
Risk & Compliance Lead
Posted 4 days ago

Posted 4 days ago
This is a fully remote position, open to applicants in Tennessee.
• Take ownership of and enhance Hi Rasmus' risk and compliance program, focusing on privacy and security compliance practices.
• Lead risk assessments, conduct policy reviews, prepare for audits, manage evidence, and spearhead continuous improvement initiatives.
• Define the long-term risk and compliance strategy as the organization expands.
• Develop scalable programs to meet changing requirements and priorities.
• Create and manage processes for customer security evaluations, HECVATs, questionnaires, and due diligence inquiries.
• Establish and maintain the customer-facing Security Center and trust resources.
• Collaborate with Sales and Customer Success during customer evaluations and procurement activities.
• Oversee Data Processing Agreements, Business Associate Agreements, security exhibits, and associated terms.
• Ensure that contractual terms and compliance obligations are consistently applied across customer engagements.
• Work with internal stakeholders and external legal counsel when specialized legal advice is required.
• Maintain policies, standards, documentation, controls, and compliance evidence diligently.
• Coordinate audits, assessments, certifications, and remediation efforts.
• Design and implement security awareness and compliance training programs.
• Provide practical risk-management guidance for teams.
• Collaborate with external auditors, consultants, and compliance vendors.
• Utilize data, evidence, and prioritization to allocate resources to significant risks.
• Work closely with Engineering, Product, Sales, Customer Success, Finance, and Leadership teams.
• Offer leadership with data-driven insights into risks, priorities, and progress.
• Seamlessly integrate risk and compliance into company operations without unnecessary bureaucracy.
• Over 5 years of experience leading or supporting risk, compliance, privacy, security, or related programs within SaaS, healthcare technology, or another regulated sector.
• Proven experience in building or enhancing risk and compliance programs rather than just maintaining them.
• Background in supporting customer security assessments, vendor evaluations, due diligence, enterprise procurement processes, and/or compliance-related customer contracts.
• Practical knowledge of HIPAA and experience applying privacy and security regulations in a business context.
• Experience in preparing for or assisting with security audits, certifications, or compliance evaluations.
• Excellent written communication skills, with the ability to simplify complex requirements into clear, actionable guidance.
• Strong business acumen and ability to collaborate effectively with both technical and non-technical teams.
• Familiarity with GDPR, CCPA, or other privacy frameworks.
• Experience with SOC 2, ISO 27001, HITRUST, NIST, or similar standards.
• Background in healthcare, behavioral health, education, or another highly regulated field.
• Knowledge of HECVATs, VPATs, accessibility requirements, or enterprise procurement processes.
• Experience in a growing SaaS organization where processes and priorities change rapidly.
• Flexible working hours aligned with US time zones, with some morning overlap with European hours; Eastern Time is optimal, while Pacific or other time zones are suitable for those who can start earlier.
• 100% covered health, dental, and vision premium for employee-only standard plan (Family can join too, with a variable cost).
• Employer Sponsored Short-Term Disability Coverage.
• Employer Sponsored Life Insurance.
• Optional group benefits: AD&D, long-term disability.
• Participation in a 401k plan through Empower.
• Opportunities for professional development.
• Room for advancement within the organization.
• Paid Time Off: 10 vacation days, 5 sick days, 7 paid holidays + 3 floating holidays for maximum flexibility.
• All Parents/Caregivers: 6 weeks of fully paid parental leave.
• Birthing Parents: Up to 14 weeks of paid parental leave.
• Fully remote and flexible work environment—work from wherever suits you best!
• Chance to make a significant impact in the Autism healthcare sector.
• Flat organizational structure with open communication.
• Emphasis on work-life balance.
• Real impact, real growth.
Brightidea
Eli Lilly and Company
Cisco
GitLab
Get handpicked remote jobs straight to your inbox weekly.