Remote job
Security & Compliance Manager
Job details
About this role
Role overview A women's health-focused virtual mental health care provider is scaling a HIPAA-regulated, AI-enabled platform and needs a Security & Compliance Manager to run the operational backbone of its security program. The role sits between a product leader acting as Security Officer and a contractor CISO, owning day-to-day execution while those leaders retain governance, sign-off, and board reporting. It is a hands-on builder position suited to someone who can turn policy into tracked remediation in a fast-paced remote startup.
Responsibilities - Run the recurring security calendar: Security Risk Assessment cadence, penetration test coordination and remediation, phishing simulations, and annual security awareness training. - Draft and maintain Policies & Procedures for executive review, keeping documentation current as the regulatory landscape evolves. - Lead vendor security assessments and Business Associate Agreement audits across the vendor ecosystem. - Operate the incident and breach response process, escalating to executive owners per the response plan. - Drive MDM and BYOD device compliance in partnership with internal IT and a managed service provider. - Track remediation items from risk assessments, audits, and vendor reviews to closure using a program-level tracker. - Prepare recurring board-level risk and compliance reporting, including a forward-looking roadmap, alongside executive owners. - Evaluate and roll out compliance automation tooling to support a SOC 2 or HITRUST-ready posture. - Support identity and access management improvements such as SSO and an enterprise password manager rollout. - Help define AI security guardrails, including PHI handling policies for AI tooling used in clinical workflows.
Requirements - Three to six-plus years in security compliance, IT security, or GRC roles. - Hands-on experience with HIPAA Security Rule requirements, Security Risk Assessments, and vendor or BAA risk reviews, ideally in healthcare or another regulated industry. - Demonstrated ability to run a security calendar and close remediation items across multiple stakeholders. - Experience partnering with a fractional or contractor CISO, MSP, or external advisor, and translating technical risk into clear non-technical reporting for leadership or a board. - Strong documentation and project management discipline. - Comfort working independently in a fast-paced, fully remote startup environment.
Nice to have - Direct experience preparing for or achieving SOC 2 or HITRUST certification. - Familiarity with compliance automation platforms such as Drata, Vanta, or comparable tools. - Experience with MDM or endpoint tools, Google Workspace security controls (DLP, Vault), and password manager rollouts. - Background in early-stage or high-growth startups building process from scratch. - Familiarity with AI governance and security considerations for tools handling PHI.
Benefits and work setup - Remote-first work environment. - Compensation range: $132,000–$140,000.