardant Health Glassdoor Company Review
3.3 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
Guardant Health DE&I Review
3.54 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
CEO of Guardant Health
Guardant Health CEO photo
Helmy Eltoukhy and AmirAli Talasaz
Approve of CEO

Average salary estimate

$152000 / YEARLY (est.)
min
max
$128000K
$176000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Governance, Risk & Compliance Lead , Guardant Health

Are you ready to take your career to the next level? Guardant Health, a leader in precision oncology, is on the lookout for a Governance, Risk & Compliance Lead to join our dynamic team in Palo Alto, CA. If you have 5-10 years of experience in governance, risk, and compliance, and you're passionate about leveraging innovative strategies rather than sticking to traditional compliance norms, you're in the right place! At Guardant, compliance isn't just a checkbox; it's an opportunity to enhance our mission of transforming patient care and making a real difference in people's lives. In this exciting role, you’ll develop and enhance our GRC program by implementing automation and proactive compliance measures that align with regulatory requirements, such as HIPAA, ISO 27001, and GDPR. You'll work closely with cross-functional teams, ensuring our security strategies blend seamlessly into our operations. We're looking for a forward-thinking leader who isn't afraid to roll up their sleeves and dive into the work while mentoring others in the process. So, if you're eager to redefine governance, risk, and compliance—and want to do this in an environment that values creativity and collaboration—then we can't wait to meet you!

Frequently Asked Questions (FAQs) for Governance, Risk & Compliance Lead Role at Guardant Health
What are the responsibilities of a Governance, Risk & Compliance Lead at Guardant Health?

As a Governance, Risk & Compliance Lead at Guardant Health, you will be tasked with developing, maintaining, and enhancing our GRC program. Your responsibilities will include leading our pursuit of ISO 27001 certification, implementing automated compliance controls, conducting internal assessments, and collaborating with various teams to ensure compliance with regulations like HIPAA and GDPR. The role emphasizes the importance of streamlining governance processes through automation and proactive monitoring, making it an integral part of our strategy to improve patient outcomes.

Join Rise to see the full answer
What qualifications are needed for the Governance, Risk & Compliance Lead position at Guardant Health?

To qualify for the Governance, Risk & Compliance Lead role at Guardant Health, you should have at least 5 years of experience in GRC or a related field, with a minimum of 2 years in a leadership role. Familiarity with compliance frameworks such as ISO 27001, HIPAA, and GDPR is crucial. Experience in healthcare settings, knowledge of risk management techniques, and proficiency with Atlassian tools like JIRA and Confluence will set you apart. Additionally, certifications like CISSP or CISA are preferred.

Join Rise to see the full answer
How does Guardant Health approach Governance, Risk & Compliance differently?

At Guardant Health, we take an innovative approach to Governance, Risk & Compliance by viewing compliance as a business enabler rather than a hindrance. We're seeking someone who is forward-thinking and ready to challenge traditional methods. By leveraging technology and streamlining processes, the GRC Lead will drive the evolution of our compliance strategies, focus on automation, and ensure a culture of accountability through continuous monitoring and improvement.

Join Rise to see the full answer
What is the work culture like for the Governance, Risk & Compliance Lead at Guardant Health?

The work culture at Guardant Health for the Governance, Risk & Compliance Lead is collaborative and supportive. We promote a hybrid work model that allows for both in-person collaboration and remote work, fostering a healthy work-life balance. The environment encourages hands-on involvement from leaders, allowing you to contribute directly to projects while mentoring your team and driving innovation within the organization's security strategy.

Join Rise to see the full answer
Are there opportunities for professional growth as a Governance, Risk & Compliance Lead at Guardant Health?

Absolutely! At Guardant Health, we prioritize your professional growth and provide resources and mentorship to help you advance in your career. As a Governance, Risk & Compliance Lead, you'll have the chance to innovate within our compliance framework and gain valuable experience in a fast-paced, cutting-edge environment. You'll also be collaborating with experts in the field, which can broaden your skill set and open doors for future opportunities.

Join Rise to see the full answer
Common Interview Questions for Governance, Risk & Compliance Lead
How do you approach developing a Governance, Risk & Compliance program?

When developing a GRC program, I focus on aligning compliance initiatives with business objectives first and foremost. This includes understanding regulatory requirements, establishing a framework that incorporates automation to handle repetitive tasks, and fostering a culture of continuous improvement through accountability metrics. It's essential to engage stakeholders at every level to ensure the program is practical and relevant.

Join Rise to see the full answer
Can you describe your experience with regulatory frameworks?

I have extensive experience with several regulatory frameworks such as ISO 27001, HIPAA, and GDPR. My approach has always been to ensure that compliance is seamlessly integrated into our operational processes. I stay updated with evolving regulations, conduct regular assessments, and maintain open communication with teams to guarantee that we’re not just compliant, but proactively managing our risk landscape.

Join Rise to see the full answer
How do you handle compliance challenges effectively?

Handling compliance challenges effectively requires a proactive mindset and collaboration. I advocate for utilizing data to identify potential risks early on and implementing automated controls that ease the burden of manual compliance checks. I also emphasize the importance of training programs and fostering an open dialogue within the organization to address compliance queries in real-time.

Join Rise to see the full answer
What metrics do you believe are essential for measuring the success of a GRC program?

Key metrics for measuring the success of a GRC program include the number of compliance incidents over time, the effectiveness of risk assessments, and the rate of vendor compliance. Additionally, tracking time taken to resolve compliance issues and monitoring the completion of required training are vital for evaluating our efforts and showcasing continuous improvement.

Join Rise to see the full answer
How would you integrate GRC objectives into business operations?

Integrating GRC objectives into business operations involves embedding compliance into the fabric of daily activities. This means collaborating with various departments to ensure that compliance measures support their goals rather than hinder them. I also believe in creating accessible resources and training that help teams understand and prioritize GRC elements relevant to their roles.

Join Rise to see the full answer
Describe a time you successfully led a team through a major compliance initiative.

In my previous role, I led a team through the ISO 27001 certification process. This involved conducting a thorough gap analysis, developing a project roadmap, and engaging with cross-functional teams for input. Regular updates and training sessions helped maintain momentum, and ultimately, we not only achieved certification but also cultivated a stronger culture of compliance within the organization.

Join Rise to see the full answer
How do you stay informed about changes in laws and regulations?

I stay informed about changes in laws and regulations by subscribing to industry newsletters, attending relevant conferences, and participating in professional networks. Additionally, I engage with legal and compliance teams to discuss emerging trends. This proactive approach allows me to adapt our compliance strategies promptly and effectively.

Join Rise to see the full answer
What role does technology play in your GRC strategy?

Technology plays a critical role in my GRC strategy, particularly in automation and data analytics. Utilizing tools to automate routine compliance tasks helps free up resources for more strategic initiatives. Additionally, technology enables us to track compliance metrics in real-time, providing valuable insights into risk management and compliance performance.

Join Rise to see the full answer
How do you foster a culture of compliance within an organization?

Fostering a culture of compliance requires ongoing communication and engagement. I focus on training programs that make compliance relatable, promoting the benefits of a strong compliance framework. I encourage team participation in discussions about compliance challenges and solutions, instilling a sense of shared responsibility for our compliance goals.

Join Rise to see the full answer
What is your leadership style when it comes to managing a GRC team?

My leadership style is collaborative and empowering. I believe in setting clear expectations while giving my team the autonomy to innovate and suggest improvements to our GRC initiatives. Regular feedback and recognition are key aspects of my approach, as is fostering an environment where team members feel comfortable sharing ideas and challenges.

Join Rise to see the full answer
Similar Jobs
Posted 2 days ago

Guardant Health seeks a passionate Associate Account Executive to promote their innovative cancer screening solutions in the Winner, South Dakota area.

Guardant Health Hybrid Walnut Creek, California, United States
Posted 2 days ago

Join Guardant Health as an Account Executive, where you will leverage your sales expertise to transform cancer screening practices.

Photo of the Rise User

A Senior Business Analyst with a strong background is needed to enhance client operations and facilitate communication between business and development teams.

Photo of the Rise User

Join Smith+Nephew as a Global Clinical Strategy Lead to shape the future of our Sports Medicine portfolio with innovative clinical strategies and insights.

APM Group Hybrid Collingwood VIC 3066, Australia
Posted 4 days ago

Join APM as an Employment Consultant and help transform lives while growing your career in a supportive environment.

Join Lyra Health as a part-time Mental Health Therapist and help transform mental health care through technology and personalized support.

Photo of the Rise User

Publicis Sapient is looking for a dynamic Client Partner to lead transformative partnerships in the Travel & Hospitality sector.

Photo of the Rise User
Posted 8 days ago

Join Node.Digital as a Scrum Master, where you'll lead Agile teams and enhance delivery excellence in a dynamic environment.

Photo of the Rise User
Keurig Dr Pepper Hybrid US, Collin County, TX; Texas, Frisco, TX
Posted 10 days ago

Join Keurig Dr Pepper as a Senior Business Analyst to enhance employee experience through data-driven insights and technology solutions.

Photo of the Rise User
Coder Remote No location specified
Posted 9 days ago

Bring your cloud-native superpowers to Coder as a Solutions Architect and help us redefine productivity for developers in a remote-first environment.

Photo of the Rise User
Inclusive & Diverse
Mission Driven
Social Impact Driven
Passion for Exploration
Dare to be Different
Diversity of Opinions
Reward & Recognition
Empathetic
Feedback Forward
Work/Life Harmony
Collaboration over Competition
Growth & Learning
Transparent & Candid
Customer-Centric
Rise from Within
Friends Outside of Work
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Learning & Development
Work Visa Sponsorship
Employee Resource Groups
401K Matching
Paid Time-Off
Maternity Leave
Social Gatherings
Company Retreats
Photo of the Rise User
Homecare Gurus Remote No location specified
Posted last month

Join Homecare Gurus Ltd as a remote HR Coordinator and make a significant impact in the adult social care sector.

Photo of the Rise User
Posted 8 months ago
Customer-Centric
Inclusive & Diverse
Collaboration over Competition
Transparent & Candid
Growth & Learning
Photo of the Rise User
Posted 9 months ago
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Transparent & Candid
Growth & Learning
Fast-Paced
Collaboration over Competition
Take Risks
Friends Outside of Work
Passion for Exploration
Customer-Centric
Reward & Recognition
Feedback Forward
Rapid Growth
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Paternity Leave
Fully Distributed
Flex-Friendly
Some Meals Provided
Snacks
Social Gatherings
Pet Friendly
Company Retreats
Dental Insurance
Life insurance
Health Savings Account (HSA)
Photo of the Rise User
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Transparent & Candid
Growth & Learning
Fast-Paced
Collaboration over Competition
Take Risks
Friends Outside of Work
Passion for Exploration
Customer-Centric
Reward & Recognition
Feedback Forward
Rapid Growth
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Paternity Leave
Fully Distributed
Flex-Friendly
Some Meals Provided
Snacks
Social Gatherings
Pet Friendly
Company Retreats
Dental Insurance
Life insurance
Health Savings Account (HSA)

Guardant Health is a mission-driven company where patients are the inspiration that drives us every day. By connecting with patients and caregivers, we gain insights into the challenges they face at all stages of the journey. When you join us, you...

376 jobs
MATCH
Calculating your matching score...
FUNDING
DEPARTMENTS
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
April 24, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
Someone from OH, Marysville just viewed Security Specialist at Anduril Industries
Photo of the Rise User
Someone from OH, Cincinnati just viewed Learning Content Designer at QuantHub
Photo of the Rise User
Someone from OH, Tallmadge just viewed Manufacturing and Process Engineer at CVRx
Q
Someone from OH, Columbus just viewed Part-Time Medical Assistant at QualDerm Partners
Photo of the Rise User
Someone from OH, Cincinnati just viewed Summer 2025 Intern – Finance – Michigan at Stryker
Photo of the Rise User
Someone from OH, Cleveland just viewed Remote Customer Service Representative at Conduent
Photo of the Rise User
Someone from OH, Cleveland just viewed Customer Support Team Lead (6-month Contract) at Jane App