Security & Compliance Manager
Core
Own the operational backbone of a HIPAA-regulated security and compliance program for an AI-enabled mental health platform, managing risk assessments, vendor audits, and incident response.
Role type
Security & Compliance Manager (GRC)
Builds
Operational security program, compliance documentation, and risk reporting for a healthcare AI platform.
Domain
Healthcare / AI / Cybersecurity
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
HIPAA Security Rule expertise, Security Risk Assessment (SRA) execution, vendor/BAA risk management, incident response coordination, policy drafting, project management, stakeholder communication
Preferred skills
SOC2 or HITRUST certification preparation, compliance automation tooling (Drata/Vanta), MDM/endpoint security management, AI governance for PHI
Technologies
Drata, Vanta, Google Workspace, SSO, password managers
Responsibilities
Manage security calendar and track remediation of risk assessments and penetration tests; Lead vendor security assessments and BAA audits; Serve as day-to-day lead on incident/breach response; Draft and maintain security policies and procedures; Support rollout of identity and access management improvements; Evaluate and roll out compliance-automation tooling; Define and maintain AI security guardrails for PHI handling.
Seniority
Mid-level, hands-on IC