
Security & Compliance Manager, GRC
Posted Sep 17

Posted Sep 17
This is a fully remote position, open to applicants in United States.
• Take full ownership of security and compliance processes as the sole individual in this role.
• Develop a scalable security and compliance strategy while minimizing unnecessary operational burdens.
• Respond to customer security inquiries.
• Complete AI governance assessments and responsible-AI evaluations for the AI patient billing agent.
• Facilitate live security discussions with prospective clients' InfoSec teams.
• Oversee health-system procurement platforms, including Archer, ProcessUnity, and Venminder.
• Manage annual customer reattestation cycles.
• Address customer security escalations, incident communications, and customer-facing root cause analyses (RCAs).
• Organize audits for clients exercising their right-to-audit clauses.
• Distribute SOC 2, HITRUST certifications, penetration test summaries, and subprocessor notices under NDA.
• Create and maintain a public trust center, a standard security package, and an answer library.
• Oversee readiness for HITRUST i1 and SOC 2 Type 2, including evidence, auditor management, and remediation tracking.
• Manage PCI DSS Self-Assessment Questionnaires (SAQs), collect processor Attestation of Compliance (AOCs), and define scopes for card-present and card-not-present transactions.
• Conduct the annual HIPAA Security Risk Analysis and maintain the risk register.
• Supervise the penetration testing lifecycle, which includes scheduling, scoping, remediation tracking, and customer-facing summaries.
• Carry out quarterly user access reviews.
• Coordinate Business Continuity Plan (BCP) and Disaster Recovery (DR) tabletops and annual testing.
• Administer Vanta and security scanning tools.
• Extract evidence from various systems, including CI, infrastructure-as-code, identity provider, endpoint detection and response (EDR), and cloud configuration systems.
• Aim to reduce manually evidenced controls each year.
• Manage Business Associate Agreements (BAAs), security exhibits, Data Processing Agreements (DPAs), and the subprocessor inventory.
• Conduct tiered vendor security assessments and annual vendor reattestation.
• Maintain policies and manage security awareness programs, HIPAA training, phishing simulations, and completion tracking.
• Own the incident response program, which includes runbooks, tabletops, and incident coordination.
• Supervise breach notification timelines and contractual notification requirements.
• Maintain a documented exception process with an approver, expiration date, and compensating control.
• Serve as the HIPAA Privacy Officer.
• Monitor state privacy laws such as CCPA/CPRA and Washington's My Health My Data.
• Establish AI governance for the AI patient billing agent, which encompasses model inventory, human oversight, and monitoring.
• Keep track of emerging state regulations regarding AI in healthcare and AI-generated patient communications.
• Note that remediation engineering is not part of this role; it falls under DevOps responsibilities.
• Be aware that shipping decisions are not under this role's purview; document risks and escalate issues while the CTO prioritizes tasks.
• This position does not involve gatekeeping in design or code reviews.
• Significant experience in security compliance or Governance, Risk, and Compliance (GRC), particularly in healthcare SaaS or other environments handling Protected Health Information (PHI).
• Proven track record of managing SOC 2 and HITRUST processes as an owner rather than a contributor.
• In-depth understanding of HIPAA regulations, including the Security Rule, Privacy Rule, Breach Notification Rule, BAAs, and the principle of minimum necessary.
• Practical experience with Vanta or a similar compliance automation tool.
• Strong familiarity with security frameworks and the capability to independently apply unfamiliar frameworks.
• Ability to work with NIST AI Risk Management Framework (RMF) and ISO 42001 standards.
• Proficient in drafting customer-facing documents.
• Capable of engaging in technical discussions involving architecture diagrams, infrastructure-as-code, access control models, and cloud configurations.
• Skilled in evaluating threat models and assessing exploitability, mitigations, applicability, and escalation requirements.
• A background in software engineering or security engineering is highly desirable, though not mandatory.
• Experience with PCI DSS in a payments context is an asset.
• Relevant certifications such as CIPP/US, HCISPP, CISSP, and HITRUST CCSFP are preferred.
• Demonstrated ability to actively research information during collaborative sessions.
• Unlimited Paid Time Off (PTO).
• Comprehensive medical, dental, and vision insurance fully covered for you and your dependents.
• Stock options available.
• 401(k) plan with a generous company match.
• Contributions towards student loan repayments.
LabConnect
Ripple Effect
Binance
biBerk Business Insurance
Get handpicked remote jobs straight to your inbox weekly.