Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Collectly

Security & Compliance Manager, GRC

Collectly

. Own security and compliance end to end as the sole person in the function .

Posted 9/17/2026full-timeRemote • United StatesMid-LevelSenior💰 $190,000 - $220,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates extensive experience in security compliance and governance, particularly within healthcare SaaS environments, with a strong focus on managing SOC 2 and HITRUST compliance. Proficient in handling HIPAA regulations, security frameworks, and compliance automation tools while effectively communicating with stakeholders.

Highest-signal resume keywords
SOC 2 Compliance ManagementHITRUST OwnershipHIPAA Security Rule ExpertiseVanta Compliance AutomationNIST AI RMF Knowledge

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Security ComplianceGRC ManagementRisk AnalysisIncident ResponseVendor Security ReviewsPenetration TestingSecurity Framework ApplicationThreat ModelingCustomer Security QuestionnairesBCP/DR Coordination
Soft Skills
Effective CommunicationProblem SolvingResearch SkillsCollaboration
Tools & Technologies
VantaArcherProcessUnityVenminderSecurity ScannersCloud Configuration Systems
Certifications & Qualifications
CIPP/USHCISPPCISSPHITRUST CCSFP
Industry Keywords
Healthcare SaaSPHI HandlingPCI DSSAI GovernanceState Privacy Laws

Tech Stack

Tools & technologies
Cloud

About the role

Key responsibilities & impact
  • Own security and compliance end to end as the sole person in the function
  • Build a scalable security and compliance program without adding unnecessary operational drag
  • Answer customer security questionnaires
  • Complete AI governance questionnaires and responsible-AI reviews for the AI patient billing agent
  • Lead live security calls with prospects’ InfoSec teams
  • Manage health-system procurement portals, including Archer, ProcessUnity, and Venminder
  • Manage annual customer reattestation cycles
  • Handle customer security escalations, incident communications, and customer-facing RCAs
  • Host customers exercising right-to-audit clauses
  • Distribute SOC 2, HITRUST certification, penetration-test summaries, and subprocessor notices under NDA
  • Create and maintain a public trust center, standard security package, and answer library
  • Own HITRUST i1 and SOC 2 Type 2 readiness, evidence, auditor management, and remediation tracking
  • Own PCI DSS SAQs, collect processor AOCs, and define scope for card-present and card-not-present flows
  • Conduct the annual HIPAA Security Risk Analysis and maintain the risk register
  • Manage the penetration-test lifecycle, including scheduling, scoping, remediation tracking, and customer-facing summaries
  • Conduct quarterly user access reviews
  • Coordinate BCP/DR tabletops and annual testing
  • Administer Vanta and security scanners
  • Pull evidence from CI, infrastructure-as-code, identity provider, EDR, and cloud configuration systems
  • Reduce manually evidenced controls annually
  • Manage BAAs, security exhibits, DPAs, and the subprocessor inventory
  • Conduct tiered vendor security reviews and annual vendor reattestation
  • Maintain policies; manage security awareness, HIPAA training, phishing simulations, and completion tracking
  • Own the incident response program, including runbooks, tabletops, and incident coordination
  • Manage breach-notification timelines and contractual notification windows
  • Maintain a documented exception process with approver, expiry date, and compensating control
  • Serve as HIPAA Privacy Officer
  • Track state privacy laws including CCPA/CPRA and Washington My Health My Data
  • Establish AI governance for the AI patient billing agent, including model inventory, human oversight, and monitoring
  • Track emerging state rules on AI in healthcare and AI-generated patient communications
  • Do not own remediation engineering; DevOps owns findings and fixes
  • Do not own shipping decisions; document risk and escalate while the CTO sets priorities
  • Do not serve as a gate in design or code review

Requirements

What you’ll need
  • Extensive experience in security compliance or GRC, including time in healthcare SaaS or another PHI-handling environment
  • Has run SOC 2 and HITRUST as an owner, not a contributor
  • Deep HIPAA fluency: Security Rule, Privacy Rule, Breach Notification Rule, BAAs, minimum necessary
  • Hands-on with Vanta or a comparable compliance automation platform
  • Strong knowledge of security frameworks; ability to apply unfamiliar frameworks independently
  • Ability to work with NIST AI RMF and ISO 42001
  • Ability to write final-draft customer-facing prose
  • Ability to follow technical conversations involving architecture diagrams, infrastructure-as-code, access control models, and cloud configuration
  • Ability to reason about threat models and assess exploitability, mitigations, applicability, and escalation needs
  • Software engineering or security engineering background is a strong plus, though not required
  • PCI DSS in a payments context is a plus
  • Recognized certifications include CIPP/US, HCISPP, CISSP, and HITRUST CCSFP
  • Ability to actively research information during the working-session exercise

Benefits

Comp & perks
  • Unlimited PTO
  • Fully paid medical, dental, and vision insurance for you and your dependents
  • Stock options
  • 401(k) with a generous company match
  • Contributions toward student loans