Skip to content

Open nowPosted 4 hours agoWe saw it 45 min after it went up

Senior Manager, Security & Compliance

Leap17 open roles

Pay
$150,000 – $190,000 a year
Where
US (Remote)
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Manager, Security & ComplianceLeap · US (Remote)
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Leap's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.0% of postings close within 7 days. Measured by our own scanner across the market. Leap postings stay open a median of 8 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 8.0%7 days
  4. 15.0%14 days
  5. 34.2%30 days
This job: posted 4 hours ago

Leap median: 8 days open

The posting

ABOUT LEAP

Leap is one of the fastest-growing benefits solutions and a category-defining pioneer in employer specialty pharmacy. We are reshaping how life-changing therapies are delivered and financed, ensuring patients get the treatment they need while employers finally get a fair deal.

Specialty drugs and infusions represent nearly 10% of all healthcare spend and are the fastest-growing cost category for employers. Leap tackles this challenge with a novel approach: eliminating hidden markups, expanding access to high-quality infusion providers, and bringing clarity and fairness to how therapies are priced and paid for.

We’re proud to partner with numerous Fortune 500 companies and leading TPAs. Each patient we serve creates immediate ROI: lower costs, improved access, and better care. Join us as we redefine what’s possible in specialty care.

ABOUT THE ROLE

Leap is hiring a Senior Manager, Security & Compliance to lead the next phase of our security program. We have an established foundation, including SOC 2 Type II and HIPAA-aligned controls. Now we’re looking for a leader to shape where the program goes next and own the work of getting there, starting with HITRUST certification.

This is a hands-on builder role. You’ll set the direction for our security and compliance program and do much of the work yourself: running audits and certifications, writing policies, reviewing controls, and completing security questionnaires. You’ll also be trusted with the judgment calls that matter most, including the security obligations Leap commits to, the vendors and tools we adopt, and how new controls roll out across the company.

You’ll represent Leap with client and partner security teams when it counts, but the core of the job is building and maintaining a program strong enough to make those conversations easy. You’ll work closely with Engineering, Operations, and our go-to-market teams, and you’ll manage our external security partner.

This is an individual contributor role for an ambitious, highly autonomous security leader who thrives on building end-to-end and driving strategic impact.

WHAT YOU'LL ACCOMPLISH

LEAD OUR COMPLIANCE PROGRAM

- Run HITRUST certification from kickoff through completion next year, including gap assessment, control mapping, remediation, and assessor management.

- Own SOC 2 Type II end to end, including evidence collection, the auditor relationship, and closing gaps.

- Maintain our HIPAA security and privacy controls, core policies, and BAA obligations.

BUILD AND STRENGTHEN OUR SECURITY PROGRAM

- Complete a full review of Leap’s security posture and deliver a prioritized roadmap of improvements and tooling recommendations.

- Roll out new controls, policies, and processes across the company, partnering with Engineering on implementation across our GCP and data stack.

- Assess new vendors and tools, including AI tools, and run ongoing third-party risk reviews.

OWN WHAT LEAP COMMITS TO ON SECURITY

- Complete security questionnaires, RFP security sections, and controls reviews yourself, with responses that are accurate and consistent.

- Make the call on the security obligations Leap takes on in client and partner agreements.

- Build a response library and repeatable review process that keeps pace as we grow, and represent Leap with client and partner security teams when needed.

RUN OUR SECURITY PARTNERSHIPS AND REPORTING

- Select and manage our external security partner, making sure they extend the program we own internally.

- Keep leadership informed on security posture, risk, and compliance status, and flag where investment is needed.

WHAT YOU BRING

- 7+ years in healthcare information security, governance/risk/compliance (GRC), or IT audit, including directly owning at least one full SOC 2 Type II audit cycle.

- Deep familiarity with security and compliance frameworks such as SOC 2, HIPAA, and HITRUST, and an audit- and GRC-first approach to building a program.

- Experience building a security or compliance program from scratch, or owning one end to end as an early security hire at a startup or growth-stage company.

- Hands-on experience completing security questionnaires and representing your company with enterprise or health plan security teams.

- Working knowledge of the HIPAA Security and Privacy Rules and of handling patient health data (PHI) in B2B healthcare.

- Enough technical depth in cloud infrastructure (GCP preferred) and modern data stacks to review controls and advise engineers through implementation. This isn’t a policy-only role.

- Comfort staying deep in the details while making judgment calls that commit the company.

BONUS POINTS FOR

- Hands-on experience taking a company through HITRUST certification.

- Health tech, digital health, or benefits experience, especially with health plans and large self-funded employers.

- ISO 27001 experience.

- Experience with compliance automation tools such as Vanta, Drata, or Secureframe.

- CISSP, CISA, CISM, or CRISC certification.

At Leap, we’re building an outlier company with real impact — and that takes focus, energy, and commitment. If that excites you, we’d love to hear from you.

Leap is an equal opportunity employer and welcomes applicants from all backgrounds. We’re committed to building a team that reflects a diversity of perspectives, experiences, and identities.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Leap's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Leap's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Leap's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.