Security & Compliance Manager @Collectly
Compliance
Salary $190,000 - $220..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 1wk ago

[Hiring] Security & Compliance Manager @Collectly

1wk ago - Collectly is hiring a remote Security & Compliance Manager. πŸ’Έ Salary: $190,000 - $220,000 per year πŸ“Location: USA

Role Description

You'll own security and compliance end to end. Today it's split between the CTO and whichever engineer happens to be nearest. You'll take all of it. You'll be the only person in this function, so the job is to build a program that scales without adding drag. Automate the evidence, delete the controls nobody can trace to a requirement, and answer the hard customer questions yourself instead of routing them to engineering.

What you'll own

  • Customer-facing security and compliance
  • Answering customers’ security questionnaires
  • AI governance questionnaires and responsible-AI reviews covering our AI patient billing agent
  • Live security calls with prospects' InfoSec teams β€” technical conversations, not slide reading
  • Health-system procurement portals (Archer, ProcessUnity, Venminder and similar)
  • Annual customer reattestation cycles
  • Customer security escalations, incident communications, and customer-facing RCAs
  • Hosting customers who exercise right-to-audit clauses
  • Distribution of SOC 2, HITRUST certification, pen test summaries, and subprocessor notices under NDA
  • A public trust center, standard security package, and answer library β€” so most of the above becomes a lookup rather than a project
  • Audits and certifications
  • HITRUST i1 and SOC 2 Type 2, end to end: readiness, evidence, auditor management, remediation tracking
  • PCI DSS: SAQ ownership, AOC collection from processors, scope definition for card-present and card-not-present flows
  • Annual HIPAA Security Risk Analysis and risk register
  • Pen test lifecycle: scheduling, scoping, remediation tracking, customer-facing summary
  • Quarterly user access reviews
  • BCP/DR tabletops and annual test coordination
  • Compliance tooling
  • Own Vanta and our security scanners as an administrator
  • Pull evidence from systems β€” CI, infrastructure-as-code, identity provider, EDR, cloud config β€” instead of collecting screenshots
  • Reduce the count of manually evidenced controls every year
  • Contracts, BAAs, and vendor risk
  • BAAs in both directions, customer and subcontractor, from template through negotiation
  • Security exhibits, DPAs, subprocessor inventory
  • Tiered vendor security review, so a no-PHI vendor gets a one-page checklist and a same-day answer
  • Annual vendor reattestation
  • Policies, training, and incident response
  • Own and maintain the policy set
  • Security awareness and HIPAA training, phishing simulations, completion tracking
  • Own the incident response program: runbooks, tabletops, coordination during an incident
  • Breach notification clock management β€” the HIPAA window, state AG requirements, cyber insurance notice, and the per-contract customer notification windows in our MSAs
  • A documented exception process with a named approver, expiry date, and compensating control
  • Privacy and AI governance
  • HIPAA Privacy Officer designation
  • State privacy law tracking: CCPA/CPRA, Washington My Health My Data, and what follows
  • Stand up a durable AI governance framework for our AI patient billing agent β€” model inventory, human oversight, monitoring β€” replacing today's per-customer, from-scratch approach
  • Track emerging state rules on AI in healthcare and AI-generated patient communications

What you won't own

  • Remediation engineering.
  • Shipping decisions.
  • A seat as a gate in design or code review.

Qualifications

  • Extensive experience in security compliance or GRC, including time in healthcare SaaS or another PHI-handling environment
  • Has run SOC 2 and HITRUST as an owner, not a contributor
  • Deep HIPAA fluency: Security Rule, Privacy Rule, Breach Notification Rule, BAAs, minimum necessary
  • Hands-on with Vanta or a comparable compliance automation platform
  • Strong on frameworks generally, and able to pick up an unfamiliar one and apply it without a playbook β€” NIST AI RMF and ISO 42001 are where we're headed and neither has settled practice yet
  • Writes final-draft customer-facing prose: clear, accurate, no hedging
  • Able to follow a technical conversation with our DevOps and platform engineers unassisted β€” architecture diagrams, infrastructure-as-code, access control models, cloud configuration
  • Reasons about threat models, not finding titles.
  • A software engineering or security engineering background is a strong plus here, though not required β€” what matters is the judgment, however you acquired it.
  • Also a plus: PCI DSS in a payments context. Certifications we recognize: CIPP/US, HCISPP, CISSP, HITRUST CCSFP.

Process

Intro with the CTO, then a working session where we answer a real inbound security questionnaire together, then a scenario conversation and cross-functional interviews. No take-home. Please be prepared to actively research information during the exercise.

Benefits

  • Unlimited PTO: We believe in work-life balance and encourage you to recharge when you need it.
  • Comprehensive Health Coverage: Fully paid medical, dental, and vision insurance for you and your dependents, because your well-being matters to us.
  • Equity Opportunities: Share in our success with stock options - your hard work will drive our growth.
  • Retirement Planning Made Easy: Enjoy a 401(k) with a generous company match to secure your future.
  • Student Loan Support: We help lighten the load with contributions toward your student loans.
  • Competitive Compensation: $190,000 - $220,000 per year
Before You Apply
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Security & Compliance Manager @Collectly
Compliance
Salary $190,000 - $220..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 1wk ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 120,000+ Remote Jobs
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 120,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 120,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 124,107+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later