Skip to content

Open nowPosted 8 hours agoWe saw it 84 min after it went up

Manager of Security and Compliance

Jobgether4,270 open roles

Where
US
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowManager of Security and ComplianceJobgether · US
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Jobgether's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.0% of postings close within 7 days. Measured by our own scanner across the market. Jobgether postings stay open a median of 5 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.5%3 days
  3. 8.0%7 days
  4. 15.0%14 days
  5. 34.1%30 days
This job: posted 8 hours ago

Jobgether median: 5 days open

The posting

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Manager of Security and Compliance based in United States.

This is a high-impact security and compliance leadership role within a growing healthcare SaaS environment. You will own the day-to-day execution and continued maturity of security, privacy, risk, and healthcare compliance programs. The role combines strategic program leadership with hands-on security, audit, incident response, and risk-management work. You will work closely with Engineering, Product, SRE, IT, Legal, and customer-facing teams to embed security into technology and business processes. A major priority will be leading HITRUST certification while strengthening HIPAA, SOC 2, privacy, and broader security controls. You will also help modernize compliance through automation, continuous evidence collection, measurable risk management, and scalable processes. This role is ideal for a security leader who can turn complex regulatory requirements into practical controls and trusted business partnerships.

Accountabilities

  • Own and continuously mature security, privacy, and compliance programs covering HIPAA, SOC 2, HITRUST, and applicable healthcare privacy requirements.
  • Lead HITRUST certification end to end, including scoping, readiness assessments, evidence collection, assessor coordination, remediation, and corrective action plans.
  • Manage internal and external audits, risk assessments, penetration tests, security reviews, evidence collection, and remediation activities.
  • Build a path toward continuous, system-generated compliance rather than relying primarily on point-in-time evidence collection.
  • Manage external security and compliance partners, including advisors, assessors, and penetration-testing providers, ensuring clear scopes, priorities, accountability, and remediation ownership.
  • Maintain the security and compliance roadmap, ensuring vulnerabilities, risks, audit findings, and control gaps have defined owners and resolution plans.
  • Partner with Engineering, Product, Platform, SRE, and IT to integrate security into architecture, infrastructure, product development, and the software development lifecycle.
  • Establish security and PHI-handling standards and guardrails, including considerations for AI-assisted development.
  • Oversee critical controls including identity and access management, logging and monitoring, encryption, vulnerability management, data retention, data protection, and vendor risk.
  • Lead security incident response, including investigation, stakeholder communication, post-incident reviews, and corrective actions within a unified incident-management framework.
  • Maintain security policies, procedures, Business Associate Agreements, data-handling requirements, and breach-response plans.
  • Serve as the operational lead for HIPAA Security Rule obligations while supporting the designated HIPAA Security Official and collaborating with the Privacy Officer.
  • Support customer security reviews, due diligence, onboarding, and security and privacy requirements during contract negotiations.
  • Establish security and compliance metrics that provide leadership with clear visibility into risks, incidents, vulnerabilities, remediation progress, and audit readiness.
  • Lead security awareness and compliance training while managing, developing, and mentoring the security and compliance team.
  • 7+ years of experience in information security, healthcare compliance, privacy, risk management, or a closely related discipline, preferably within healthcare SaaS or health technology.
  • Strong working knowledge of HIPAA, SOC 2, HITRUST, healthcare privacy requirements, and security control frameworks.
  • Demonstrated experience leading audits, risk assessments, compliance programs, remediation initiatives, and external security or compliance partners.
  • Proven experience serving as the accountable owner for at least one HITRUST certification, either i1 or r2, from scoping through evidence collection, assessor management, and corrective action planning.
  • Practical knowledge of cloud and SaaS security, identity and access management, vulnerability management, encryption, logging, data protection, and incident response.
  • Experience partnering with Engineering and Product teams to integrate security into technology architecture and development processes.
  • Experience with vendor risk management and third-party security assessments.
  • Strong communication skills, with the ability to translate technical, regulatory, and security requirements for both technical and non-technical stakeholders.
  • Experience working with healthcare technology, electronic medical records, clinical systems, or sensitive healthcare data environments.
  • Experience in PACE, value-based care, Medicare/Medicaid, or other regulated healthcare environments is a plus.
  • Experience building or scaling security and compliance programs within a growing SaaS organization is preferred.
  • Familiarity with cloud-native environments, particularly Azure and Kubernetes/AKS, as well as DevSecOps and security automation, is advantageous.
  • Experience leading a small security/compliance team or cross-functional security initiatives is a plus.
  • Relevant certifications such as CCSFP, CISSP, CISM, or HCISPP are preferred.
  • Strong organizational skills, sound judgment, ownership, and the ability to operate effectively in a growing and evolving environment are essential.
  • This is a fully remote role for candidates based in the United States and is not eligible for sponsorship.
  • Base salary range of $130,000–$150,000, with final compensation determined by experience, skills, and organizational needs.
  • Fully remote position within the United States.
  • Opportunity to lead and mature security, privacy, and compliance programs within a growing healthcare technology organization.
  • High-impact role with significant cross-functional exposure across Engineering, Product, SRE, IT, Legal, and customer-facing teams.
  • Opportunity to lead HITRUST certification and build scalable, proactive security and compliance capabilities.
  • Meaningful leadership responsibility, including team development and mentorship.
  • Opportunity to influence security architecture, compliance automation, incident management, and organizational risk strategy.

How Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Why Apply Through Jobgether?

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Jobgether's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Jobgether's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Jobgether's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.