Назад
Company hidden
обновлено 3 дня назад

Director of Compliance & AI Governance

Формат работы
hybrid
Тип работы
fulltime
Грейд
director
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Director of Compliance & AI Governance (Healthcare SaaS/AI): Owning and evolving compliance programs for an AI-native healthcare revenue-cycle platform with an accent on HITRUST, SOC 2, HIPAA, and AI governance. Focus on automating evidence collection, implementing continuous control monitoring, translating NIST AI RMF requirements into operational controls, and supporting enterprise customer trust.

Location: Hybrid, with at least 3 days per week onsite at the South San Francisco headquarters.

Company

hirify.global builds generative AI solutions for healthcare revenue-cycle operations, helping health systems improve clinical documentation, coding, and operational efficiency.

What you will do

  • Own HITRUST CSF, SOC 2 Type II, and HIPAA certification and audit programs from control design through remediation.
  • Develop compliance roadmaps and drive cross-functional adoption of regulatory requirements.
  • Build an AI governance program based on the NIST AI RMF, including model risk assessments, policies, and documentation.
  • Automate GRC processes, evidence collection, continuous control monitoring, policy drafting, control mapping, and audit preparation.
  • Manage the policy lifecycle, including reviews, exceptions, attestations, version control, and framework mapping.
  • Support customer security reviews, enterprise sales cycles, audits, BAAs, trust-center materials, vendor risk management, training, and incident-response exercises.

Requirements

  • 8+ years of experience in security compliance, GRC, or risk management, including 2+ years leading a team or function.
  • Hands-on expertise with HITRUST CSF, SOC 2 Type II, HIPAA Security and Privacy Rules, and NIST AI RMF.
  • Experience running certification and audit cycles end to end and translating AI governance standards into controls for systems handling PHI.
  • Experience with GRC and continuous control monitoring platforms such as Vanta, Drata, or Hyperproof, plus automated evidence collection.
  • Experience using AI tools such as ChatGPT or Claude to improve compliance workflows.
  • Ability to work onsite at the South San Francisco headquarters at least 3 days per week.

Nice to have

  • Experience with ISO 27001, ISO 42001, or HITRUST AI certifications.
  • Familiarity with Okta, Kandji/Iru, SentinelOne, Nightfall, AWS, and modern security operations.
  • Knowledge of CCPA/CPRA, state health data laws, or GDPR.
  • Scripting or low-code automation skills with Python, Zapier, or Tray.io.
  • CISSP, CISA, CIPP/US, HCISPP, or HITRUST CCSFP certification.

Culture & Benefits

  • Flexible paid time off.
  • Health, dental, and vision coverage, with employer HSA contributions.
  • Generous parental leave and company-paid life insurance.
  • Home office stipend, phone and internet reimbursement, commuting benefits, and paid holidays.
  • 401(k) plan and an inclusive, collaborative work environment.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →