Lead Security & Compliance Analyst (Healthcare)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Lead Security & Compliance Analyst (Healthcare): Managing the end-to-end compliance audit cycle and implementing technical security controls within an AWS environment with an accent on GRC and vulnerability management. Focus on coordinating SOC/HITRUST audits, remediating cloud security findings, and automating evidence collection.
Location: Must be based in the US. This role is not eligible for employer visa sponsorship.
Salary: $80,000 - $130,000
Company
is a leading digital ordering platform for medical equipment and supplies, connecting health systems, health plans, and suppliers to improve patient care.
What you will do
- Own SOC 1, SOC 2, HITRUST CSF, and HITRUST AI audit cycles from scoping and evidence collection to remediation.
- Develop and implement compliance policies and procedures for HIPAA, HITRUST, and SOC frameworks.
- Manage compliance automation and trust platforms such as Drata and SafeBase.
- Lead the vulnerability management program, including scanning, triage, and driving remediation with engineering teams.
- Remediate security findings across the AWS environment (EKS, WAF, Shield, IAM) and the SaaS stack.
- Support security incident response, fraud investigations, and forensic log analysis.
Requirements
- 4+ years of combined experience in security compliance/GRC and hands-on technical security.
- Must be legally authorized to work in the United States at the time of application.
- Direct experience supporting at least one full cycle of SOC 1/2 or HITRUST audits.
- Working knowledge of HIPAA Security and Privacy requirements.
- Hands-on experience with vulnerability scanning and AWS security concepts (IAM, WAF, logging).
- Ability to write clear policies, procedures, and technical remediation tickets.
Nice to have
- Experience with compliance automation platforms like Drata or Vanta.
- Experience in healthcare or other highly regulated industries.
- Certifications such as CISSP, CISA, CRISC, HITRUST CCSFP, or CISM.
- Experience with SIEM tools, forensic log analysis, or eDiscovery requests.
Culture & Benefits
- Comprehensive Medical, Dental, and Vision coverage with employer HSA contributions.
- 401(k) retirement plan and Equity Incentive Plan.
- Annual company-wide bonus of up to 15%.
- Remote-first culture with flexible vacation and 5 additional "Summer Fridays" off.
- Stipends for home office, wellness, monthly internet, and annual learning and development.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →