Senior Security & Compliance Analyst
Core
Ensure security capabilities and controls within the technology stack to mitigate risks and meet compliance requirements for a mental health platform.
Role type
Senior Security & Compliance Analyst
Builds
Security controls, compliance documentation, and risk assessments for Headspace Health stack
Domain
Healthtech / Cybersecurity
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Security compliance frameworks (ISO 27001, PCI-DSS, HIPAA, GDPR, FedRAMP, HITRUST, SOC 2), Cloud security (DevSecOps, IaC, CI/CD, SAST, DAST), Security engineering (incident response, threat detection, vulnerability management), Third-party risk management, Security awareness training
Preferred skills
None stated
Technologies
None explicitly listed as tools, only concepts
Responsibilities
Interact with security architects, privacy officer, and legal teams to ensure security controls; Respond to security assessment questionnaires for prospects; Research and recommend new security technologies; Conduct security architecture and application reviews; Support product testing during audits; Provide post-audit analysis
Seniority
Senior, hands-on IC