
Lead Security & Compliance Analyst
Posted Jul 29

Posted Jul 29
This is a fully remote position, open to applicants in United States.
• Take full ownership of SOC 1, SOC 2, HITRUST CSF, and HITRUST AI audits from start to finish, including scoping, evidence gathering, auditor coordination, and addressing findings.
• Create, update, modify, and enforce compliance policies, procedures, and practices related to security frameworks (HIPAA, HITRUST, SOC) as well as overall compliance and operations.
• Oversee our compliance automation and trust platforms (Drata, SafeBase), managing control monitoring and responding to customer security questionnaires.
• Collaborate with external vendors and clients to collect necessary information for compliance reviews, validations, and audits.
• Conduct third-party/vendor risk assessments and respond to customer security evaluations and external inquiries.
• Provide HIPAA and security awareness training while assessing control effectiveness through internal audits.
• Manage the vulnerability management program: including scanning, triage, prioritization, and driving remediation efforts with engineering teams.
• Investigate and resolve security findings within our AWS environment (EKS, WAF, Shield, CloudFront, IAM) and SaaS applications.
• Analyze external attack surface findings (e.g., SecurityScorecard) and implement necessary fixes, including adjustments to CSP headers, subresource integrity, and TLS configurations.
• Assist in security incident response through log analysis, forensic evidence collection, and containment measures.
• Support fraud and forensic investigations by analyzing authentication logs, extracting targeted data, and preserving evidence for legal and compliance purposes.
• Enhance our security tools and automate evidence collection, utilizing scripting (Python, Bash) to eliminate manual tasks.
• A minimum of 4 years of combined experience in security compliance/GRC and practical technical security roles.
• Direct involvement in supporting SOC 1/SOC 2 and/or HITRUST audits, having completed at least one full audit cycle.
• Proficient understanding of HIPAA Security and Privacy requirements.
• Practical experience with vulnerability scanning and remediation, as well as familiarity with interpreting technical findings (CVEs, misconfigurations, cloud security issues).
• Knowledge of AWS security concepts (IAM, security groups, logging, WAF).
• Capability to draft clear policies and procedures, along with equally clear remediation tickets.
• Medical, Dental, and Vision Coverage: Comprehensive plans with options for low-to-no-cost premiums.
• Employer HSA Contribution: Company-funded contributions to your Health Savings Account.
• 401(k) Retirement Plan
• Equity Incentive Plan
• Annual Company-Wide Bonus: Opportunity for up to 15% bonus based on company performance.
• Remote-First Culture: We are remote-first with a dedicated NYC office and reimbursement options for co-working spaces.
• Flexible Vacation Policy
• Summer Fridays: 5 additional Fridays off during the summer (separate from PTO).
• Home Office and Wellness Stipend
• Monthly Internet Stipend
• Annual Learning and Development Stipend
The Home Depot
Lennar
Golden 1 Credit Union
NuHarbor Security
Get handpicked remote jobs straight to your inbox weekly.