Own the day-to-day operations of a growing security and compliance program in a remote, AI-enabled healthcare environment. Coordinate risk assessments, penetration testing, remediation, vendor security reviews, incident response, and compliance reporting. Lead HIPAA compliance improvements and build toward SOC 2 or HITRUST readiness while establishing security controls for devices, identity, third parties, and AI tools.
Key Highlights
Key Responsibilities
Technical Skills Required
Benefits & Perks
Nice to Have
Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security & Compliance Manager based in United States.
This role owns the day-to-day operational backbone of a growing security and compliance program within a remote, AI-enabled healthcare environment.
You will coordinate risk assessments, penetration testing, remediation, vendor security reviews, and compliance activities across the organization.
The position combines hands-on security operations with governance, documentation, project management, and cross-functional collaboration.
You will work closely with senior security leadership while independently driving execution and ensuring critical actions reach completion.
A major focus will be strengthening HIPAA compliance and building toward a formal SOC 2 or HITRUST-ready posture.
You will also help establish practical security controls for devices, identity and access, third-party vendors, incidents, and AI tools handling sensitive information.
This is an opportunity to build scalable security processes from the ground up in a fast-moving healthcare startup.
Accountabilities
- Own the daily operation of the security program, including Security Risk Assessment cadence, penetration-test coordination, remediation tracking, phishing simulations, and annual security-awareness training.
- Draft and maintain security policies and procedures for leadership review, ensuring documentation evolves alongside organizational and regulatory requirements.
- Lead vendor security assessments and Business Associate Agreement reviews across the third-party ecosystem.
- Monitor MDM and BYOD compliance, partnering with IT and managed service providers on device enrollment and endpoint-security status.
- Act as the day-to-day lead for incident and breach response, escalating matters to senior security leadership according to established response procedures.
- Support identity and access management improvements, including SSO implementation and deployment of a company-wide password manager.
- Prepare recurring security and compliance reporting for leadership and board-level discussions, including risk status and forward-looking roadmaps.
- Evaluate and implement compliance-automation platforms such as Drata, Vanta, or comparable solutions to support SOC 2 or HITRUST readiness.
- Track remediation actions from risk assessments, audits, and vendor reviews through completion using established security-program tracking processes.
- Establish and maintain AI security guardrails, including policies governing the handling of protected health information when using AI-enabled tools.
- Maintain comprehensive records covering security controls, risks, incidents, vendor assessments, remediation activities, and strategic initiatives.
- Build repeatable security and compliance processes that can scale with the organization while maintaining strong operational discipline.
Interested in remote work opportunities in Cyber Security? Discover Cyber Security Remote Jobs featuring exclusive positions from top companies that offer flexible work arrangements.
- 3–6+ years of experience in security compliance, IT security, GRC, or a related field.
- Direct experience with HIPAA Security Rule requirements, Security Risk Assessments, and vendor or BAA risk reviews, preferably within healthcare or another regulated environment.
- Demonstrated ability to manage security calendars, coordinate multiple stakeholders, and drive remediation items through to closure.
- Experience working with a fractional or contractor CISO, managed service provider, or external security advisor.
- Ability to translate technical security risks and requirements into clear, concise communications for leadership and board-level audiences.
- Strong documentation, organization, project management, and follow-through skills.
- Ability to work independently and take ownership in a fast-paced, remote startup environment.
- Experience preparing for or achieving SOC 2 or HITRUST certification is a plus.
- Familiarity with compliance automation platforms such as Drata, Vanta, or similar tools is desirable.
- Experience with MDM and endpoint-security solutions, Google Workspace security controls such as DLP and Vault, and password-manager deployments is beneficial.
- Experience building security and compliance processes from scratch in an early-stage or high-growth organization is a plus.
- Familiarity with AI governance and security considerations, particularly for tools that may process protected health information, is desirable.
Browse our curated collection of remote jobs across all categories and industries, featuring positions from top companies worldwide.
- Annual compensation range of $132,000–$140,000.
- Fully remote work opportunity.
- Opportunity to take ownership of a growing security and compliance program.
- Exposure to HIPAA-regulated healthcare operations and AI-enabled technology.
- Opportunity to build scalable security processes and controls in a high-growth environment.
- Collaboration with senior security and product leadership.
- Potential to contribute to SOC 2 or HITRUST readiness and broader security-program maturity.
- Opportunity to shape practical governance and security standards for emerging AI use cases.
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Similar Jobs
Explore other opportunities that match your interests