Skip to content
SpoorSign in

Jobgether

Security & Compliance Manager

USRemoteFull-time

Apply Now

Posted today

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security & Compliance Manager based in United States.

This role owns the day-to-day operational backbone of a growing security and compliance program within a remote, AI-enabled healthcare environment.
You will coordinate risk assessments, penetration testing, remediation, vendor security reviews, and compliance activities across the organization.
The position combines hands-on security operations with governance, documentation, project management, and cross-functional collaboration.
You will work closely with senior security leadership while independently driving execution and ensuring critical actions reach completion.
A major focus will be strengthening HIPAA compliance and building toward a formal SOC 2 or HITRUST-ready posture.
You will also help establish practical security controls for devices, identity and access, third-party vendors, incidents, and AI tools handling sensitive information.
This is an opportunity to build scalable security processes from the ground up in a fast-moving healthcare startup.

Accountabilities

  • Own the daily operation of the security program, including Security Risk Assessment cadence, penetration-test coordination, remediation tracking, phishing simulations, and annual security-awareness training.

  • Draft and maintain security policies and procedures for leadership review, ensuring documentation evolves alongside organizational and regulatory requirements.

  • Lead vendor security assessments and Business Associate Agreement reviews across the third-party ecosystem.

  • Monitor MDM and BYOD compliance, partnering with IT and managed service providers on device enrollment and endpoint-security status.

  • Act as the day-to-day lead for incident and breach response, escalating matters to senior security leadership according to established response procedures.

  • Support identity and access management improvements, including SSO implementation and deployment of a company-wide password manager.

  • Prepare recurring security and compliance reporting for leadership and board-level discussions, including risk status and forward-looking roadmaps.

  • Evaluate and implement compliance-automation platforms such as Drata, Vanta, or comparable solutions to support SOC 2 or HITRUST readiness.

  • Track remediation actions from risk assessments, audits, and vendor reviews through completion using established security-program tracking processes.

  • Establish and maintain AI security guardrails, including policies governing the handling of protected health information when using AI-enabled tools.

  • Maintain comprehensive records covering security controls, risks, incidents, vendor assessments, remediation activities, and strategic initiatives.

  • Build repeatable security and compliance processes that can scale with the organization while maintaining strong operational discipline.

Requirements

  • 3–6+ years of experience in security compliance, IT security, GRC, or a related field.

  • Direct experience with HIPAA Security Rule requirements, Security Risk Assessments, and vendor or BAA risk reviews, preferably within healthcare or another regulated environment.

  • Demonstrated ability to manage security calendars, coordinate multiple stakeholders, and drive remediation items through to closure.

  • Experience working with a fractional or contractor CISO, managed service provider, or external security advisor.

  • Ability to translate technical security risks and requirements into clear, concise communications for leadership and board-level audiences.

  • Strong documentation, organization, project management, and follow-through skills.

  • Ability to work independently and take ownership in a fast-paced, remote startup environment.

  • Experience preparing for or achieving SOC 2 or HITRUST certification is a plus.

  • Familiarity with compliance automation platforms such as Drata, Vanta, or similar tools is desirable.

  • Experience with MDM and endpoint-security solutions, Google Workspace security controls such as DLP and Vault, and password-manager deployments is beneficial.

  • Experience building security and compliance processes from scratch in an early-stage or high-growth organization is a plus.

  • Familiarity with AI governance and security considerations, particularly for tools that may process protected health information, is desirable.

Benefits

  • Annual compensation range of $132,000–$140,000.

  • Fully remote work opportunity.

  • Opportunity to take ownership of a growing security and compliance program.

  • Exposure to HIPAA-regulated healthcare operations and AI-enabled technology.

  • Opportunity to build scalable security processes and controls in a high-growth environment.

  • Collaboration with senior security and product leadership.

  • Potential to contribute to SOC 2 or HITRUST readiness and broader security-program maturity.

  • Opportunity to shape practical governance and security standards for emerging AI use cases.

How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
 Why Apply Through Jobgether? 
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1

Request a company

Privacy

Did you apply?