Security Operations Lead

Tandem
New York
Workplace: OnsiteFull timeFunction: Program & Project Management (PMO)Experience: 4-7 yearsSkills: ["Communication","Stakeholder management","Risk management","Ownership mindset","Problem solving"]

Own end-to-end security and compliance programs, including SOC 2 Type II, HIPAA, and HITRUST, from readiness through audit and continuous monitoring. Build the customer trust function (questionnaires, RFPs, due diligence, trust center) so security accelerates deals. Stand up compliance automation for evidence collection and control monitoring, author security policies and run awareness/access reviews, and partner with engineering and legal to map frameworks to technical controls and coordinate auditors and penetration-testing firms.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Tandem
Tandem
1 month ago

Security Operations Lead

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 14 hours agoStatus: Live

Job Summary

Own end-to-end security and compliance programs, including SOC 2 Type II, HIPAA, and HITRUST, from readiness through audit and continuous monitoring. Build the customer trust function (questionnaires, RFPs, due diligence, trust center) so security accelerates deals. Stand up compliance automation for evidence collection and control monitoring, author security policies and run awareness/access reviews, and partner with engineering and legal to map frameworks to technical controls and coordinate auditors and penetration-testing firms.
Location: New York
Workplace: Onsite
Employment Type: Full time
Job Function: Program & Project Management (PMO)

Key Responsibilities

  • •Own security compliance programs end to end (SOC 2 Type II, HIPAA, HITRUST) from readiness through audit and continuous monitoring.
  • •Build and run the customer trust function (security questionnaires, RFPs, due diligence, and trust center) to accelerate deals.
  • •Stand up and administer compliance automation to turn evidence collection and control monitoring into a continuous, low-toil system.
  • •Author security policies, run security-awareness training, and drive access reviews and audit readiness.
  • •Partner with engineering and legal to translate framework and customer requirements into controls, coordinating auditors and penetration-testing firms; own the risk register.

Pay and Benefits

Perks:Health InsuranceVisionDentalPaid LeaveParental Leave401kCommuter Benefits

Key Requirements

  • •Typically 4–7 years in GRC, security compliance, or security program management, with a track record of running audits end to end.
  • •Hands-on experience with SOC 2 and HIPAA; HITRUST experience is a strong plus, including standing up a new framework from scratch.
  • •Experience in a regulated, high-growth environment, ideally healthcare or another serious data-handling domain.
  • •Fluency with compliance automation tooling and enough technical literacy to work with engineers on cloud, identity, and logging controls.
  • •Experience owning customer-facing security for enterprise buyers, including questionnaires, trust centers, and due diligence.
Experience:4-7 yearsHealthcareGRCSecurity complianceRegulated environmentEnterprise security
Skills:CommunicationStakeholder managementRisk managementOwnership mindsetProblem solving
Tech Stack:SOC 2HIPAAHITRUSTCompliance automationVendor risk assessmentsSecurity questionnairesRFPsTrust centerPenetration testingCloudIdentityLogging

Company Brief

Tandem
Builds a virtual office platform that helps remote teams connect, collaborate, and communicate in real time with presence, audio rooms, and workspace tools designed to recreate an in-person office experience online.
Industry: Enterprise Software
Website