Senior Manager, Security & Compliance @Leap
Compliance
Salary usd 150,000 - 1..
Remote Location
🇺🇸 USA Only
Employment Type full-time
Posted Today

[Hiring] Senior Manager, Security & Compliance @Leap

Today - Leap is hiring a remote Senior Manager, Security & Compliance. 💸 Salary: usd 150,000 - 190,000 per year 📍Location: USA

Role Description

Leap is hiring a Senior Manager, Security & Compliance to lead the next phase of our security program. We have an established foundation, including SOC 2 Type II and HIPAA-aligned controls. Now we’re looking for a leader to shape where the program goes next and own the work of getting there, starting with HITRUST certification.

This is a hands-on builder role. You’ll set the direction for our security and compliance program and do much of the work yourself:

  • Running audits and certifications
  • Writing policies
  • Reviewing controls
  • Completing security questionnaires

You’ll also be trusted with the judgment calls that matter most, including:

  • The security obligations Leap commits to
  • The vendors and tools we adopt
  • How new controls roll out across the company

You’ll represent Leap with client and partner security teams when it counts, but the core of the job is building and maintaining a program strong enough to make those conversations easy. You’ll work closely with Engineering, Operations, and our go-to-market teams, and you’ll manage our external security partner.

This is an individual contributor role for an ambitious, highly autonomous security leader who thrives on building end-to-end and driving strategic impact.

Qualifications

  • 7+ years in healthcare information security, governance/risk/compliance (GRC), or IT audit, including directly owning at least one full SOC 2 Type II audit cycle.
  • Deep familiarity with security and compliance frameworks such as SOC 2, HIPAA, and HITRUST, and an audit- and GRC-first approach to building a program.
  • Experience building a security or compliance program from scratch, or owning one end to end as an early security hire at a startup or growth-stage company.
  • Hands-on experience completing security questionnaires and representing your company with enterprise or health plan security teams.
  • Working knowledge of the HIPAA Security and Privacy Rules and of handling patient health data (PHI) in B2B healthcare.
  • Enough technical depth in cloud infrastructure (GCP preferred) and modern data stacks to review controls and advise engineers through implementation. This isn’t a policy-only role.
  • Comfort staying deep in the details while making judgment calls that commit the company.

Requirements

  • Run HITRUST certification from kickoff through completion next year, including gap assessment, control mapping, remediation, and assessor management.
  • Own SOC 2 Type II end to end, including evidence collection, the auditor relationship, and closing gaps.
  • Maintain our HIPAA security and privacy controls, core policies, and BAA obligations.
  • Complete a full review of Leap’s security posture and deliver a prioritized roadmap of improvements and tooling recommendations.
  • Roll out new controls, policies, and processes across the company, partnering with Engineering on implementation across our GCP and data stack.
  • Assess new vendors and tools, including AI tools, and run ongoing third-party risk reviews.
  • Complete security questionnaires, RFP security sections, and controls reviews yourself, with responses that are accurate and consistent.
  • Make the call on the security obligations Leap takes on in client and partner agreements.
  • Build a response library and repeatable review process that keeps pace as we grow, and represent Leap with client and partner security teams when needed.
  • Select and manage our external security partner, making sure they extend the program we own internally.
  • Keep leadership informed on security posture, risk, and compliance status, and flag where investment is needed.

Benefits

  • Hands-on experience taking a company through HITRUST certification.
  • Health tech, digital health, or benefits experience, especially with health plans and large self-funded employers.
  • ISO 27001 experience.
  • Experience with compliance automation tools such as Vanta, Drata, or Secureframe.
  • CISSP, CISA, CISM, or CRISC certification.

Company Description

At Leap, we’re building an outlier company with real impact — and that takes focus, energy, and commitment. If that excites you, we’d love to hear from you.

Leap is an equal opportunity employer and welcomes applicants from all backgrounds. We’re committed to building a team that reflects a diversity of perspectives, experiences, and identities.

Before You Apply
️
🇺🇸 Be aware of the location restriction for this remote position: USA Only
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Senior Manager, Security & Compliance @Leap
Compliance
Salary usd 150,000 - 1..
Remote Location
🇺🇸 USA Only
Employment Type full-time
Posted Today
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 125,000+ Remote Jobs
️
🇺🇸 Be aware of the location restriction for this remote position: USA Only
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 125,000+ Remote Jobs
×
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 ★★★★★ from 500+ reviews

⚡ 125,129+ remote jobs, refreshed hourly

🔔 Real-time alerts: Apply first, direct to employer

🛡️ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later