Senior Manager, Security & Compliance
Core
Lead the end-to-end execution of HITRUST and SOC 2 Type II certifications while maintaining HIPAA-aligned security and privacy controls for a specialty pharmacy platform.
Role type
Senior Manager, Security & Compliance (Hands-on IC) (via careerplan.io/jobs/7d8efcd9-5a0d-4cb8-8214-b1e4b130944b-senior-manager-security-compliance-at-leap)
Builds
Security and compliance program, audit evidence, control frameworks
Domain
Healthcare technology, specialty pharmacy, B2B benefits
Required skills
HITRUST certification execution, SOC 2 Type II audit management, HIPAA security and privacy rules, GRC frameworks, security questionnaire completion, cloud infrastructure review (GCP), third-party risk assessment
Preferred skills
Health tech or digital health experience, compliance automation tools (Vanta, Drata, Secureframe), ISO 27001, CISSP/CISA/CISM/CRISC certifications
Technologies
GCP, data stacks, compliance automation platforms
Responsibilities
Run HITRUST certification from kickoff through completion, own SOC 2 Type II end-to-end including evidence collection and auditor management, maintain HIPAA security and privacy controls and BAAs, review security posture and deliver prioritized roadmap, roll out new controls and policies across Engineering and Operations, complete security questionnaires and RFP security sections, manage external security partner, represent company with client and partner security teams
Seniority
Senior Manager, hands-on IC
