Job Description
📋 Description Support HITRUST, SOC 2, PCI-DSS, and HIPAA audit readiness. Build and manage vendor security assessment lifecycle. Stand up and run security awareness training program. Operate the centralized risk register and track security risks. Partner cross-functionally with Privacy, Legal, IT, and Engineering to embed compliance. 🎯 Requirements 5+ years in a GRC, compliance, or security risk role. Knowledge of at least two of HITRUST, SOC 2, PCI-DSS, HIPAA. Experience with a GRC platform (Vanta, Drata, OneTrust, or similar). Clear communication of compliance needs to technical and non-technical audiences. Preference for repeatable processes over one-off efforts. Excitement for using AI and modern tooling to scale compliance ops. 🎁 Benefits Equity compensation Medical, Dental, and Vision coverage 401K Work-from-Home Stipend Therapy Reimbursement Flexible PTO