Security & Compliance Manager (GRC)

C
CollectlyHealthcare SaaS
US-basedFull-TimeManager
Salary$190,000 - $220,000 per year
Apply NowOpens the employer's application page

Job Details

Required Skills
HIPAA

Requirements

  • Extensive experience in security compliance or GRC, with specific background in healthcare SaaS or PHI-handling environments.
  • Proven history as an owner of SOC 2 and HITRUST programs.
  • Deep HIPAA fluency including Security Rule, Privacy Rule, and Breach Notification Rule.
  • Hands-on experience with Vanta or comparable compliance automation platforms.
  • Ability to interpret technical conversations with DevOps regarding architecture, infrastructure-as-code, and access control models.
  • Strong understanding of threat modeling and ability to assess control implementation and exploitability.
  • Exceptional written communication skills for creating customer-facing security documentation.
  • Ability to work effectively in a technical, engineering-adjacent role.
  • Experience with PCI DSS in a payments context is a plus.
  • Relevant certifications such as CIPP/US, HCISPP, CISSP, or HITRUST CCSFP are highly regarded.

Responsibilities

  • Own end-to-end security and compliance programs, including HITRUST i1, SOC 2 Type 2, and PCI DSS.
  • Manage customer-facing security questionnaires, audits, and health-system procurement portals.
  • Automate evidence collection from infrastructure and cloud configuration systems using tools like Vanta.
  • Oversee vendor risk management, including BAA negotiations and security exhibits.
  • Maintain the incident response program, policy sets, and security awareness training.
  • Act as HIPAA Privacy Officer and lead AI governance frameworks.
  • Facilitate penetration testing lifecycles, BCP/DR testing, and quarterly user access reviews.
View Full Description & ApplyYou'll be redirected to the employer's site
$190,000 - $220,000 per year
Apply Now