
Senior Manager, Security & Compliance
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in New York.
• Oversee the HITRUST certification process from the initial kickoff to final completion, encompassing gap assessments, control mapping, remediation, and management of assessors.
• Take full ownership of the SOC 2 Type II process from start to finish, which includes collecting evidence, managing auditor relationships, and resolving gaps.
• Ensure compliance with HIPAA security and privacy controls, maintain core policies, and fulfill BAA obligations.
• Evaluate Leap’s security posture and provide a prioritized roadmap for improvements and tooling.
• Implement controls, policies, and procedures throughout the organization.
• Collaborate with Engineering to facilitate implementation across Google Cloud Platform (GCP) and the data stack.
• Evaluate new vendors and tools, including those related to AI.
• Conduct ongoing reviews of third-party risks.
• Complete security questionnaires, address security sections in RFPs, and conduct controls reviews.
• Identify security obligations within client and partner agreements.
• Create a library for responses and establish a repeatable review process.
• Represent Leap during interactions with client and partner security teams.
• Select and manage relationships with external security partners.
• Keep leadership updated on the status of security posture, risks, and compliance.
• Identify areas where further investment in security is necessary.
• Minimum of 7 years of experience in healthcare information security, governance/risk/compliance (GRC), or IT auditing.
• Proven experience managing at least one complete SOC 2 Type II audit cycle.
• In-depth knowledge of SOC 2, HIPAA, and HITRUST frameworks.
• Experience in building a security or compliance program from the ground up, or managing one end-to-end as an early security hire in a startup or growth-stage company.
• Practical experience in completing security questionnaires and representing a company in discussions with enterprise or health plan security teams.
• Strong understanding of HIPAA Security and Privacy Rules.
• Experience in managing patient health information (PHI) in a B2B healthcare environment.
• Technical expertise in cloud infrastructure, preferably GCP.
• Familiarity with modern data stacks.
• Ability to review controls and guide engineers during implementation.
• Comfortable making decisions that involve significant commitments for the company.
• Bonus: hands-on experience with HITRUST certification.
• Bonus: experience in health tech, digital health, or benefits.
• Bonus: experience with health plans and large self-funded employers.
• Bonus: familiarity with ISO 27001.
• Bonus: experience using Vanta, Drata, or Secureframe.
• Bonus: holding CISSP, CISA, CISM, or CRISC certifications.
• Equity/stock options.
• Competitive total rewards package.
• Comprehensive benefits.
• Equal opportunity employer dedicated to promoting diversity in perspectives, experiences, and identities.
• Application limit: up to 3 applications within any 90-day timeframe.
• Candidates not offered a position may reapply for the same role after a 60-day waiting period.
Yordas Group
Yordas Group
Get handpicked remote jobs straight to your inbox weekly.