Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security GRC Lead (GCP): Building Candid Health’s first in-house GRC program and continuous compliance telemetry for an autonomous healthcare revenue cycle management platform with an accent on automated evidence pipelines, compliance-as-code, and continuous controls monitoring. Focus on mapping SOC 2, HITRUST, PCI, and HIPAA controls, integrating compliance into CI/CD, and automating audit, vendor risk, and live vulnerability tracking.
Location: Hybrid in San Francisco, Denver, or New York City, United States
Company
Candid Health builds an AI-powered autonomous Revenue Cycle Management platform that automates medical claims and healthcare payment operations for U.S. healthcare organizations.
What you will do
- Build the first in-house GRC program, including automated evidence pipelines, compliance-as-code, continuous controls monitoring, dashboards, and alerts.
- Develop scripts and API integrations to collect compliance evidence directly from infrastructure, identity systems, CI/CD pipelines, and other system sources.
- Define and enforce security baselines using infrastructure-as-code and policy enforcement rules.
- Map technical controls across SOC 2, HITRUST, PCI, HIPAA, and other regulatory or industry frameworks.
- Partner with DevOps and Software Engineering to embed compliance controls into CI/CD pipelines.
- Lead technical audit readiness, external audits, vendor risk automation, and continuous risk tracking based on vulnerability and identity telemetry.
Requirements
- 3+ years of experience in a technical security role such as Security Engineering, Cloud Security, or Technical GRC.
- Proficiency in Python, TypeScript, and SQL, with hands-on experience using APIs, parsing logs, and querying databases.
- Hands-on experience with a major cloud platform; GCP is preferred.
- Experience with infrastructure-as-code tools such as Terraform, CI/CD pipelines, Git workflows, and container environments including Docker and Kubernetes.
- Familiarity with SOC 2, HITRUST, PCI, and HIPAA frameworks, as well as policy-as-code engines.
- Background in software development, DevOps, or platform engineering.
Nice to have
- Certifications such as CISSP, CISA, CRISC, AWS Certified Security – Specialty, or CCSP.
- Experience with continuous compliance platforms such as Vanta, Drata, or Anecdotes.
Culture & Benefits
- Work in a hybrid engineering role based in San Francisco, Denver, or New York City.
- Collaborate with Legal on Medicare and Medicaid compliance.
- Partner with Legal and Finance on due diligence and future compliance projects.
- Help replace point-in-time audits with continuous, engineering-driven compliance monitoring.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →