TL;DR
Security Engineer II (GRC): Managing the end-to-end lifecycle of inbound security questionnaires and outbound vendor assessments with an accent on translating complex technical architecture into compliant and persuasive responses. Focus on optimizing the assessment workflow, ensuring adherence to HIPAA, HITRUST, and NIST standards, and maintaining the security response repository.
Location: Remote in the United States
Company
hirify.global is a public benefit corporation focused on empowering independent primary care by creating value-based contracts and strengthening continuity of care.
What you will do
- Manage the end-to-end lifecycle of inbound security questionnaires from partner physician practices.
- Lead security evaluations for hirify.global’s vendors, analyzing SOC2 reports, penetration test results, and self-assessments.
- Maintain and optimize the security response knowledge base, ensuring it reflects infrastructure evolution.
- Identify and implement scalable solutions for assessment workflow bottlenecks, such as self-service Trust Centers.
Requirements
- 3-5 years of experience in Governance, Risk, and Compliance, Information Security, or related fields.
- Practical experience working with SOC2, HIPAA, SOX/ITGC, HITRUST, and CPRA.
- Demonstrated experience preparing organizations for external audits and regulatory certifications.
- Hands-on experience with GRC platforms (e.g., Vanta, OneTrust, Archer, or similar).
- Must be based in the United States.
Nice to have
- Knowledge of GRC frameworks and regulations (NIST, ISO 27001).
- Skilled in leveraging GRC platforms (e.g., Vanta, OneTrust) to automate compliance.
Culture & Benefits
- Flexible work schedules and a remote-first, collaborative, inclusive culture.
- Health, dental, and vision insurance paid up to 80% for employees, dependents, and domestic partners.
- Robust time-off plan (21 days PTO in the first year), two paid volunteer days, and 11 paid holidays.
- 12 weeks paid parental leave for all new parents and six weeks paid sabbatical after six years of service.
- Educational Assistant Program and 401(k) with up to 4% match.
- Stock options.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →