Remote job
Senior Manager, Security & Compliance
Job details
About this role
Role overview A fast-growing benefits and specialty healthcare organization is hiring a senior security and compliance leader to take its established program to the next stage. The role is an individual-contributor position that blends hands-on execution with strategic ownership, with HITRUST certification as the headline near-term initiative. The work spans compliance, engineering, operations, and external partner management in a healthcare context that handles protected health information.
Responsibilities - Lead HITRUST certification from gap assessment and control mapping through remediation, assessor management, and final completion. - Own SOC 2 Type II end to end, including evidence collection, auditor relationship, and closing identified gaps. - Maintain HIPAA-aligned security and privacy controls, core policies, and business associate agreement obligations. - Conduct a full review of the current security posture and deliver a prioritized roadmap of improvements and tooling recommendations. - Roll out new controls, policies, and processes organization-wide, partnering with engineering on implementation across a Google Cloud and modern data stack. - Evaluate new vendors and tools, including AI offerings, and run ongoing third-party risk reviews. - Complete security questionnaires, RFP security sections, and controls reviews, and represent the company with client and partner security teams. - Select and manage an external security partner, and keep leadership informed on posture, risk, and investment needs.
Requirements - At least seven years in healthcare information security, GRC, or IT audit, with direct ownership of at least one full SOC 2 Type II audit cycle. - Deep familiarity with SOC 2, HIPAA, and HITRUST, and an audit- and GRC-first approach to program building. - Experience building a security or compliance program from scratch, or owning one end to end as an early security hire at a startup or growth-stage company. - Hands-on experience completing security questionnaires and representing the company with enterprise or health plan security teams. - Working knowledge of the HIPAA Security and Privacy Rules and handling PHI in B2B healthcare settings. - Enough technical depth in cloud infrastructure (Google Cloud preferred) and modern data stacks to review controls and guide engineers through implementation.
Nice to have - Hands-on experience taking a company through HITRUST certification. - Background in health tech, digital health, or benefits, especially with health plans and large self-funded employers. - ISO 27001 experience. - Familiarity with compliance automation tools such as Vanta, Drata, or Secureframe. - CISSP, CISA, CISM, or CRISC certification.
Benefits and work setup - Equal opportunity employer committed to building a team that reflects a diversity of perspectives, experiences, and identities.