Jobgether logo

Security & Compliance Manager

Jobgether
Remote
Remote$132k–$140k· about 9 hours ago

Straight from Jobgether’s careers page. Apply on the company site — no recruiter, no middleman.

Security & Compliance Manager

Team: IT

Location: US

Commitment: Full-time

Workplace Type: remote

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security & Compliance Manager based in United States.

This role owns the day-to-day operational backbone of a growing security and compliance program within a remote, AI-enabled healthcare environment.
You will coordinate risk assessments, penetration testing, remediation, vendor security reviews, and compliance activities across the organization.
The position combines hands-on security operations with governance, documentation, project management, and cross-functional collaboration.
You will work closely with senior security leadership while independently driving execution and ensuring critical actions reach completion.
A major focus will be strengthening HIPAA compliance and building toward a formal SOC 2 or HITRUST-ready posture.
You will also help establish practical security controls for devices, identity and access, third-party vendors, incidents, and AI tools handling sensitive information.
This is an opportunity to build scalable security processes from the ground up in a fast-moving healthcare startup.

Accountabilities

    • Own the daily operation of the security program, including Security Risk Assessment cadence, penetration-test coordination, remediation tracking, phishing simulations, and annual security-awareness training.

    • Draft and maintain security policies and procedures for leadership review, ensuring documentation evolves alongside organizational and regulatory requirements.

    • Lead vendor security assessments and Business Associate Agreement reviews across the third-party ecosystem.

    • Monitor MDM and BYOD compliance, partnering with IT and managed service providers on device enrollment and endpoint-security status.

    • Act as the day-to-day lead for incident and breach response, escalating matters to senior security leadership according to established response procedures.

    • Support identity and access management improvements, including SSO implementation and deployment of a company-wide password manager.

    • Prepare recurring security and compliance reporting for leadership and board-level discussions, including risk status and forward-looking roadmaps.

    • Evaluate and implement compliance-automation platforms such as Drata, Vanta, or comparable solutions to support SOC 2 or HITRUST readiness.

    • Track remediation actions from risk assessments, audits, and vendor reviews through completion using established security-program tracking processes.

    • Establish and maintain AI security guardrails, including policies governing the handling of protected health information when using AI-enabled tools.

    • Maintain comprehensive records covering security controls, risks, incidents, vendor assessments, remediation activities, and strategic initiatives.

    • Build repeatable security and compliance processes that can scale with the organization while maintaining strong operational discipline.

    • Requirements

      • 3–6+ years of experience in security compliance, IT security, GRC, or a related field.

      • Direct experience with HIPAA Security Rule requirements, Security Risk Assessments, and vendor or BAA risk reviews, preferably within healthcare or another regulated environment.

      • Demonstrated ability to manage security calendars, coordinate multiple stakeholders, and drive remediation items through to closure.

      • Experience working with a fractional or contractor CISO, managed service provider, or external security advisor.

      • Ability to translate technical security risks and requirements into clear, concise communications for leadership and board-level audiences.

      • Strong documentation, organization, project management, and follow-through skills.

      • Ability to work independently and take ownership in a fast-paced, remote startup environment.

      • Experience preparing for or achieving SOC 2 or HITRUST certification is a plus.

      • Familiarity with compliance automation platforms such as Drata, Vanta, or similar tools is desirable.

      • Experience with MDM and endpoint-security solutions, Google Workspace security controls such as DLP and Vault, and password-manager deployments is beneficial.

      • Experience building security and compliance processes from scratch in an early-stage or high-growth organization is a plus.

      • Familiarity with AI governance and security considerations, particularly for tools that may process protected health information, is desirable.

      • Benefits

        • Annual compensation range of $132,000–$140,000.

        • Fully remote work opportunity.

        • Opportunity to take ownership of a growing security and compliance program.

        • Exposure to HIPAA-regulated healthcare operations and AI-enabled technology.

        • Opportunity to build scalable security processes and controls in a high-growth environment.

        • Collaboration with senior security and product leadership.

        • Potential to contribute to SOC 2 or HITRUST readiness and broader security-program maturity.

        • Opportunity to shape practical governance and security standards for emerging AI use cases.

How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the roles core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
 
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
 
 
## LI-CL1

Similar remote jobs

More like this →
Oxfam America logo

Oxfam America

Manager, Cybersecurity and Infrastructure

Remote
Boston, MA
✓ From careers page· about 3 hours ago
CVS Health logo

CVS Health

Staff Software Development Engineer (Remote)

Remote
$107k–$284k
✓ From careers page· about 6 hours ago
MUSC Health logo

MUSC Health

Digital Analytics Specialist

Remote
South Carolina
✓ From careers page· about 6 hours ago
RTX logo

RTX

Data Loss Prevention Administrator

Remote
Santa Isabel, PR
✓ From careers page· about 8 hours ago

Discover More than 100,000 Hidden Remote Jobs Before Everyone Else

Unlock All Remote Jobs Today

Simple pricing. Big savings on Quarterly and Yearly.

Monthly Access

$19/month
  • Instant access to fresh remote jobs from 500+ companies
  • New opportunities added hourly, often 3-7 days before anywhere else
  • Advanced filtering by role type, stack, pay, and location
  • Priority customer support
Start 7-day trial — $2.95
Most Popular

Yearly Access

$59/year
  • Everything in Monthly
  • Save $169 (~74%) vs paying monthly
  • Average job search takes ~6 months - get covered for the whole journey
  • Less than the cost of one lunch per month for competitive advantage
  • Equivalent to just ~$4.92/month
Start 7-day trial — $2.95