Security & Compliance Manager (GRC), US-based

Collectly
United States
Workplace: RemoteFull timeUSD 190,000 - 220,000 annuallyFunction: Legal, Risk & ComplianceSkills: ["Customer-facing communication","Risk judgment","Threat modeling","Technical conversation fluency","Evidence automation"]

Own security and compliance end to end for a US healthcare patient billing and payments platform handling PHI and card payments. Lead SOC 2, HITRUST, PCI DSS, HIPAA, and pen test lifecycle activities; manage customer security questionnaires, audits, right-to-audit support, and customer-facing incident communications. Build scalable GRC automation using Vanta and security evidence collection, plus privacy and AI governance for an AI patient billing agent.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Collectly
Collectly
1 day ago

Security & Compliance Manager (GRC), US-based

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 8 hours agoStatus: Live

Job Summary

Own security and compliance end to end for a US healthcare patient billing and payments platform handling PHI and card payments. Lead SOC 2, HITRUST, PCI DSS, HIPAA, and pen test lifecycle activities; manage customer security questionnaires, audits, right-to-audit support, and customer-facing incident communications. Build scalable GRC automation using Vanta and security evidence collection, plus privacy and AI governance for an AI patient billing agent.
Location: United States
Workplace: Remote
Employment Type: Full time
Job Function: Legal, Risk & Compliance
Seniority: Manager level

Key Responsibilities

  • •Answer customer security questionnaires, including AI governance and responsible-AI reviews for the AI patient billing agent.
  • •Run and manage security audits and certifications (SOC 2, HITRUST, PCI DSS, HIPAA Security Risk Analysis), including readiness, evidence, auditor management, and remediation tracking.
  • •Own customer-facing escalations, incident communications, customer-facing RCAs, and right-to-audit clause hosting.
  • •Administer compliance tooling and evidence collection (Vanta, security scanners), pulling evidence from systems instead of manual screenshots and reducing manually evidenced controls.
  • •Lead privacy and AI governance work, including HIPAA Privacy Officer designation, state privacy law tracking, and a durable AI governance framework.

Pay and Benefits

Salary: USD 190,000 - 220,000 annually
Equity and Bonus:Equity
Perks:Paid LeaveHealth InsuranceDentalVision401kEquityStudent Loan

Key Requirements

  • •Extensive experience in security compliance or GRC in a healthcare SaaS or PHI-handling environment, ideally having run SOC 2 and HITRUST as an owner.
  • •Deep HIPAA fluency across Security Rule, Privacy Rule, and Breach Notification Rule, including BAAs and minimum necessary.
  • •Hands-on with Vanta or a comparable compliance automation platform and the ability to pick up new GRC frameworks (e.g., NIST AI RMF, ISO 42001).
  • •Expert ownership of security questionnaires, audits/certifications, and pen test lifecycle including scoping, remediation tracking, and customer-facing summaries.
  • •Strong threat-model judgment and the ability to follow technical conversations with DevOps and platform engineers to determine exploitability and appropriate escalation.
Experience:Healthcare SaaSPHIGRCSecurity compliancePayments
Skills:Customer-facing communicationRisk judgmentThreat modelingTechnical conversation fluencyEvidence automation
Certifications:CIPP/USHCISPPCISSPHITRUST CCSFP
Tech Stack:VantaSOC 2HITRUSTHITRUST i1PCI DSSHIPAAHITRUST CCSFPSOC 2 Type 2NIST AI RMFISO 42001CCPA/CPRAWashington My Health My DataArcherProcessUnityVenminderEDRInfrastructure-as-codeIdentity providerDevOpsEHR

Company Brief

Collectly
Offers a healthcare revenue cycle platform that automates patient billing, payment communications, and collections workflows to increase payments, reduce accounts receivable, and improve patient financial engagement.
Industry: HealthTech
Website