Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Governance, Risk & Compliance Lead image - Rise Careers
Job details

Governance, Risk & Compliance Lead - job 2 of 2

Company Description

Guardant Health is a leading precision oncology company focused on guarding wellness and giving every person more time free from cancer. Founded in 2012, Guardant is transforming patient care and accelerating new cancer therapies by providing critical insights into what drives disease through its advanced blood and tissue tests, real-world data and AI analytics. Guardant tests help improve outcomes across all stages of care, including screening to find cancer early, monitoring for recurrence in early-stage cancer, and treatment selection for patients with advanced cancer. For more information, visit guardanthealth.com and follow the company on LinkedInX (Twitter) and Facebook.

Job Description

About the Role:

Guardant is seeking a Governance, Risk & Compliance (GRC) Lead with 5-10 years of experience to drive the evolution of our Information Security Governance, Risk, and Compliance program. At Guardant, we value innovation over rigid adherence to traditional compliance methods—our ideal candidate is a forward-thinking, non-dogmatic,  new leader who sees compliance as a business enabler rather than a bottleneck. After gaining experience supporting  GRC programs designed or led by others, you are eager to build one that challenges the status quo.  This role is designed for someone who is willing to leverage native workplace technology to eliminate manual, repetitive, and performative tasks, allowing the organization to focus on our core mission.

The ideal candidate will have a mastery of compliance frameworks and a passion for streamlining governance processes through automation, modern risk management techniques, and proactive controls. At Guardant, we believe in staying "Connected to the Work," meaning that even in leadership roles, team members are expected to stay hands-on—contributing as engineers or analysts in their field. If you're looking to redefine GRC, drive efficiency, and integrate security seamlessly into business operations, we’d love to hear from you.

Essential Duties and Responsibilities:

  • Develop, maintain, and enhance the security governance, risk, and compliance program, emphasizing automation, right-sized controls, and proactive compliance monitoring, ensuring alignment with business objectives and regulatory requirements (e.g., HIPAA Security Rule, ISO 27001, GDPR,SOX-404).
  • Lead the organization’s pursuit of ISO 27001 certification, ensuring compliance and continuous improvement of best practices.
  • Drive a culture of accountability through success metrics and goals through continuous monitoring.
  • Develop and maintain security policies, standards, and procedures that align with business goals and regulatory requirements.
  • Identify and address governance gaps, ensuring timely implementation of recommendations across business units.
  • Implement automated compliance and security controls to continuously monitor security risks, exceptions, testing, and overall compliance.
  • Conduct and oversee internal assessments and security control testing, ensuring compliance with regulations and protecting sensitive data.
  • Prepare and present risk assessments, and remediation plans to leadership, tracking progress toward resolution.
  • Partner with Privacy, Compliance and Regulatory teams to ensure security operations meet regulatory and business needs.
  • Establish and maintain a Security Trust Program to support customer engagements, audits, and assessments.
  • Act as a trusted advisor to both business and technical teams, ensuring GRC goals align with the overall security strategy.
  • Provide insights and recommendations to the CISO on regulatory changes and emerging risks.
  • Restructure and streamline the third-party risk management program, ensuring vendors meet security and compliance requirements.

Qualifications

Essential Qualifications:

  • 5+ years of experience in Governance, Risk, and Compliance (GRC) or a related field, with at least 2 years in a leadership or program management role.
  • Experience in healthcare settings preferred but not required.
  • Experience with qualitative risk approaches or the ambition to fast ramp on such approaches.
  • Strong knowledge of information security management, governance, and compliance principles, including laws, regulations, and industry standards.
  • Deep understanding of regulatory frameworks and industry standards, including:
    • Required: ISO 27001, HIPAA, GDPR, 21 CFR Part 11.
    • Preferred: NIST CSF, NIST SP 800-53 r5, NIST SP 800-30 r1, Secure Controls Framework (SCF).
  • Strong familiarity with cybersecurity and cloud security frameworks, experience with the Secure Controls Framework desired but not required.
  • Experience with risk management, compliance, resilience, security policy and standards, vendor risk management, security metrics, and security training & awareness.
  • Proficiency with Atlassian tools (JIRA, Confluence) for designing projects, dashboards, and dynamic documentation.
  • Conceptual understanding of security technologies across both on-premises and cloud infrastructures.
  • Certifications (Preferred, but Not Required): CISSP, CISA, CRISC
  • Exceptional ability to convey technical and security concepts to diverse stakeholders, including non-technical audiences.
  • Skilled in tackling compliance challenges and making informed risk-based decisions.
  • Proven ability to establish credibility and build trust across the organization, particularly with engineers, researchers, and G&A functions.
  • Sustained capability to stay updated with evolving regulations, industry best practices, and emerging risks.

Additional Information

Hybrid Work Model: At Guardant Health, we have defined days for in-person/onsite collaboration and work-from-home days for individual-focused time. All U.S. employees who live within 50 miles of a Guardant facility will be required to be onsite on Mondays, Tuesdays, and Thursdays. We have found aligning our scheduled in-office days allows our teams to do the best work and creates the focused thinking time our innovative work requires. At Guardant, our work model has created flexibility for better work-life balance while keeping teams connected to advance our science for our patients.

For positions based in Redwood City, CA, the base salary range for this full-time position is $128,000 to $176,000. The range does not include benefits, and if applicable, bonus, commission, or equity.

Within the range, individual pay is determined by work location and additional factors, including, but not limited to, job-related skills, experience, and relevant education or training. If you are selected to move forward, the recruiting team will provide details specific to the factors above.

Employee may be required to lift routine office supplies and use office equipment. Majority of the work is performed in a desk/office environment; however, there may be exposure to high noise levels, fumes, and biohazard material in the laboratory environment. Ability to sit for extended periods of time.

Guardant Health is committed to providing reasonable accommodations in our hiring processes for candidates with disabilities, long-term conditions, mental health conditions, or sincerely held religious beliefs. If you need support, please reach out to [email protected]

Guardant Health is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status and will not be discriminated against on the basis of disability.

All your information will be kept confidential according to EEO guidelines.

To learn more about the information collected when you apply for a position at Guardant Health, Inc. and how it is used, please review our Privacy Notice for Job Applicants.

Please visit our career page at: http://www.guardanthealth.com/jobs/

Guardant Health Glassdoor Company Review
3.3 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
Guardant Health DE&I Review
3.54 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
CEO of Guardant Health
Guardant Health CEO photo
Helmy Eltoukhy and AmirAli Talasaz
Approve of CEO

Average salary estimate

$152000 / YEARLY (est.)
min
max
$128000K
$176000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Governance, Risk & Compliance Lead, Guardant Health

If you're passionate about driving change and seeking a role that redefines the Governance, Risk & Compliance landscape, then the opportunity at Guardant Health in Palo Alto, California, is perfect for you! As the GRC Lead, you will play a pivotal role in enhancing our Information Security Governance, Risk, and Compliance program. At Guardant, we prioritize innovation over traditional compliance methods. We’re on the lookout for someone with 5-10 years of experience who isn’t afraid to challenge the status quo. You’ll have the chance to streamline processes by leveraging automation and proactive controls, ensuring that compliance aligns with our business goals while enabling growth. You will be spearheading our journey to obtain ISO 27001 certification and leading internal assessments to protect sensitive data. We believe in a hands-on approach; even in a leadership capacity, you’ll be actively involved in executing key projects. Join us to cultivate a culture of accountability and continuous learning, while being a trusted advisor across technical and business teams. If command over various compliance frameworks excites you and you’re keen on making a tangible impact in the healthcare space, we invite you to be part of our mission to transform patient care through innovative cancer therapies.

Frequently Asked Questions (FAQs) for Governance, Risk & Compliance Lead Role at Guardant Health
What are the primary responsibilities of the Governance, Risk & Compliance Lead at Guardant Health?

The Governance, Risk & Compliance Lead at Guardant Health is responsible for enhancing the security governance, risk, and compliance program, focusing on automation, compliance monitoring, and alignment with regulatory requirements such as HIPAA, ISO 27001, and GDPR. You will lead the organization's pursuit of ISO 27001 certification and drive internal assessments to uphold standards while advising various teams on compliance matters.

Join Rise to see the full answer
What qualifications are required to apply for the Governance, Risk & Compliance Lead position at Guardant Health?

Candidates for the Governance, Risk & Compliance Lead role at Guardant Health should have 5+ years of experience in GRC or a related field, including at least 2 years in a leadership role. A strong understanding of compliance frameworks such as ISO 27001, HIPAA, and GDPR is essential, alongside skills in risk management, security policy development, and automation techniques.

Join Rise to see the full answer
How does the Governance, Risk & Compliance Lead support ISO 27001 certification at Guardant Health?

In the Governance, Risk & Compliance Lead role at Guardant Health, you will spearhead the organization's effort to obtain ISO 27001 certification by ensuring continuous compliance and improvement of best practices. You will develop and maintain security policies while addressing governance gaps, overseeing internal assessments, and ensuring timely implementation of security controls.

Join Rise to see the full answer
What tools and platforms should a Governance, Risk & Compliance Lead at Guardant Health be familiar with?

The Governance, Risk & Compliance Lead at Guardant Health should be proficient in Atlassian tools such as JIRA and Confluence for project management, documentation, and dashboard design. Familiarity with cybersecurity frameworks and security technologies in both cloud and on-premises environments is also essential for effectively managing the GRC program.

Join Rise to see the full answer
What team dynamics can the Governance, Risk & Compliance Lead expect at Guardant Health?

At Guardant Health, the Governance, Risk & Compliance Lead will work in a collaborative environment that values innovation and hands-on contributions. You will partner closely with Privacy, Compliance, and Regulatory teams, while also engaging with various business units to ensure that GRC goals align seamlessly with the overall security strategy.

Join Rise to see the full answer
Common Interview Questions for Governance, Risk & Compliance Lead
What inspired you to apply for the Governance, Risk & Compliance Lead position at Guardant Health?

When answering this question, reflect on your passion for compliance combined with your desire to innovate. Mention specifically how Guardant Health’s mission aligns with your personal values and career goals, emphasizing your proactive approach to addressing compliance challenges in the healthcare industry.

Join Rise to see the full answer
Can you describe your experience with ISO 27001 compliance?

Highlight any direct experience you have in obtaining ISO 27001 certification or in managing compliance frameworks. Discuss your understanding of the requirements involved, your role in implementing controls, and any strategies you employed to achieve and maintain compliance.

Join Rise to see the full answer
How do you prioritize risks when addressing compliance issues?

Emphasize your systematic approach to risk assessment, mentioning any frameworks or methodologies you apply. Explain how you analyze the likelihood and impact of risks, and how you prioritize them to address the most critical issues effectively.

Join Rise to see the full answer
What methods do you utilize for compliance monitoring and reporting?

Discuss the technologies and tools you are familiar with, such as automated dashboards, and how you structure your compliance monitoring processes. Detail the metrics you focus on and your approach to providing transparent, actionable reports to stakeholders.

Join Rise to see the full answer
How do you ensure your team understands compliance requirements?

Talk about your experience in conducting training sessions and workshops to enhance your team's understanding of compliance. Cite examples where you tailored your communication style to diverse audiences, ensuring they grasp critical compliance concepts and their importance.

Join Rise to see the full answer
What strategies do you have for managing vendor risk?

Explain your approach to vendor risk management, including due diligence processes, regular assessments, and establishing clear security requirements for vendors. Share how you maintain ongoing relationships with vendors to ensure they continue to comply with your organization’s standards.

Join Rise to see the full answer
Describe a challenging compliance issue you've managed in your previous roles.

Prepare to give a specific example that illustrates your problem-solving skills. Discuss the context of the challenge, the steps you took to address it, and the outcome, emphasizing any lessons learned and how they informed your approach to future compliance issues.

