Jobs · Legal

Lead Security & Compliance Analyst

Jobgether · United States · 3 wk ago
RemoteRemoteLegal$80k–$135k/yrFull-time

About the role

The Lead Security & Compliance Analyst will combine security governance expertise with hands-on technical security operations, owning critical compliance programs and strengthening security practices in a growing healthcare technology environment.

Responsibilities

  • Own end-to-end compliance audit activities, including SOC 1, SOC 2, HITRUST CSF, and HITRUST AI audits.
  • Develop, maintain, and improve security policies, procedures, and operational practices aligned with frameworks such as HIPAA, HITRUST, and SOC.
  • Manage compliance automation and trust management platforms, ensuring controls are monitored effectively and customer security requests are addressed efficiently.
  • Coordinate with external auditors, vendors, and customers to support security reviews, compliance validations, and assessment processes.
  • Lead third-party risk assessments and manage responses to customer security questionnaires and external security inquiries.
  • Deliver security awareness and compliance training while evaluating the effectiveness of internal controls.
  • Manage vulnerability management processes, including security scanning, vulnerability prioritization, remediation tracking, and collaboration with engineering teams.
  • Investigate and address security findings across cloud environments, including AWS services such as EKS, WAF, Shield, CloudFront, and IAM.
  • Review external attack surface findings and implement technical improvements related to security configurations, encryption, headers, and infrastructure protections.
  • Support security incident response activities, including log analysis, forensic evidence collection, investigation, and containment efforts.
  • Aid in fraud investigations and forensic reviews by analyzing authentication logs, extracting relevant data, and preserving evidence when required.
  • Improve security operations through automation, scripting, and process optimization using tools and technologies such as Python or Bash.

Requirements

  • 4+ years of combined experience in security compliance, GRC, and hands-on technical security roles.
  • Proven experience supporting SOC 1, SOC 2, and/or HITRUST audits, including participation in a complete audit lifecycle.
  • Strong understanding of HIPAA Security and Privacy requirements.
  • Hands-on experience with vulnerability management, security scanning, remediation workflows, and interpreting technical findings such as CVEs and cloud misconfigurations.
  • Familiarity with AWS security concepts, including IAM, security groups, logging, monitoring, and web application security controls.
  • Ability to create clear security policies, procedures, remediation plans, and technical documentation.
  • Strong communication skills with the ability to collaborate with engineering teams, auditors, vendors, and business stakeholders.
  • Experience working with compliance automation platforms such as Drata, Vanta, or similar tools is preferred.
  • Background in healthcare or another regulated industry is a plus.
  • Security certifications such as CISSP, CISA, CRISC, HITRUST CCSFP, or CISM are highly valued.
  • Experience with SIEM platforms, log analysis, forensic investigations, fraud analysis, or legal/eDiscovery support is beneficial.

Benefits

  • Competitive base salary range of $80,000 to $135,000 USD, depending on experience and level.
  • An annual company-wide bonus opportunity of up to 15% based on company performance.
  • Equity incentive plan.
  • Comprehensive medical, dental, and vision coverage with flexible plan options.
  • Employer-funded Health Savings Account (HSA) contributions.
  • 401(k) retirement plan.
  • Remote-first work environment with access to office and coworking space support.
  • Flexible vacation policy.
  • Additional paid summer Fridays.
  • Home office and wellness stipend.
  • Annual learning and professional development stipend.
  • Opportunity to contribute to meaningful healthcare technology initiatives while working in a collaborative security-focused environment.

Similar jobs

Lead Security Analyst

Ovative GroupChicago, IL· 3 wk ago
Information Technology$90k/yrapply on ovative.wd12.myworkdayjobs.com