Green Card Data Governance Lead Jobs
Data Governance Lead roles qualify for EB-2 or EB-3 green card sponsorship through the PERM labor certification process, which requires your employer to document that no qualified U.S. worker is available. Employers in financial services, healthcare, and enterprise tech regularly sponsor this role given the specialized intersection of data policy, compliance frameworks, and stakeholder management it demands.
Find Green Card Data Governance Lead JobsOverview
Showing 5 of 338+ Data Governance Lead jobs










See all 338+ Data Governance Lead Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Data Governance Lead roles.
Get Access To All Jobs
INTRODUCTION
Virta Health is on a mission to reverse metabolic disease in one billion people. Current treatment approaches aren’t working—over half of US adults have either type 2 diabetes or prediabetes, and obesity rates are at an all-time high. Virta is changing this by helping people reverse their metabolic condition through innovations in technology, personalized nutrition, and virtual care delivery reinvented from the ground up. We have raised over $350 million from top-tier investors, and partner with the largest health plans, employers, and government organizations to help their employees and members restore their health and take back their lives. Join us on our mission to reverse metabolic disease in one billion people.
As our Senior Manager of GRC, you will have a high-impact, transformative opportunity to lead Virta’s Governance, Risk, and Compliance (GRC) function in a highly automated, AI-first environment. You will be the ultimate champion of security compliance and risk culture across the enterprise—collaborating closely with Sales to unblock commercial velocity, supervising compliance audits, and hardening our HIPAA, HITRUST, and SOC 2 frameworks. If you are passionate about driving risk governance, designing automated evidence collection, and enabling employees with frictionless SaaS reviews and compliance workflows, this role is your opportunity to redefine healthcare compliance.
Responsibilities
Information Security GRC Program Management: Maintain and mature Virta Health's information security compliance program, policies, procedures, and controls to address emerging risks as the organization scales. Continuously evaluate and enhance the GRC framework to align with industry best practices and regulatory requirements. This is inclusive of:
- Lead GRC & Compliance Automation: Oversee Virta’s GRC function, scaling our platform (Vanta) to automate continuous evidence collection, ensuring audit-readiness and defending our HIPAA, HITRUST CSF, and SOC 2 certifications.
- Enable Commercial Velocity (RFPs & Security Questionnaires): Partner directly with Sales and Customer Success to navigate enterprise customer evaluations and security reviews, communicating Virta's strong security compliance posture to external stakeholders.
- Own Policy, Risk & Compliance Governance: Define and own Virta's security policy lifecycle, exception management processes, vendor risk assessments, and executive risk reporting. Conduct regular risk assessments to identify vulnerabilities, assess potential impact, and guide business owners on mitigation.
- Champion GRC Employee Experience: Manage the administrative security queue for Virta employees. Design and optimize frictionless ticketing workflows (such as Zendesk or Jira) and SLAs for access governance reviews, SaaS tool compliance evaluations, and policy exception requests.
- Coordinate Cross-Functional Security Alignment: Collaborate closely with IT, Enterprise Security Engineering, and Product Development teams to ensure operational GRC policies map seamlessly into our technical architectures and evolving AI governance frameworks (e.g., ISO 42001, NIST AI RMF).
- Security Awareness & Compliance Training: Champion a culture of security awareness across all levels of the organization. Design and deliver targeted training programs so employees understand their roles in maintaining compliance and data privacy.
90 Day Plan
Within your first 90 days at Virta, we expect you will do the following:
- First 30 days: Deep dive into our current GRC tool configurations (Vanta), evaluate our control framework status, meet with key stakeholders across IT and Security Engineering, and take ownership of the daily employee SaaS review and GRC request queue.
- Day 30-60: Establish baseline SLAs for employee compliance requests (SaaS reviews, access reviews) and optimize automation workflows to streamline customer security questionnaire and RFP responses. Initiate coordination with external auditors and partners for upcoming assessments.
- Day 60-90: Complete a comprehensive internal risk assessment and present a clean, unified risk and compliance metric dashboard to senior leadership covering GRC control health, exception trends, and upcoming audit preparation timelines.
BASIC QUALIFICATIONS
- 7+ years of dedicated experience in Cybersecurity GRC, IT Auditing, or Information Security Compliance, with at least 2+ years leading programs or managing teams in regulated environments (such as Healthcare or Digital Health).
- Direct, hands-on experience managing and maintaining at least one of the major security and healthcare frameworks, specifically HITRUST CSF, HIPAA, and SOC 2.
- Proven track record of leveraging modern SaaS GRC automation platforms (such as Vanta or Drata) to scale continuous compliance programs.
- Outstanding client-facing communication skills with a track record of partnering with Sales/CS teams to navigate complex enterprise security evaluations, vendor questionnaires, and RFP processes.
- Successfully designed and implemented repeatable AI-enabled workflows that address team bottlenecks and improve efficiency.
- Ability to operate in gray areas, finding the right balance between corporate risk tolerance, operational efficiency, and regulatory requirements.
- Strong cross-functional leadership skills with the ability to influence technical and non-technical business partners to align on security compliance objectives.
VALUES-DRIVEN CULTURE
Virta’s company values drive our culture, so you’ll do well if:
- You put people first and take care of yourself, your peers, and our patients equally
- You have a strong sense of ownership and take initiative while empowering others to do the same
- You prioritize positive impact over busy work
- You have no ego and understand that everyone has something to bring to the table regardless of experience
- You appreciate transparency and promote trust and empowerment through open access of information
- You are evidence-based and prioritize data and science over seniority or dogma
- You take risks and rapidly iterate
Is this role not quite what you're looking for? Join our Talent Community and follow us on Linkedin to stay connected!
Virta has a location based compensation structure. Starting pay will be based on a number of factors and commensurate with qualifications & experience. For this role, the compensation range is $161,500-209,000/year. Information about Virta’s benefits is on our Careers page at: https://www.virtahealth.com/careers.
As part of your duties at Virta, you may come in contact with sensitive patient information that is governed by HIPAA. Throughout your career at Virta, you will be expected to follow Virta's security and privacy procedures to ensure our patients' information remains strictly confidential. Security and privacy training will be provided.
As a remote-first company, our team is spread across various locations with office hubs in Denver and San Francisco.
Clinical roles: We currently do not hire in the following states: AK, HI, RI
Corporate roles: We currently do not hire in the following states: AK, AR, DE, HI, ME, MS, NM, OK, SD, VT, WI.
Virta uses Ashby as its applicant tracking system, which incorporates AI-powered tools (provided by OpenAI, AWS, and Google Gemini) in certain aspects of the recruiting process, including application review, candidate screening, and interview note taking; your data is not used to train AI models, and all final hiring decisions are made by Virta Health personnel. For more information, see Ashby's AI Terms at https://www.ashbyhq.com/resources/terms-ai-features
See all 338+ Green Card Data Governance Lead Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Green Card Data Governance Lead Jobs.
Get Access To All JobsTips for Finding Green Card Sponsorship in Data Governance Lead
Align your credentials to EB-2 requirements
Data Governance Lead positions typically qualify under EB-2 when the role requires a master's degree in information management, computer science, or a related field. Document any graduate-level credentials and specialized certifications like CDMP before your employer initiates the PERM process.
Target employers with active PERM filing history
Search the DOL's OFLC Wage Search to identify employers who have filed PERM applications for data governance or data management roles. Companies already familiar with the process move faster and are less likely to withdraw sponsorship mid-filing due to compliance concerns.
Use Migrate Mate to find sponsoring employers
Filter your job search on Migrate Mate to surface Data Governance Lead openings at employers with verified green card sponsorship history. This cuts the time spent cold-applying to companies that haven't sponsored PERM cases in your occupation category.
Clarify the prevailing wage tier before accepting an offer
DOL assigns your role a prevailing wage level at PERM filing, which must match or fall below your actual offered salary. Ask your employer which SOC code they plan to file under so you can verify the wage tier using the OFLC Wage Search before signing your offer letter.
Build documentation that supports specialty occupation status
Employers sometimes underestimate how closely USCIS scrutinizes data governance roles at the I-140 stage. Gather job descriptions from published industry frameworks, O*NET occupation profiles, and internal governance charters that confirm a bachelor's degree or higher in a specific field is standard for the role.
Understand how your country of birth affects your green card timeline
EB-2 and EB-3 priority dates move independently, and applicants born in India or China face backlogs that can stretch years. Review the monthly Visa Bulletin with your employer's attorney to decide whether concurrent filing of the I-140 and I-485 is available to you now.
Green Card Data Governance Lead: Frequently Asked Questions
Does a Data Governance Lead role typically qualify for EB-2 or EB-3 sponsorship?
Most Data Governance Lead positions qualify for EB-2 because they require at least a bachelor's degree in a specific field such as information management, computer science, or business analytics, and often a master's degree in practice. If the employer's internal requirements meet the advanced-degree threshold, EB-2 is the stronger filing path. EB-3 remains available for roles where a four-year degree is the stated minimum.
How does PERM green card sponsorship differ from H-1B for this role?
H-1B visa sponsorship is temporary and subject to an annual lottery, while PERM-based green card sponsorship leads to lawful permanent residency with no cap concerns at the EB-3 level for most countries. The PERM process requires the employer to conduct a supervised recruitment campaign and certify no qualified U.S. worker was available, which takes longer upfront but results in a permanent immigration outcome rather than a renewable status.
What documentation should I prepare before my employer files PERM for a data governance role?
Gather your official transcripts, any graduate-level diplomas, and professional certifications relevant to data governance such as the Certified Data Management Professional credential. You'll also need a detailed employment history that maps your past roles to the specialty occupation requirements USCIS reviews at the I-140 stage. Gaps between your degree field and your current role should be addressed with supporting documentation before your employer's attorney drafts the labor certification.
How do I find Data Governance Lead jobs where employers are already open to green card sponsorship?
Migrate Mate lets you search for Data Governance Lead openings filtered by employers with verified PERM and employment-based sponsorship history, so you're not wasting applications on companies that have never navigated the labor certification process. Targeting employers with existing PERM filings in data management or governance occupations significantly shortens the path from job offer to filing.
Can my employer start the PERM process while I'm on H-1B status?
Yes, your employer can initiate PERM labor certification while you maintain valid H-1B status. Filing early matters because your priority date is established when USCIS receives the approved I-140 petition, not when PERM is filed. For applicants born in countries without backlogs, concurrent filing of the I-140 and I-485 may be possible once PERM is certified, potentially compressing the overall timeline.