9 дней назад
Security & Compliance Manager (GRC), US-based
190 000 - 220 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security & Compliance Manager (GRC), US-based (Healthcare SaaS): Owning Collectly’s customer-facing security program, audits, certifications, compliance tooling, vendor risk, incident response, privacy, and AI governance with an accent on HIPAA, SOC 2, HITRUST, PCI DSS, and customer security diligence. Focus on automating evidence collection, handling technical security reviews, building an AI governance framework, and making threat-based compliance decisions across a healthcare payments platform.
Location: Remote, US-based
Salary: $190,000–$220,000 per year
Company
provides a patient billing and payments platform for US healthcare providers, handling protected health information and card payments while integrating with major EHRs.
What you will do
- Own customer-facing security and compliance, including questionnaires, AI governance reviews, live InfoSec calls, procurement portals, reattestations, escalations, audit requests, and security documentation.
- Manage HITRUST i1, SOC 2 Type 2, PCI DSS, HIPAA risk analysis, penetration testing, access reviews, and business continuity and disaster recovery exercises.
- Administer Vanta and security scanners, automate evidence collection from CI, infrastructure-as-code, identity, endpoint, and cloud systems, and reduce manual control evidence.
- Manage BAAs, security exhibits, DPAs, subprocessors, tiered vendor reviews, and annual vendor attestations.
- Maintain policies, training, phishing simulations, incident response runbooks, breach notification timelines, and the exception management process.
- Serve as HIPAA Privacy Officer and build an AI governance framework covering model inventory, human oversight, monitoring, and emerging healthcare AI requirements.
Requirements
- Extensive security compliance or GRC experience, including work in healthcare SaaS or another PHI-handling environment.
- Ownership of SOC 2 and HITRUST programs, plus deep knowledge of the HIPAA Security, Privacy, and Breach Notification Rules and BAAs.
- Hands-on experience with Vanta or a comparable compliance automation platform.
- Ability to apply security frameworks independently, with familiarity or interest in NIST AI RMF and ISO 42001.
- Ability to participate independently in technical discussions involving architecture, infrastructure-as-code, access control, and cloud configuration.
- Strong threat-modeling judgment and ability to assess exploitability, compensating controls, applicability, and escalation needs.
Nice to have
- Software engineering or security engineering background.
- PCI DSS experience in a payments context.
- CIPP/US, HCISPP, CISSP, or HITRUST CCSFP certification.
Culture & Benefits
- Fully remote work with unlimited paid time off.
- Fully paid medical, dental, and vision coverage for employees and dependents.
- Stock options and a 401(k) with company matching.
- Student loan contribution support.
Hiring process
- Introductory conversation with the CTO.
- Working session answering a real inbound security questionnaire, followed by a scenario conversation and cross-functional interviews.
- No take-home assignment; active research is expected during the exercise.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
11 дней назад
Lead Security Analyst - GRC (Cybersecurity)
172 500 - 215 625$
Wispr Flow
10 дней назад
Security Assurance & GRC Lead (AI)
150 000 - 190 000$
12 дней назад
Director of Cyber Security (Cybersecurity)
200 000 - 245 000$
12 дней назад
Chief Information Security Officer (CISO) (Healthcare)
299 000 - 344 000$
12 дней назад
Security Team Lead (MSP)
10 дней назад