Join Rise to see the full answer
How do you stay updated on changing regulations and compliance standards?

Illustrate your commitment to continuous learning by mentioning the resources and networks you rely on, such as industry publications, professional organizations, and webinars. Explain how you leverage these insights to adapt your strategies and keep your team informed.

Join Rise to see the full answer
What is your experience with security control testing?

Detail your familiarity with various testing methodologies and tools for security control assessment. Discuss your approach to planning and executing these tests and how you analyze the results to make timely adjustments to controls.

Join Rise to see the full answer
In your opinion, how can we reinvigorate our approach to Governance, Risk & Compliance?

Share innovative ideas that demonstrate your forward-thinking mindset. Propose ways to simplify processes, integrate automation, and foster a culture of compliance that views it as a business enabler rather than a barrier.

Join Rise to see the full answer
Similar Jobs
Posted 2 days ago

Guardant Health seeks a passionate Associate Account Executive to promote their innovative cancer screening solutions in the Winner, South Dakota area.

Guardant Health Hybrid Walnut Creek, California, United States
Posted 2 days ago

Join Guardant Health as an Account Executive, where you will leverage your sales expertise to transform cancer screening practices.

Photo of the Rise User
Dental Insurance
Flexible Spending Account (FSA)
Health Savings Account (HSA)
Disability Insurance
Vision Insurance
Paid Holidays

Join Dollar Shave Club as an IT Support Engineer II and enable our teams to maximize their productivity through effective technology solutions.

Posted 5 days ago

Join Inetum as an Incident Manager and Project Leader to drive strategic themes for server and application maintenance in an international environment.

Photo of the Rise User

As a Security Operations Analyst at Springer Nature, you'll play a key role in safeguarding our digital assets through proactive threat management in a hybrid work environment.

PAE Hybrid OCONUS-Australia-Alice Springs
Posted 5 days ago

Join Amentum as an Information Systems Security Officer in Alice Springs, Australia, where you will enhance our cybersecurity measures and ensure compliance with standards.

Deutsche Bank seeks a dynamic Enterprise Security Architect to guide the security architecture strategy while managing a global team.

Photo of the Rise User

Join Blue Cross Minnesota as an ITSM Engineer to enhance service delivery through innovative IT service management solutions.

Tek Spikes Remote No location specified
Posted 11 days ago

As a Lead SOC DV Sr Engineer with Intverse, you will lead security operations to safeguard our systems and data integrity.

Posted 14 days ago

Trigyn Technologies is looking for a highly skilled Senior Oracle Fusion Middleware Systems Administrator to guide innovative middleware hosting services remotely.

Photo of the Rise User
Dare to be Different
Diversity of Opinions
Inclusive & Diverse
Customer-Centric
Transparent & Candid
Growth & Learning
Photo of the Rise User
Inclusive & Diverse
Diversity of Opinions
Work/Life Harmony
Dare to be Different
Reward & Recognition
Empathetic
Take Risks
Growth & Learning
Transparent & Candid
Mission Driven
Passion for Exploration
Feedback Forward
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Learning & Development
Paid Time-Off
Maternity Leave
Social Gatherings
Photo of the Rise User
Inclusive & Diverse
Empathetic
Collaboration over Competition
Growth & Learning
Transparent & Candid
Medical Insurance
Dental Insurance
Mental Health Resources
Life insurance
Disability Insurance
Child Care stipend
Employee Resource Groups
Learning & Development
Photo of the Rise User
Inclusive & Diverse
Empathetic
Collaboration over Competition
Growth & Learning
Transparent & Candid
Medical Insurance
Dental Insurance
Mental Health Resources
Life insurance
Disability Insurance
Child Care stipend
Employee Resource Groups
Learning & Development

Guardant Health is a mission-driven company where patients are the inspiration that drives us every day. By connecting with patients and caregivers, we gain insights into the challenges they face at all stages of the journey. When you join us, you...

377 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
April 23, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!