Lead Security & Compliance Analyst
Jobgether · United States · 3 wk ago
RemoteRemoteLegal$80k–$135k/yrFull-time
About the role
The Lead Security & Compliance Analyst will combine security governance expertise with hands-on technical security operations, owning critical compliance programs and strengthening security practices in a growing healthcare technology environment.
Responsibilities
- Own end-to-end compliance audit activities, including SOC 1, SOC 2, HITRUST CSF, and HITRUST AI audits.
- Develop, maintain, and improve security policies, procedures, and operational practices aligned with frameworks such as HIPAA, HITRUST, and SOC.
- Manage compliance automation and trust management platforms, ensuring controls are monitored effectively and customer security requests are addressed efficiently.
- Coordinate with external auditors, vendors, and customers to support security reviews, compliance validations, and assessment processes.
- Lead third-party risk assessments and manage responses to customer security questionnaires and external security inquiries.
- Deliver security awareness and compliance training while evaluating the effectiveness of internal controls.
- Manage vulnerability management processes, including security scanning, vulnerability prioritization, remediation tracking, and collaboration with engineering teams.
- Investigate and address security findings across cloud environments, including AWS services such as EKS, WAF, Shield, CloudFront, and IAM.
- Review external attack surface findings and implement technical improvements related to security configurations, encryption, headers, and infrastructure protections.
- Support security incident response activities, including log analysis, forensic evidence collection, investigation, and containment efforts.
- Aid in fraud investigations and forensic reviews by analyzing authentication logs, extracting relevant data, and preserving evidence when required.
- Improve security operations through automation, scripting, and process optimization using tools and technologies such as Python or Bash.
Requirements
- 4+ years of combined experience in security compliance, GRC, and hands-on technical security roles.
- Proven experience supporting SOC 1, SOC 2, and/or HITRUST audits, including participation in a complete audit lifecycle.
- Strong understanding of HIPAA Security and Privacy requirements.
- Hands-on experience with vulnerability management, security scanning, remediation workflows, and interpreting technical findings such as CVEs and cloud misconfigurations.
- Familiarity with AWS security concepts, including IAM, security groups, logging, monitoring, and web application security controls.
- Ability to create clear security policies, procedures, remediation plans, and technical documentation.
- Strong communication skills with the ability to collaborate with engineering teams, auditors, vendors, and business stakeholders.
- Experience working with compliance automation platforms such as Drata, Vanta, or similar tools is preferred.
- Background in healthcare or another regulated industry is a plus.
- Security certifications such as CISSP, CISA, CRISC, HITRUST CCSFP, or CISM are highly valued.
- Experience with SIEM platforms, log analysis, forensic investigations, fraud analysis, or legal/eDiscovery support is beneficial.
Benefits
- Competitive base salary range of $80,000 to $135,000 USD, depending on experience and level.
- An annual company-wide bonus opportunity of up to 15% based on company performance.
- Equity incentive plan.
- Comprehensive medical, dental, and vision coverage with flexible plan options.
- Employer-funded Health Savings Account (HSA) contributions.
- 401(k) retirement plan.
- Remote-first work environment with access to office and coworking space support.
- Flexible vacation policy.
- Additional paid summer Fridays.
- Home office and wellness stipend.
- Annual learning and professional development stipend.
- Opportunity to contribute to meaningful healthcare technology initiatives while working in a collaborative security-focused environment.