J

Security & Compliance Manager (HIPAA, SOC 2, HITRUST Readiness) - Remote

Jobgether • United State
Remote
Apply Now
AI Summary

Own the day-to-day operations of a growing security and compliance program in a remote, AI-enabled healthcare environment. Coordinate risk assessments, penetration testing, remediation, vendor security reviews, incident response, and compliance reporting. Lead HIPAA compliance improvements and build toward SOC 2 or HITRUST readiness while establishing security controls for devices, identity, third parties, and AI tools.

Key Highlights
Day-to-day ownership of security risk assessment cadence, penetration testing coordination, remediation tracking, and security awareness
Focus on HIPAA compliance and building a SOC 2 or HITRUST-ready security and compliance posture
Hands-on security operations plus governance, documentation, vendor/BAA reviews, incident response leadership, and compliance automation evaluation
Key Responsibilities
Own the daily operation of the security program, including security risk assessment cadence, penetration-test coordination, and remediation tracking.
Draft and maintain security policies and procedures for leadership review, ensuring documentation evolves with organizational and regulatory requirements.
Lead vendor security assessments and Business Associate Agreement (BAA) reviews across the third-party ecosystem.
Monitor MDM and BYOD compliance, partnering with IT and managed service providers on device enrollment and endpoint-security status.
Act as the day-to-day lead for incident and breach response, escalating matters to senior security leadership according to established procedures.
Support identity and access management improvements, including SSO implementation and deployment of a company-wide password manager.
Prepare recurring security and compliance reporting for leadership and board-level discussions, including risk status and forward-looking roadmaps.
Evaluate and implement compliance-automation platforms to support SOC 2 or HITRUST readiness.
Track remediation actions from risk assessments, audits, and vendor reviews through completion using established security-program tracking processes.
Establish and maintain AI security guardrails, including policies for handling protected health information when using AI-enabled tools.
Maintain comprehensive records covering security controls, risks, incidents, vendor assessments, remediation activities, and strategic initiatives.
Build repeatable security and compliance processes that can scale with the organization while maintaining strong operational discipline.
Technical Skills Required
HIPAA Security Rule Security Risk Assessments SOC 2 or HITRUST readiness
Benefits & Perks
Annual compensation range of $132,000–$140,000
Fully remote work opportunity
Opportunity to take ownership of a growing security and compliance program
Nice to Have
Experience preparing for or achieving SOC 2 or HITRUST certification
Familiarity with compliance automation platforms such as Drata or Vanta
Experience with MDM and endpoint-security solutions, Google Workspace security controls such as DLP and Vault, and password-manager deployments
Experience building security and compliance processes from scratch in an early-stage or high-growth organization
Familiarity with AI governance and security considerations for tools that may process protected health information
Experience working with a fractional or contractor CISO, managed service provider, or external security advisor

Job Description


This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security & Compliance Manager based in United States.

This role owns the day-to-day operational backbone of a growing security and compliance program within a remote, AI-enabled healthcare environment.

You will coordinate risk assessments, penetration testing, remediation, vendor security reviews, and compliance activities across the organization.

The position combines hands-on security operations with governance, documentation, project management, and cross-functional collaboration.

You will work closely with senior security leadership while independently driving execution and ensuring critical actions reach completion.

A major focus will be strengthening HIPAA compliance and building toward a formal SOC 2 or HITRUST-ready posture.

You will also help establish practical security controls for devices, identity and access, third-party vendors, incidents, and AI tools handling sensitive information.

This is an opportunity to build scalable security processes from the ground up in a fast-moving healthcare startup.

Accountabilities

  • Own the daily operation of the security program, including Security Risk Assessment cadence, penetration-test coordination, remediation tracking, phishing simulations, and annual security-awareness training.
  • Draft and maintain security policies and procedures for leadership review, ensuring documentation evolves alongside organizational and regulatory requirements.
  • Lead vendor security assessments and Business Associate Agreement reviews across the third-party ecosystem.
  • Monitor MDM and BYOD compliance, partnering with IT and managed service providers on device enrollment and endpoint-security status.
  • Act as the day-to-day lead for incident and breach response, escalating matters to senior security leadership according to established response procedures.
  • Support identity and access management improvements, including SSO implementation and deployment of a company-wide password manager.
  • Prepare recurring security and compliance reporting for leadership and board-level discussions, including risk status and forward-looking roadmaps.
  • Evaluate and implement compliance-automation platforms such as Drata, Vanta, or comparable solutions to support SOC 2 or HITRUST readiness.
  • Track remediation actions from risk assessments, audits, and vendor reviews through completion using established security-program tracking processes.
  • Establish and maintain AI security guardrails, including policies governing the handling of protected health information when using AI-enabled tools.
  • Maintain comprehensive records covering security controls, risks, incidents, vendor assessments, remediation activities, and strategic initiatives.
  • Build repeatable security and compliance processes that can scale with the organization while maintaining strong operational discipline.

Requirements

  • 3–6+ years of experience in security compliance, IT security, GRC, or a related field.
  • Direct experience with HIPAA Security Rule requirements, Security Risk Assessments, and vendor or BAA risk reviews, preferably within healthcare or another regulated environment.
  • Demonstrated ability to manage security calendars, coordinate multiple stakeholders, and drive remediation items through to closure.
  • Experience working with a fractional or contractor CISO, managed service provider, or external security advisor.
  • Ability to translate technical security risks and requirements into clear, concise communications for leadership and board-level audiences.
  • Strong documentation, organization, project management, and follow-through skills.
  • Ability to work independently and take ownership in a fast-paced, remote startup environment.
  • Experience preparing for or achieving SOC 2 or HITRUST certification is a plus.
  • Familiarity with compliance automation platforms such as Drata, Vanta, or similar tools is desirable.
  • Experience with MDM and endpoint-security solutions, Google Workspace security controls such as DLP and Vault, and password-manager deployments is beneficial.
  • Experience building security and compliance processes from scratch in an early-stage or high-growth organization is a plus.
  • Familiarity with AI governance and security considerations, particularly for tools that may process protected health information, is desirable.

Benefits

  • Annual compensation range of $132,000–$140,000.
  • Fully remote work opportunity.
  • Opportunity to take ownership of a growing security and compliance program.
  • Exposure to HIPAA-regulated healthcare operations and AI-enabled technology.
  • Opportunity to build scalable security processes and controls in a high-growth environment.
  • Collaboration with senior security and product leadership.
  • Potential to contribute to SOC 2 or HITRUST readiness and broader security-program maturity.
  • Opportunity to shape practical governance and security standards for emerging AI use cases.

How Jobgether Works

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Why Apply Through Jobgether?

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.


Similar Jobs

Explore other opportunities that match your interests

Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Not Applicable

WorkOS

United State

Software Security Engineer

Cyber Security
•
1d ago
Visa Sponsorship Relocation Remote
Job Type Contract
Experience Level Mid-Senior level

Mindlance

United State

Senior Corporate Security Specialist II

Cyber Security
•
2d ago
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Not Applicable

actblue

United State

Subscribe our newsletter

New Things Will Always Update Regularly