Milliman Logo

Milliman

Governance, Risk & Compliance (GRC) Manager

Posted Yesterday
Be an Early Applicant
In-Office or Remote
Hiring Remotely in Seattle, WA
118K-223K Annually
Senior level
In-Office or Remote
Hiring Remotely in Seattle, WA
118K-223K Annually
Senior level
Manage and supervise the global Governance, Risk & Compliance team, oversee vendor risk management and security contract review, coordinate internal assessments and external audits across 60+ offices, support regulatory compliance (HIPAA, GDPR, CCPA), liaise with IT, Legal, Finance and executives, and drive GRC program planning, performance tracking, and targeted security training.
The summary above was generated by AI

POSITION SUMMARY:

This position manages the corporate governance, risk, and compliance (GRC) teams, including internal security review, security contract review, and vendor risk management. The GRC Program Manager supervises employees across experience levels and works with IT compliance stakeholders to assess risk and provide practical guidance aligned with Milliman’s risk appetite.

The position works with 60+ offices worldwide and their local administrators to coordinate internal assessments, support external audits, and identify and assess critical vendors. The position reports directly to the Chief Information Security Officer (CISO) and resides within Global Corporate Services (GCS).

The GRC Manager will support program planning, staff supervision, and execution of GRC-related projects. This position will oversee the technical work of GRC team personnel and work directly with IT leads, managers, the project management office (PMO), and executives to communicate relevant business and technical information. The GRC Manager will set performance expectations for team members and provide regular, constructive feedback.

RESPONSIBILITIES:

  • Manage the Global GRC team across regions and serve as an escalation point for complex issues.
  • Support Talent Management: Support hiring, performance reviews, compensation discussions, and staffing decisions.
  • Support Client Engagement: Work with GCS Legal and business stakeholders on information security contract requirements, escalating to the CISO as needed.
  • Monitor Regulatory Requirements: Monitor applicable requirements, including HIPAA, GDPR, and CCPA, and assess impact to GRC responsibilities.
  • Support Compliance Initiatives: Work with GDPT and internal stakeholders to support regulatory and client compliance requirements.
  • Oversee Vendor Risk Management: Oversee vendor security risk processes and support alignment with vendor management.
  • Track Team Performance: Monitor team performance against SLAs and address gaps as needed.
  • Report on Program Performance: Provide program updates and align GRC work with organizational priorities.
  • Coordinate with IT, Legal, Finance, and GCS leadership on risk and compliance priorities.
  • Communicate and Share risk and compliance updates and support targeted security training when policies or gaps require it.
FUNCTIONAL COMPETENCIES:
  • Ability to find opportunities for efficiencies, using state of the art software tools and AI
  • Risk Management: Understanding of risk management methodologies, frameworks, and principles for measuring, reporting, and mitigating risk.
  • Communication & Collaboration: Ability to communicate clearly with business and technical stakeholders and translate technical concepts into practical guidance.
  • Project & Time Management: Ability to manage multiple projects, prioritize work, and support timely completion of assigned activities.
  • Global & Cross-Functional Engagement: Ability to work with stakeholders across geographically dispersed offices and support coordination across business functions.
SKILLS & QUALIFICATIONS REQUIRED:
  • Bachelor's degree in Risk Management, Information Systems, Computer Science, or Cybersecurity (or equivalent years of relevant professional hands-on work experience).
  • The ideal candidate should have minimum 7 years of hands-on IT Cybersecurity or Risk Management experience.
SKILLS & QUALIFICATIONS PREFERRED:
  • Certified in at least one of the following: Risk and Information Systems Control (CRISC), Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP) or willingness to obtain.
  • Experience using GRC/VRM tools and platforms.
  • Experience with HIPAA/HITRUST, GDPR, ISO 27001 /2, and other industry regulatory controls and compliance.
  • Experience within consulting or professional service organizations.
  • Experience with SharePoint administration.

LOCATION:

This is a remote role. The expected application deadline for this job is July 31, 2026.

COMPENSATION:

The overall range for this role is $117,500 - $222,985. For candidates residing in: 

  • Alaska, California, Connecticut, Illinois, Maryland, Massachusetts, New Jersey, New York City, Pennsylvania, Virginia, Washington, or the District of Columbia the range is $135,125 - $222,985. 
  •  All other locations the range is $117,500 - $193,900. 

 A combination of factors will be considered, including, but not limited to, education, relevant work experience, qualifications, skills, certifications, etc.

BENEFITS:

We offer a comprehensive benefits package designed to support employees’ health, financial security, and well-being. Benefits include: 

  • Medical, Dental and Vision – Coverage for employees, dependents, and domestic partners. 
  • Employee Assistance Program (EAP) – Confidential support for personal and work-related challenges. 
  • 401(k) Plan – Includes a company matching program and profit-sharing contributions. 
  • Discretionary Bonus Program – Recognizing employee contributions. 
  • Flexible Spending Accounts (FSA) – Pre-tax savings for dependent care, transportation, and eligible medical expenses. 
  • Paid Time Off (PTO) – Begins accruing on the first day of work. Full-time employees accrue 15 days per year, and employees working less than full-time accrue PTO on a prorated basis. 
  • Holidays – A minimum of 10 paid holidays per year. 
  • Family Building Benefits – Includes adoption and fertility assistance. 
  • Paid Parental Leave – 11 weeks of paid leave for employees who meet eligibility criteria. 
  • Life Insurance & AD&D – 100% of premiums covered by Milliman. 
  • Short-Term and Long-Term Disability – Fully paid by Milliman. 

                      ABOUT MILLIMAN:

                      Independent for over 77 years, Milliman delivers market-leading services and solutions to clients worldwide. Today, we are helping companies take on some of the world’s most critical and complex issues, including retirement funding and healthcare financing, risk management and regulatory compliance, data analytics and business transformation.

                      Through a team of professionals ranging from actuaries to clinicians, technology specialists to plan administrators, we offer unparalleled expertise in employee benefits, investment consulting, healthcare, life insurance and financial services, and property and casualty insurance.

                      EQUAL OPPORTUNITY:

                      All qualified applicants will receive consideration for employment, without regard to race, color, religion, sex, sexual orientation, national origin, disability, or status as a protected veteran.

                      #LI-REMOTE

                      Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
                      This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.

                      Milliman Cambridge, Massachusetts, USA Office

                      Cambridge, United States

                      Milliman Wakefield, Massachusetts, USA Office

                      201 Edgewater Drive, Suite 289, Wakefield, MA, United States, 01880-6215

                      Similar Jobs

                      56 Minutes Ago
                      Remote or Hybrid
                      USA
                      100K-223K Annually
                      Senior level
                      100K-223K Annually
                      Senior level
                      Machine Learning • Payments • Security • Software • Financial Services
                      Lead and mature detection and incident response lifecycle, run day-to-day SOC operations, manage on‑call readiness, drive SIEM detections and automation, coordinate cross‑team responses, maintain playbooks and run readiness exercises, mentor analysts, and ensure regulatory and post‑incident improvements.
                      Top Skills: Cloud SecurityEdrElasticEndpoint SecurityFedrampHipaaIdentity And Access ManagementIds/IpsIso 27035JIRAMitre Att&CkNist 800-61Pci DssServicenowSIEMSoc 2SplunkThreat Intelligence
                      57 Minutes Ago
                      Remote or Hybrid
                      USA
                      100K-223K Annually
                      Senior level
                      100K-223K Annually
                      Senior level
                      Machine Learning • Payments • Security • Software • Financial Services
                      Lead and develop a team of automation engineers, own test automation backlog and frameworks, drive UI/API/performance testing, integrate AI-driven testing practices, collaborate cross-functionally, hire and mentor staff, and contribute hands-on to automation and CI/CD improvements.
                      Top Skills: Agentic AiApache JmeterAWSAzureBitbucketCi/CdContainerizationCypressGCPGenerative AiGithub ActionsJavaScriptJenkinsMonitoringObservabilityPlaywrightPostmanPrompt EngineeringPythonRest ApisSeleniumTypescript
                      2 Hours Ago
                      Remote or Hybrid
                      United States
                      116K-145K Annually
                      Senior level
                      116K-145K Annually
                      Senior level
                      Artificial Intelligence • Big Data • Cloud • Information Technology • Software • Big Data Analytics • Automation
                      Lead strategy, administration, and optimization of AI tools for the SDR organization (Qualified, Gong, Microsoft Co‑Pilot). Identify AI use cases, build implementation roadmaps, define requirements and success metrics, manage pilots and vendors, monitor adoption and impact, maintain governance and documentation, and partner cross-functionally to improve SDR productivity, lead conversion, and pipeline generation.
                      Top Skills: 6SenseAi ToolsChatbotsConversational Marketing PlatformsGongGong Agent StudioLeandataMarketoMicrosoft Co-PilotQualifiedSales Engagement PlatformsSalesforce

                      What you need to know about the Boston Tech Scene

                      Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

                      Key Facts About Boston Tech

                      • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
                      • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
                      • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
                      • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
                      • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
                      • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

                      Sign up now Access later

                      Create Free Account

                      Please log in or sign up to report this job.

                      Create Free Account