Security & Compliance Manager (GRC)
C
CollectlyHealthcare SaaS
US-basedFull-TimeManager
Salary$190,000 - $220,000 per year
Apply NowOpens the employer's application page
Job Details
- Required Skills
- HIPAA
Requirements
- Extensive experience in security compliance or GRC, with specific background in healthcare SaaS or PHI-handling environments.
- Proven history as an owner of SOC 2 and HITRUST programs.
- Deep HIPAA fluency including Security Rule, Privacy Rule, and Breach Notification Rule.
- Hands-on experience with Vanta or comparable compliance automation platforms.
- Ability to interpret technical conversations with DevOps regarding architecture, infrastructure-as-code, and access control models.
- Strong understanding of threat modeling and ability to assess control implementation and exploitability.
- Exceptional written communication skills for creating customer-facing security documentation.
- Ability to work effectively in a technical, engineering-adjacent role.
- Experience with PCI DSS in a payments context is a plus.
- Relevant certifications such as CIPP/US, HCISPP, CISSP, or HITRUST CCSFP are highly regarded.
Responsibilities
- Own end-to-end security and compliance programs, including HITRUST i1, SOC 2 Type 2, and PCI DSS.
- Manage customer-facing security questionnaires, audits, and health-system procurement portals.
- Automate evidence collection from infrastructure and cloud configuration systems using tools like Vanta.
- Oversee vendor risk management, including BAA negotiations and security exhibits.
- Maintain the incident response program, policy sets, and security awareness training.
- Act as HIPAA Privacy Officer and lead AI governance frameworks.
- Facilitate penetration testing lifecycles, BCP/DR testing, and quarterly user access reviews.
View Full Description & ApplyYou'll be redirected to the employer's site