
Security and Compliance Manager
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in United States.
• Take charge of the daily management of the security program, which includes overseeing the cadence of Security Risk Assessments, coordinating penetration tests, tracking remediation efforts, conducting phishing simulations, and organizing the annual security awareness training calendar.
• Create and maintain Policies & Procedures for review and approval by the CISO and leadership, ensuring documentation remains up-to-date.
• Lead security assessments of vendors and conduct audits for Business Associate Agreements across the vendor landscape.
• Manage compliance monitoring for MDM/BYOD devices in collaboration with the IT Systems Administrator and Managed Service Provider (MSP).
• Act as the primary point of contact for incident and breach responses, escalating issues to the Chief Privacy Officer (CPO) and contractor CISO as necessary.
• Assist in enhancing identity and access management processes, including Single Sign-On (SSO) and the implementation of a company-wide password manager.
• Prepare regular risk and compliance status reports for the board, along with a forward-looking roadmap.
• Oversee the evaluation and implementation of compliance-automation tools, such as Drata or Vanta.
• Monitor and ensure the closure of open items from Security Risk Assessments, audits, and vendor reviews using the Security Program Tracker.
• Contribute to the definition and maintenance of AI security guardrails, particularly regarding policies for handling Protected Health Information (PHI) in AI tools.
• Keep comprehensive documentation and records related to security controls, risks, incidents, vendor audits, and initiatives on the roadmap.
• 3–6+ years of experience in security compliance, IT security, or GRC (governance, risk, and compliance) roles.
• Direct experience with HIPAA Security Rule requirements, conducting Security Risk Assessments, and performing vendor/BAA risk reviews, preferably in healthcare or another regulated sector.
• Proficient in managing a security calendar and ensuring remediation items are tracked to completion across various stakeholders.
• Experience collaborating with a fractional or contractor CISO, Managed Service Provider (MSP), or external security advisor, with the ability to translate technical risks into clear, non-technical reports for leadership or board presentations.
• Strong skills in documentation and project management.
• Capable of working autonomously in a dynamic, remote startup environment.
• Nice-to-have: Direct experience in preparing for or achieving SOC2 or HITRUST certification.
• Nice-to-have: Familiarity with compliance automation platforms like Drata, Vanta, or similar.
• Nice-to-have: Experience with MDM/endpoint tools, Google Workspace security controls (DLP, Vault), and rolling out password managers.
• Nice-to-have: Background in an early-stage or high-growth startup, comfortable with building processes from the ground up.
• Nice-to-have: Understanding of AI governance/security considerations for tools that handle PHI.
• Competitive salary and performance-based bonuses.
• Flexible work schedule and remote work options.
• Professional development opportunities and support for certifications.
• Comprehensive health, dental, and vision insurance.
• Generous paid time off and holiday policy.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.