обновлено 3 дня назад
Director of Compliance & AI Governance
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Director of Compliance & AI Governance (Healthcare SaaS/AI): Owning and evolving compliance programs for an AI-native healthcare revenue-cycle platform with an accent on HITRUST, SOC 2, HIPAA, and AI governance. Focus on automating evidence collection, implementing continuous control monitoring, translating NIST AI RMF requirements into operational controls, and supporting enterprise customer trust.
Location: Hybrid, with at least 3 days per week onsite at the South San Francisco headquarters.
Company
builds generative AI solutions for healthcare revenue-cycle operations, helping health systems improve clinical documentation, coding, and operational efficiency.
What you will do
- Own HITRUST CSF, SOC 2 Type II, and HIPAA certification and audit programs from control design through remediation.
- Develop compliance roadmaps and drive cross-functional adoption of regulatory requirements.
- Build an AI governance program based on the NIST AI RMF, including model risk assessments, policies, and documentation.
- Automate GRC processes, evidence collection, continuous control monitoring, policy drafting, control mapping, and audit preparation.
- Manage the policy lifecycle, including reviews, exceptions, attestations, version control, and framework mapping.
- Support customer security reviews, enterprise sales cycles, audits, BAAs, trust-center materials, vendor risk management, training, and incident-response exercises.
Requirements
- 8+ years of experience in security compliance, GRC, or risk management, including 2+ years leading a team or function.
- Hands-on expertise with HITRUST CSF, SOC 2 Type II, HIPAA Security and Privacy Rules, and NIST AI RMF.
- Experience running certification and audit cycles end to end and translating AI governance standards into controls for systems handling PHI.
- Experience with GRC and continuous control monitoring platforms such as Vanta, Drata, or Hyperproof, plus automated evidence collection.
- Experience using AI tools such as ChatGPT or Claude to improve compliance workflows.
- Ability to work onsite at the South San Francisco headquarters at least 3 days per week.
Nice to have
- Experience with ISO 27001, ISO 42001, or HITRUST AI certifications.
- Familiarity with Okta, Kandji/Iru, SentinelOne, Nightfall, AWS, and modern security operations.
- Knowledge of CCPA/CPRA, state health data laws, or GDPR.
- Scripting or low-code automation skills with Python, Zapier, or Tray.io.
- CISSP, CISA, CIPP/US, HCISPP, or HITRUST CCSFP certification.
Culture & Benefits
- Flexible paid time off.
- Health, dental, and vision coverage, with employer HSA contributions.
- Generous parental leave and company-paid life insurance.
- Home office stipend, phone and internet reimbursement, commuting benefits, and paid holidays.
- 401(k) plan and an inclusive, collaborative work environment.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
1 день назад
Compliance Lead (Healthcare AI)
1 день назад
Senior Director of Information Risk & Governance (Healthcare)
231 300 - 272 100$
Decagon
2 дня назад
Governance, Risk, and Compliance Manager (AI)
190 000 - 275 000$
3 дня назад
Compliance Management Lead (FedRAMP)
108 960 - 130 000$
16 часов назад
Manager, Security Governance & Risk (AI Governance)
7 дней назад