Senior Security and Compliance Lead
$145k - $185krater8
Join rater8, voted a Great Place to Work™ by its employees since 2022!
The Senior Security and Compliance Lead owns the strategy, execution, and continuous improvement of the organization's information security and regulatory compliance programs. This leader is accountable for protecting the company, customer, and employee data; maintaining the organization's security posture across cloud environments; and ensuring that the business meets its legal, contractual, and industry-standard obligations.
The role combines hands-on technical leadership with executive-level program management. The Lead builds and leads the security and compliance function, partners across Engineering, Product, and Operations, and reports to the CTO.
Responsible for establishing and maintaining the organization's IT governance framework, risk management methodologies, and cybersecurity compliance programs. Develops enterprise policies and control frameworks while ensuring alignment with regulatory requirements and security standards such as ISO 27001, SOC 2, NIST, and HISTRUST. Conducts risk assessments, manages third-party risk evaluations, and facilitates cybersecurity audits. Creates and maintains security policies, develops security awareness training programs, and serves as the liaison between business, IT, and regulatory bodies to translate compliance requirements into actionable governance strategies.
What you’ll do
Security Strategy & Leadership
- Define and own the multi-year information security strategy and roadmap aligned to business objectives.
- Build, mentor, and lead the security and compliance team, including security engineers, analysts, and GRC (governance, risk management, and compliance) staff.
- Establish and report on security KPIs, KRIs, and program maturity metrics.
- Manage the security and compliance budget, vendor relationships, and tooling investments.
Governance, Risk & Compliance (GRC)
- Own the enterprise risk management program: identify, assess, prioritize, and track remediation of security risks.
- Lead audit readiness and certification efforts (e.g., SOC 2 Type II, ISO 27001, HIPAA, HITRUST, GDPR, CCPA).
- Develop, maintain, and enforce security policies, standards, and procedures.
- Manage relationships with external auditors, assessors, and regulators; coordinate evidence collection and remediation.
- Oversee third-party and vendor risk management and customer security questionnaire responses.
- Partner with other functions on data privacy obligations, breach notification readiness, and cross-functional compliance matters.
Security Operations & Engineering
- Direct security operations, including monitoring, detection, vulnerability management, and patching.
- Own the incident response program — preparation, detection, containment, eradication, recovery, and post-incident review.
- Oversee identity and access management, encryption, network security, and cloud security posture management.
- Champion "security by design" and shift-left practices within the software development lifecycle.
- Lead business continuity and disaster recovery planning, testing, and continuous improvement.
Awareness & Culture
- Design and administer security awareness, training, and phishing simulation programs across the organization.
- Foster a “security is everyone’s responsibility” culture — serve as the internal champion and go-to escalation point for security matters.
- Act as a calm, credible communicator during security events, translating technical risk into clear business language for executives, customers, and the board.
- Other Duties as Assigned
What you’ll bring
- 5+ years in cybersecurity with demonstrated program ownership. You’ve driven initiatives end-to-end, influenced without authority, and been accountable for outcomes, whether or not you carried a management title.
- Familiar with and can demonstrate knowledge and ownership of regulatory compliance, such as SOC 2, HIPAA, HITRUST, GDPR.
- Strong working knowledge of cloud security (Azure, AWS, or GCP), IAM, network security, encryption, and secure SDLC.
- Proven track record leading incident response and managing breaches end-to-end including communication with executives and external stakeholders.
- Experience building and leading teams and managing cross-functional security initiatives
- Ability to translate technical risk into business terms for executives, the board, and customers.
- Bachelor's degree in Computer Science, Information Security, or equivalent practical experience.
- US Residents only. Must reside in the continental U.S., be authorized to work without sponsorship, and not reside in California.
Additional Preferred Qualifications
- Nice to have one or more of the following certifications or equivalent: CISSP, CISM, CCSP, CISA, ISO 27001 Lead Auditor/Implementer, Cloud security certs (AZ-500 / AWS Security Specialty).
- Experience in a regulated or high-trust industry (healthcare, digital health, fintech, SaaS handling sensitive data).
- Familiarity with infrastructure-as-code and securing CI/CD pipelines.
- Experience scaling a compliance program from initial certification through annual renewals where you built the program.
- Master's degree in a relevant field.
Compensation
- The expected salary range for this position is $145,000 - $185,000 annually. Actual compensation will be based on a candidate’s skills, qualifications, and years of relevant experience. In addition to the base salary, this role offers a bonus 10%, an opportunity, OTE of $159,000 - $203,500. Bonus compensation will depend on individual performance and company performance.
What You’ll Get
- Smart, intellectually curious, creative, supportive, and overall awesome colleagues!
- We are 100% fully remote! Work from anywhere in the U.S. with reliable Wi-Fi, within PST–EST time zones. Employees must be physically located in the U.S.; working outside the U.S. requires prior approval from leadership.
- Medical, dental, and vision benefits
- Discounted pet insurance
- Unlimited PTO after 60 days of employment
- 401(k) after six months with company match
- Competitive salary
- Fast-track career advancement with a high-growth, Great Place to Work™ certified organization
- rater8 is a “bring your own device” company, enabling you to work on your preferred operating system; we offer a WFH stipend to offset costs per company guidelines
About rater8
rater8, the healthcare industry’s leader in reputation management, helps medical practices establish pervasive online visibility. The rater8 Visibility Engine (raVE) effortlessly gathers authentic reviews and real-time feedback from verified patients to drive sustainable practice growth, all with the support of award-winning customer service.
Based in the United States, rater8 is a rapidly growing healthtech innovator, serving over 25,000 providers at practices and hospitals of all sizes and specialties, and providing unlimited career growth and pay opportunities for its employees.
rater8 is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to equal opportunity regardless of race, color, ancestry, religion, gender, gender identity, parental or pregnancy status, national origin, sexual orientation, age, citizenship, marital status, disability, or Veteran status.
$121k - $185k
...Senior Security GRC Lead Austin | Chicago | New York City | Salt Lake City | San Francisco Gong harnesses the power of AI to transform... ...visibility, high-impact role at the center of Gong's security and compliance story. As our Senior GRC Security Lead, you will be the...SeniorRemote workWork from homeFlexible hours- Entrust seeks a Senior Security Compliance Analyst to lead PCI DSS and NIST 800-53 programs across cloud, on-prem, and hybrid environments. You will design continuous monitoring, identify gaps, and drive remediation while coordinating with Security, Engineering, and third...SeniorRemote job
- United States Digital Space LLC is seeking a Senior InfoSec GRC Analyst for a fully remote,... ...international role. You will own governance, risk, and compliance across the ISMS, drive ISO 27001 and SOC 2 audits, and review customer security requirements to enable safe production...SeniorRemote job
$149k - $202k
...If it’s high-stakes, high-security, or highly complex—Oxalis is... ...on organizations navigating compliance-heavy environments and complex... ...Principal Consultant at Oxalis, you lead the most complex IFS... ...solutions. You operate as the senior trusted advisor across the engagement...SeniorPermanent employmentFull timeLocal areaRemote work$122.65k - $227.13k
...now. We are currently seeking a Senior MuleSoft Integration Lead to join our team in Plano, Texas (US... ...exception handling, API versioning, security, and deployment governance. ·... ...improvement, release success rate, SLA compliance, and reduction of recurring incidents...SeniorPermanent employmentTemporary workWork at officeLocal areaRemote workFlexible hours$196.5k - $291.5k
..., and shopping simple, personalized, and secure, PayPal empowers consumers and businesses... ...Decisioning Platform drives fraud, credit, and compliance decisions, processing massive signal volumes in milliseconds. We're looking for a Lead Product Manager to own the strategy,...SeniorFull timeWork at officeLocal areaImmediate startFlexible hours- ...Apogee Global RMS is seeking a Senior Cybersecurity Engineer / Offensive Security Lead to support high‑visibility federal and IC programs. This role is designed for operators who bring hands‑on offensive tradecraft, current certifications, and recent red‑team experience...SeniorFull time
$97.34k - $127.2k
About the opportunitySWCA Environmental Consultants is seeking a Lead, Senior or Principal Biologist with experience in natural resource... ...needs and can withstand agency and public scrutiny.Drives compliance of safety policies and reporting requirements to ensure overall...SeniorFull timeFor contractorsFor subcontractorWork at officeImmediate startRemote work- ...our technical excellence and leading innovations, and for making a... ...thrive.Your day at NTT DATAThe Senior Team Lead, Network Field... ...installations meet industry standards, compliance requirements, and best... ...enterprise-scale AI, cloud, security, connectivity, data centers and...SeniorFull timeRemote work
$175k - $215k
...do: Halcyon is the industry’s first dedicated, adaptive security platform that combines multiple proprietary advanced prevention... ...Role: Halcyon is looking for a highly experienced Senior Deal Desk Lead to build and operate a disciplined, scalable approach to...SeniorFull timeContract workTemporary workRemote workFlexible hours- ...vision is to be the worldwide partner of choice in defense and security, and civil aviation by revolutionizing our customers’ training and... ...& HPC (High Performance Computing) group, specifically as a Lead Geospatial Engineer performing as a project lead in the development...SeniorFull timeContract workWork at officeLocal areaRemote workWorldwide
$93.6k
...proprieta... Show more Full-time Senior Consultant, Air Quality.Ready to lead complex air quality solutions and... ...roadways to reservoirs, schoolyards to security solutions, clients look to TRC for... ...to support complex regulatory compliance, permitting, and air quality modeling...SeniorPermanent employmentFull timeTemporary workPart timeCasual workWork at officeLocal areaWork from home- ...About Whirlpool CorporationWhirlpool Corporation (NYSE: WHR) is a leading home appliance company, in constantpursuit of improving life... ...communities and to ensure that all facilities are in compliance with regulations.This role in summaryAs the EHS Sr Analyst, you...SeniorFor contractorsLocal areaWork from homeMonday to Friday
$212k - $333.19k
...to accelerate access to transformative medicines and make a lasting impact on patients worldwide.Join Takeda as a Senior Director, Global Regulatory Lead - Oncology, where you will be part of the global regulatory team. In this influential role, you will lead a top-priority...SeniorMinimum wageTemporary workLocal areaRemote workWorldwide$169.5k - $248.6k
...ready to bring your best to work that truly matters for patients, we invite you to join us. About the RoleAs the Global Regulatory Lead (GRL), you will be the accountable decision maker for the development & execution of global regulatory strategies— from portfolio entry...SeniorLocal areaRemote workRelocationFlexible hours$233.4k - $392.4k
...business lines, serving as a senior advisor on complex regulatory... ...and product matters. This role leads a team of attorneys and legal... ...appropriate risk allocation, compliance, and alignment with corporate... ...(e.g., HR, Finance, Privacy, Security, Compliance, Government...SeniorPermanent employmentFull timeLive inWork at officeLocal areaRemote work- Ensemble Health Partners seeks a Senior Coding Compliance Auditor to lead the development and execution of the annual compliance workplan, including auditing and monitoring workplans, and to deliver detailed audits and high-quality reports. The role involves coaching auditors...SeniorRemote job
- Emory University is seeking a Senior Research Compliance Specialist to ensure adherence to federal, state, sponsor, and university regulations across... ...responsible research conduct. Additionally, the specialist leads export control efforts and provides training on compliance...SeniorRemote job
- Tailored Brands, Inc. is seeking a Senior Customs Compliance Manager based in Dublin, CA. This role involves leading the customs compliance program for U.S. imports and requires extensive knowledge of customs regulations. Candidates should have over 8 years of relevant...SeniorRemote job
$258.68k - $313.46k
...regional regulatory staff as Global Regulatory Lead and US Regional Regulatory Lead on... ...payments, financial information, or social security numbers during our application or... ...directed to Chat with Ripley.R1603594 : Senior Director, Global Regulatory Lead NeuroscienceSummaryLocation...SeniorHourly payFull timeTemporary workPart timeFor contractorsSummer workLive inWork at officeLocal areaRemote workFlexible hoursShift work- Centene is seeking a Compliance professional to partner with leadership in maintaining Duals (D-SNP) program compliance. The role involves regulatory interpretation, reporting, and leading auditing/monitoring strategies for D-SNPs across programs. This position supports...SeniorRemote job
- Freese and Nichols is actively seeking Cultural Resources Lead - Senior Archaeologist for immediate, full-time employment in Fort Worth,... ...Lead state and federal archaeological permitting and support compliance within applicable regulatory frameworks, including NEPA and NHPA...SeniorFull timeWork at officeLocal areaImmediate startRemote workFlexible hours
- POSITION OVERVIEWThe Senior/Lead Analyst, Market Risk, reports directly to the Manager, Market Risk, and is responsible for developing... ...Management requirements, including daily risk reporting to ensure compliance with Risk Policies and Limits as well as providing risk...SeniorWork at officeWork from homeFlexible hoursWeekend work
- Emory University in Atlanta is looking for a Senior Research Compliance Specialist to ensure compliance with federal and university research regulations. This role involves conducting compliance reviews, providing training, and managing investigations. A Bachelor's degree...SeniorRemote job
$70k - $94k
Strata Decision Technology is looking for a Senior Compliance Associate to join their IT team in Chicago, IL. The role requires expertise in IT governance, risk, and compliance, with a focus on achieving HITRUST and SOC compliance. Candidates should have 4+ years of experience...SeniorWork from home- Centene Corporation is seeking a Senior Manager, Privacy & Security Lead Regulatory Analyst Team to oversee a team responsible for managing privacy, security, and compliance risk management. You will translate complex regulatory requirements into actionable insights while...SeniorRemote job
- Land Gorilla is seeking a Senior Applications & Compliance Specialist in San Diego, CA to design, build, and maintain internal applications (vendor inspections app, OneSite) while supporting SOC compliance and audits. This is a remote-first role with weekly in-person meetings...SeniorRemote job
- ...oversee centralized filings, advise on asset classifications, and lead a multidisciplinary team across state lines. The role... ...leadership in supervising staff while maintaining timely filings and regulatory compliance. #J-18808-Ljbffr DuCharme, McMillen & Associates, Inc.SeniorRemote job
- A health organization is seeking a Senior Credentialing Specialist to oversee provider credentialing and ensure compliance with health plan requirements. This role involves supervising credentialing staff, maintaining provider data in EMR systems, and managing licensing...SeniorRemote job
$113k - $182.56k
Dentsu Aegis Network Ltd. is seeking a leader for information security within the CxM Practice Area, emphasizing embedded security in products and services. The role demands a balance of remote work with periodic in-office presence in Maryland. The ideal candidate holds...SeniorRemote jobWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Security and Compliance Lead. Be the first to apply!
- senior lead project manager Remote
- senior robotics software engineer Remote
- senior firewall engineer Remote
- senior devops engineer remote Remote
- senior sas administrator Remote
- senior IT manager Remote
- senior director of client services Remote
- senior contracts analyst Remote
- senior implementation consultant Remote
- sr project manager Remote



