FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Security and Compliance Manager
FamilyWell Health. Own day-to-day management of the security program, including Security Risk Assessment cadence, penetration test coordination and remediation tracking, phishing simulations, and the annual security awareness training calendar .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in security compliance and risk management, with a strong focus on HIPAA Security Rule requirements and vendor risk assessments. Proficient in documentation, project management, and compliance automation tools to enhance security program effectiveness.
Highest-signal resume keywords
Security Compliance ManagementHIPAA Security Rule ExpertiseSecurity Risk AssessmentVendor Security AssessmentCompliance Automation Tools
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Security Risk AssessmentIncident ResponseDocumentation ManagementProject ManagementCompliance Monitoring
Soft Skills
Independent WorkStakeholder CommunicationDetail Orientation
Tools & Technologies
DrataVantaMDM ToolsGoogle Workspace Security ControlsPassword Manager
Certifications & Qualifications
SOC2 CertificationHITRUST Certification
Industry Keywords
Governance, Risk, and Compliance (GRC)Healthcare CompliancePhishing SimulationsBusiness Associate Agreement (BAA)AI Security Governance
Tech Stack
Tools & technologiesVault
About the role
Key responsibilities & impact- Own day-to-day management of the security program, including Security Risk Assessment cadence, penetration test coordination and remediation tracking, phishing simulations, and the annual security awareness training calendar
- Draft Policies & Procedures for CISO and leadership review/approval and keep documentation current
- Lead vendor security assessments and Business Associate Agreement audits across the vendor ecosystem
- Own MDM/BYOD device compliance monitoring with the IT Systems Administrator and MSP
- Serve as day-to-day lead on incident/breach response, escalating to the CPO and contractor CISO
- Support identity and access management improvements, including SSO and a company-wide password manager
- Prepare recurring board-level risk and compliance status reporting and a forward-looking roadmap
- Own compliance-automation tooling evaluation and rollout, such as Drata or Vanta
- Track open items from SRAs, audits, and vendor reviews to closure using the Security Program Tracker
- Help define and maintain AI security guardrails, including PHI handling policies for AI tools
- Maintain detailed documentation and records of security controls, risks, incidents, vendor audits, and roadmap initiatives
Requirements
What you’ll need- 3–6+ years of experience in security compliance, IT security, or GRC (governance, risk, and compliance) roles
- Direct experience with HIPAA Security Rule requirements, Security Risk Assessments, and vendor/BAA risk reviews — ideally in healthcare or another regulated industry
- Comfortable running a security calendar and tracking remediation items to closure across multiple stakeholders
- Experience partnering with a fractional or contractor CISO, MSP, or outside security advisor, and translating technical risk into clear, non-technical reporting for leadership or a board
- Strong documentation and project management habits
- Ability to work independently in a fast-paced, remote startup environment
- Nice-to-have: Direct experience preparing for or achieving SOC2 or HITRUST certification
- Nice-to-have: Familiarity with compliance automation platforms (Drata, Vanta, or similar)
- Nice-to-have: Experience with MDM/endpoint tools, Google Workspace security controls (DLP, Vault), and password manager rollouts
- Nice-to-have: Experience in an early-stage or high-growth startup, comfortable building process from scratch
- Nice-to-have: Familiarity with AI governance/security considerations for tools used with PHI