Security & Compliance Manager, GRC

atCollectlyRemoteUS flagUnited StatesFull-timeComplianceMid-levelSenior$190k – $220k/year

Posted Sep 17

This is a fully remote position, open to applicants in United States.

📋 Description

• Take full ownership of security and compliance processes as the sole individual in this role.

• Develop a scalable security and compliance strategy while minimizing unnecessary operational burdens.

• Respond to customer security inquiries.

• Complete AI governance assessments and responsible-AI evaluations for the AI patient billing agent.

• Facilitate live security discussions with prospective clients' InfoSec teams.

• Oversee health-system procurement platforms, including Archer, ProcessUnity, and Venminder.

• Manage annual customer reattestation cycles.

• Address customer security escalations, incident communications, and customer-facing root cause analyses (RCAs).

• Organize audits for clients exercising their right-to-audit clauses.

• Distribute SOC 2, HITRUST certifications, penetration test summaries, and subprocessor notices under NDA.

• Create and maintain a public trust center, a standard security package, and an answer library.

• Oversee readiness for HITRUST i1 and SOC 2 Type 2, including evidence, auditor management, and remediation tracking.

• Manage PCI DSS Self-Assessment Questionnaires (SAQs), collect processor Attestation of Compliance (AOCs), and define scopes for card-present and card-not-present transactions.

• Conduct the annual HIPAA Security Risk Analysis and maintain the risk register.

• Supervise the penetration testing lifecycle, which includes scheduling, scoping, remediation tracking, and customer-facing summaries.

• Carry out quarterly user access reviews.

• Coordinate Business Continuity Plan (BCP) and Disaster Recovery (DR) tabletops and annual testing.

• Administer Vanta and security scanning tools.

• Extract evidence from various systems, including CI, infrastructure-as-code, identity provider, endpoint detection and response (EDR), and cloud configuration systems.

• Aim to reduce manually evidenced controls each year.

• Manage Business Associate Agreements (BAAs), security exhibits, Data Processing Agreements (DPAs), and the subprocessor inventory.

• Conduct tiered vendor security assessments and annual vendor reattestation.

• Maintain policies and manage security awareness programs, HIPAA training, phishing simulations, and completion tracking.

• Own the incident response program, which includes runbooks, tabletops, and incident coordination.

• Supervise breach notification timelines and contractual notification requirements.

• Maintain a documented exception process with an approver, expiration date, and compensating control.

• Serve as the HIPAA Privacy Officer.

• Monitor state privacy laws such as CCPA/CPRA and Washington's My Health My Data.

• Establish AI governance for the AI patient billing agent, which encompasses model inventory, human oversight, and monitoring.

• Keep track of emerging state regulations regarding AI in healthcare and AI-generated patient communications.

• Note that remediation engineering is not part of this role; it falls under DevOps responsibilities.

• Be aware that shipping decisions are not under this role's purview; document risks and escalate issues while the CTO prioritizes tasks.

• This position does not involve gatekeeping in design or code reviews.


⛳️ Requirements

• Significant experience in security compliance or Governance, Risk, and Compliance (GRC), particularly in healthcare SaaS or other environments handling Protected Health Information (PHI).

• Proven track record of managing SOC 2 and HITRUST processes as an owner rather than a contributor.

• In-depth understanding of HIPAA regulations, including the Security Rule, Privacy Rule, Breach Notification Rule, BAAs, and the principle of minimum necessary.

• Practical experience with Vanta or a similar compliance automation tool.

• Strong familiarity with security frameworks and the capability to independently apply unfamiliar frameworks.

• Ability to work with NIST AI Risk Management Framework (RMF) and ISO 42001 standards.

• Proficient in drafting customer-facing documents.

• Capable of engaging in technical discussions involving architecture diagrams, infrastructure-as-code, access control models, and cloud configurations.

• Skilled in evaluating threat models and assessing exploitability, mitigations, applicability, and escalation requirements.

• A background in software engineering or security engineering is highly desirable, though not mandatory.

• Experience with PCI DSS in a payments context is an asset.

• Relevant certifications such as CIPP/US, HCISPP, CISSP, and HITRUST CCSFP are preferred.

• Demonstrated ability to actively research information during collaborative sessions.


🏝️ Benefits

• Unlimited Paid Time Off (PTO).

• Comprehensive medical, dental, and vision insurance fully covered for you and your dependents.

• Stock options available.

• 401(k) plan with a generous company match.

• Contributions towards student loan repayments.

People also viewed

LabConnect22 hours ago

Head of IT Governance, Risk, Compliance

US flagTennessee OnlyFull-timeCompliance
ApplyView job
Ripple Effect1 day ago

Compliance Analyst

US flagMaryland OnlyFull-timeCompliance$85.3k – $98.1k/year
ApplyView job
Binance1 day ago

Team Lead – Compliance Monitoring, Assurance & Testing

AE flagUnited Arab Emirates (UAE) OnlyFull-timeCompliance
ApplyView job
biBerk Business Insurance1 day ago

Claims Compliance Analyst – Workers' Compensation

US flagUnited States OnlyFull-timeCompliance$77k – $96.5k/year
ApplyView job
Doppel1 day ago

Director, Governance, Risk & Compliance

US flagUnited States OnlyFull-timeCompliance
ApplyView job
PingWind Inc. (SDVOSB)1 day ago

Risk and Compliance Analyst

US flagUnited States OnlyFull-timeCompliance
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers