Security and Compliance Analyst II

Lasso Informatics

$80K — $95K *
Healthcare
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3+ years in security, compliance, audit, IT or systems administration with demonstrable evidence production.
  • Relevant certification: CompTIA Security+, SSCP, GSEC, CySA+ or CISA, or confirmed test date for ongoing studies.
  • Skilled in analyzing log data to identify real issues versus noise.
  • Strong writing skills that convey clarity and detail, tested via a take-home exercise.

Responsibilities

  • Conduct weekly security reviews by analyzing cloud and identity system logs and vulnerability scan results.
  • Maintain Vanta’s health by managing compliance tests and documentation for audits.
  • Track remediation efforts and proactively manage deadlines to ensure timely responses.
  • Conduct quarterly access reviews and assess third-party risks through security questionnaires.
  • Assist with incident response by gathering information, constructing timelines, and drafting notifications.
  • Lead efforts towards certification, conducting gap assessments during audit windows.
  • Manage AI governance tasks, including maintaining inventories and producing related reports.

Benefits

  • Flexible remote-friendly position with Eastern time overlap.
  • 100% employer-paid group benefits plan.
  • Retirement savings plan with a 2% employer match.
  • Professional development budget for continuous learning.
  • Structured procedures for recurring tasks with direct managerial support.
  • Opportunity to contribute to meaningful work protecting sensitive health data.
  • Fast-paced startup environment with broad responsibilities and visible impact.
Full Job Description
As a Security and Compliance Analyst at Lasso, you own the weekly security and compliance work behind a health research data platform running on AWS and Google Cloud. You review cloud and identity logs, triage vulnerabilities, keep our audit evidence current in Vanta, and help take the company through SOC 2 Type 2. You also run Lasso's AI governance execution work. This position sits under the Manager of Security, Compliance and DevOps, with oversight from the CTO, COO and CEO as appropriate. We are a HIPAA Business Associate running to a NIST 800-53 Moderate control baseline, and a federal sponsor checks our work continuously. The security team is one person today. You would be the second, and getting us certified is a real piece of the job, not a side project. As the role matures, this person may be designated Information System Security Officer (ISSO) for our NIST 800-53 authorization boundary, working under the Security Officer What You'll Do • Run the weekly security review: audit logs across our cloud and identity systems, then vulnerability scan results, written up and published, with tickets opened for anything that needs action. • Keep Vanta healthy: failing tests, evidence collection, document gaps, policy acceptances and vendor security assessments. • Maintain our remediation tracker. Chase owners and flag items before they go late. • Run quarterly access reviews and third-party risk work, including customer security questionnaires. • Support incidents: gather facts, build the timeline, keep the tracker and draft the notification. Escalation calls stay with the Security Officer. • Help get us certified. Gap assessment through observation window through audit, roughly a third of the role. • Run AI governance execution: build and quarterly-refresh the AI systems and agent inventory, and produce the shadow-AI discovery report from our identity, endpoint and monitoring data. Roughly 3 hours a week in year one, less after that. This work sits under Ian, with oversight from the CTO, COO and CEO as appropriate. Qualifications Required • Three or more years in security, compliance, audit, information technology or systems administration, where you produced evidence that someone else then inspected. • A current CompTIA Security+, SSCP, GSEC, CySA+ or CISA. Mid-study with a confirmed test date works too, tell us. • You can read logs and tell a real problem from noise. Not detection engineering: looking at a week of sign-in activity and deciding what deserves a ticket. • Writing that holds up: clear, plain, dated and specific. We test this with a short take-home exercise. We will teach you Vanta, the frameworks (HIPAA, NIST 800-53, SOC 2, ISO 27001), read-only evidence work in AWS and Google Cloud, Microsoft Entra ID and Intune, Jira and Confluence, and Splunk as we stand it up this year. Almost nobody arrives knowing all of it. Preferred • Time on the inside of a SOC 2 Type 2 or ISO/IEC 27001 certification, on the company's side of the audit rather than the auditor's. • HIPAA as a Business Associate, or NIST 800-53 or FedRAMP evidence work. • Vulnerability management and patch deadline tracking. • Experience with endpoint or awareness tooling such as CrowdStrike Falcon or KnowBe4. • Exposure to AI governance or AI risk work: tool or vendor risk assessment, model inventories, or supporting an AI use policy. You do not need a degree, a security clearance, coding experience, an on-call rotation, production access, or a prior job title with the word "compliance" in it. Hands-on experience substitutes for a degree in full. Some of our strongest candidates will be systems administrators moving into security, security operations analysts who have never done compliance, or the person at a hospital, credit union or lab who ended up answering the auditor without ever being given the title. Want to Be a Wrangler? Here's What We Look For • You hold yourself to a high standard and bring real rigor to your work. • You make the people around you better. • You stay curious and keep learning. • You see a problem and start solving it, without waiting to be asked. • You keep the whole picture in view and notice how a change in one place ripples through the evidence, the tracker and the audit. • You write clearly and document your findings with precision. • You take data privacy and responsible stewardship seriously, every time. What We Offer • A flexible, remote-friendly position with hours overlapping North American Eastern time. • Group benefits plan (Lasso pays 100%). • Group retirement savings plan with a 2% employer match. • A professional development budget. • Written procedures for every recurring duty, and a manager who does this work today and will run the first cycles alongside you. • Work that matters: protecting the data behind a health research platform that scientists depend on. • The range and pace of a start-up: broad scope, fast decisions and impact you can see.

Similar Jobs

More Jobs at Lasso Informatics

  • Full Stack Developer
    $90K — $120K *
    Montreal, QC H1A 0A1
    Information Technology
    In-Person

More Healthcare Jobs

Find similar Security and Compliance Analyst II jobs: