This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security & Compliance Manager based in United States.
This role owns the day-to-day operational backbone of a growing security and compliance program within a remote, AI-enabled healthcare environment.
You will coordinate risk assessments, penetration testing, remediation, vendor security reviews, and compliance activities across the organization.
The position combines hands-on security operations with governance, documentation, project management, and cross-functional collaboration.
You will work closely with senior security leadership while independently driving execution and ensuring critical actions reach completion.
A major focus will be strengthening HIPAA compliance and building toward a formal SOC 2 or HITRUST-ready posture.
You will also help establish practical security controls for devices, identity and access, third-party vendors, incidents, and AI tools handling sensitive information.
This is an opportunity to build scalable security processes from the ground up in a fast-moving healthcare startup.
Accountabilities
-
Own the daily operation of the security program, including Security Risk Assessment cadence, penetration-test coordination, remediation tracking, phishing simulations, and annual security-awareness training.
-
Draft and maintain security policies and procedures for leadership review, ensuring documentation evolves alongside organizational and regulatory requirements.
-
Lead vendor security assessments and Business Associate Agreement reviews across the third-party ecosystem.
-
Monitor MDM and BYOD compliance, partnering with IT and managed service providers on device enrollment and endpoint-security status.
-
Act as the day-to-day lead for incident and breach response, escalating matters to senior security leadership according to established response procedures.
-
Support identity and access management improvements, including SSO implementation and deployment of a company-wide password manager.
-
Prepare recurring security and compliance reporting for leadership and board-level discussions, including risk status and forward-looking roadmaps.
-
Evaluate and implement compliance-automation platforms such as Drata, Vanta, or comparable solutions to support SOC 2 or HITRUST readiness.
-
Track remediation actions from risk assessments, audits, and vendor reviews through completion using established security-program tracking processes.
-
Establish and maintain AI security guardrails, including policies governing the handling of protected health information when using AI-enabled tools.
-
Maintain comprehensive records covering security controls, risks, incidents, vendor assessments, remediation activities, and strategic initiatives.
-
Build repeatable security and compliance processes that can scale with the organization while maintaining strong operational discipline.
Requirements
-
3–6+ years of experience in security compliance, IT security, GRC, or a related field.
-
Direct experience with HIPAA Security Rule requirements, Security Risk Assessments, and vendor or BAA risk reviews, preferably within healthcare or another regulated environment.
-
Demonstrated ability to manage security calendars, coordinate multiple stakeholders, and drive remediation items through to closure.
-
Experience working with a fractional or contractor CISO, managed service provider, or external security advisor.
-
Ability to translate technical security risks and requirements into clear, concise communications for leadership and board-level audiences.
-
Strong documentation, organization, project management, and follow-through skills.
-
Ability to work independently and take ownership in a fast-paced, remote startup environment.
-
Experience preparing for or achieving SOC 2 or HITRUST certification is a plus.
-
Familiarity with compliance automation platforms such as Drata, Vanta, or similar tools is desirable.
-
Experience with MDM and endpoint-security solutions, Google Workspace security controls such as DLP and Vault, and password-manager deployments is beneficial.
-
Experience building security and compliance processes from scratch in an early-stage or high-growth organization is a plus.
-
Familiarity with AI governance and security considerations, particularly for tools that may process protected health information, is desirable.
Benefits
-
Annual compensation range of $132,000–$140,000.
-
Fully remote work opportunity.
-
Opportunity to take ownership of a growing security and compliance program.
-
Exposure to HIPAA-regulated healthcare operations and AI-enabled technology.
-
Opportunity to build scalable security processes and controls in a high-growth environment.
-
Collaboration with senior security and product leadership.
-
Potential to contribute to SOC 2 or HITRUST readiness and broader security-program maturity.
-
Opportunity to shape practical governance and security standards for emerging AI use cases.