About the RoleThis is a hybrid role: roughly half security compliance and audit, half hands-on technical security. You'll own our compliance audit cycle end-to-end (SOC 1, SOC 2, HITRUST CSF, HITRUST AI), and you'll also work directly on the technical side: vulnerability management, security findings remediation, cloud security reviews, and third-party risk.
ResponsibilitiesCompliance & Audit
- Own SOC 1, SOC 2, HITRUST CSF, and HITRUST AI audits end-to-end: scoping, evidence collection, auditor coordination, and findings remediation
- Develop, update, revise, and implement compliance policies, procedures, and practices for security frameworks (HIPAA, HITRUST, SOC) as well as general compliance and operations
- Manage our compliance automation and trust platforms (Drata, SafeBase), including control monitoring and responses to customer security questionnaires.
- Coordinate with external vendors and clients to gather information needed for compliance reviews, validations, and audits
- Run third-party/vendor risk assessments and respond to customer security assessments and external inquiries
- Deliver HIPAA and security awareness training and measure control effectiveness through internal audits
Technical Security- Run the vulnerability management program: scanning, triage, prioritization, and driving remediation with engineering teams
- Investigate and remediate security findings across our AWS environment (EKS, WAF, Shield, CloudFront, IAM) and SaaS stack
- Review external attack surface findings (e.g., SecurityScorecard) and implement fixes from CSP headers to subresource integrity to TLS configuration
- Support security incident response: log analysis, forensic evidence collection, and containment
- Support fraud and forensic investigations authentication log analysis, targeted data extraction, and evidence preservation in support of legal and compliance matters
- Improve our security tooling and automate evidence collection, using scripting (Python, Bash) where manual work can be eliminated
What We're Looking For- 4+ years combined experience across security compliance/GRC and hands-on technical security
- Direct experience supporting SOC 1/SOC 2 and/or HITRUST audits - you've been through at least one full audit cycle
- Working knowledge of HIPAA Security and Privacy requirements
- Hands-on experience with vulnerability scanning and remediation, and comfort reading technical findings (CVEs, misconfigurations, cloud security issues)
- Familiarity with AWS security concepts (IAM, security groups, logging, WAF)
- Ability to write clear policies and procedures and equally clear remediation tickets
Nice to Have- Experience with compliance automation platforms (Drata, Vanta, or similar)
- Experience in healthcare or another regulated industry
- Certifications such as CISSP, CISA, CRISC, HITRUST CCSFP, or CISM
- Experience with SIEM tools and log analysis
- Experience with forensic log analysis, fraud investigations, or supporting legal/eDiscovery requests
Benefits- Medical, Dental, and Vision Coverage: Comprehensive plans with options for low-to-no-cost premiums.
- Employer HSA Contribution: Company-funded contributions to your Health Savings Account.
- 401(k) Retirement Plan
- Equity Incentive Plan
- Annual Company-Wide Bonus: Opportunity for up to 15% bonus based on company performance.
- Remote-First Culture: We are remote-first with a dedicated NYC office and reimbursement options for co-working spaces.
- Flexible Vacation Policy
- Summer Fridays: 5 additional Fridays off during the summer (separate from PTO).
- Home Office and Wellness Stipend
- Monthly Internet Stipend
- Annual Learning and Development Stipend
Base Salary Band (based on experience and level)$80,000 - $130,000