Security & Compliance Manager (GRC), US-based
$190k - $220kCollectly, Inc.
About Collectly Collectly is a patient billing and payments platform for US healthcare providers. We handle protected health information and card payments at scale, integrate directly with major EHRs, and sell to health systems and large provider organizations buyers with real security programs and real diligence processes. We're HITRUST i1 Validated and SOC 2 Type 2. The role You'll own security and compliance end to end. Today it's split between the CTO and whichever engineer happens to be nearest. You'll take all of it. You'll be the only person in this function, so the job is to build a program that scales without adding drag. Automate the evidence, delete the controls nobody can trace to a requirement, and answer the hard customer questions yourself instead of routing them to engineering. What you'll own Customer-facing security and compliance The largest part of the job. Answering customers’ security questionnaires AI governance questionnaires and responsible-AI reviews covering our AI patient billing agent Live security calls with prospects' InfoSec teams - technical conversations, not slide reading Health-system procurement portals (Archer, ProcessUnity, Venminder and similar) Annual customer reattestation cycles Customer security escalations, incident communications, and customer-facing RCAs Hosting customers who exercise right-to-audit clauses Distribution of SOC 2, HITRUST certification, pen test summaries, and subprocessor notices under NDA A public trust center, standard security package, and answer library - so most of the above becomes a lookup rather than a project Audits and certifications HITRUST i1 and SOC 2 Type 2, end to end: readiness, evidence, auditor management, remediation tracking PCI DSS: SAQ ownership, AOC collection from processors, scope definition for card-present and card-not-present flows Annual HIPAA Security Risk Analysis and risk register Pen test lifecycle: scheduling, scoping, remediation tracking, customer-facing summary Quarterly user access reviews BCP/DR tabletops and annual test coordination Compliance tooling Own Vanta and our security scanners as an administrator Pull evidence from systems - CI, infrastructure-as-code, identity provider, EDR, cloud config - instead of collecting screenshots Reduce the count of manually evidenced controls every year Contracts, BAAs, and vendor risk BAAs in both directions, customer and subcontractor, from template through negotiation Security exhibits, DPAs, subprocessor inventory Tiered vendor security review, so a no-PHI vendor gets a one-page checklist and a same-day answer Annual vendor reattestation Policies, training, and incident response Own and maintain the policy set Security awareness and HIPAA training, phishing simulations, completion tracking Own the incident response program: runbooks, tabletops, coordination during an incident Breach notification clock management - the HIPAA window, state AG requirements, cyber insurance notice, and the per-contract customer notification windows in our MSAs A documented exception process with a named approver, expiry date, and compensating control Privacy and AI governance HIPAA Privacy Officer designation State privacy law tracking: CCPA/CPRA, Washington My Health My Data, and what follows Stand up a durable AI governance framework for our AI patient billing agent - model inventory, human oversight, monitoring - replacing today's per-customer, from-scratch approach Track emerging state rules on AI in healthcare and AI-generated patient communications What you won't own Remediation engineering. Findings and fixes belong to DevOps. You own the SLA dashboard and the escalation path. Shipping decisions. You document risk and elevate. The CTO decides on the priority. A seat as a gate in design or code review. What we're looking for Extensive experience in security compliance or GRC, including time in healthcare SaaS or another PHI-handling environment Has run SOC 2 and HITRUST as an owner, not a contributor Deep HIPAA fluency: Security Rule, Privacy Rule, Breach Notification Rule, BAAs, minimum necessary Hands-on with Vanta or a comparable compliance automation platform Strong on frameworks generally, and able to pick up an unfamiliar one and apply it without a playbook - NIST AI RMF and ISO 42001 are where we're headed and neither has settled practice yet Writes final-draft customer-facing prose: clear, accurate, no hedging Able to follow a technical conversation with our DevOps and platform engineers unassisted - architecture diagrams, infrastructure-as-code, access control models, cloud configuration Reasons about threat models, not finding titles. Given how a control is actually implemented in our system, you can work out whether a finding is exploitable, whether it's already mitigated elsewhere, and whether it matters for the data in question. You can close something as not applicable with a written rationale that survives an auditor, and you can tell when the opposite is true and it needs to be escalated hard. A software engineering or security engineering background is a strong plus here, though not required — what matters is the judgment, however you acquired it. Also a plus: PCI DSS in a payments context. Certifications we recognize: CIPP/US, HCISPP, CISSP, HITRUST CCSFP. Process Intro with the CTO, then a working session where we answer a real inbound security questionnaire together, then a scenario conversation and cross-functional interviews. No take-home. Please be prepared to actively research information during the exercise. Why you'll love it here Unlimited PTO: We believe in work-life balance and encourage you to recharge when you need it. Comprehensive Health Coverage: Fully paid medical, dental, and vision insurance for you and your dependents, because your well-being matters to us. Equity Opportunities: Share in our success with stock options - your hard work will drive our growth. Retirement Planning Made Easy: Enjoy a 401(k) with a generous company match to secure your future. Student Loan Support: We help lighten the load with contributions toward your student loans. Competitive Compensation: $190,000 - $220,000 per year Collectly is a tech-enabled patient billing platform that works as an add-on for your EHR/PM. Collectly accelerates and increases patient cash flow, streamlines post-service billing operations, and provides the best patient experience that works for all demographics. #J-18808-Ljbffr Collectly, Inc.
$175k - $190k
...Mineralys is a fully remote company. Sr. Manager, Compliance Operations The Senior Manager, Compliance... ...compensation may vary from posted hiring range based on geographic location, work experience, education, and/or skill level. US Salary Range: $175,000 - $190,000 #J-1880...SuggestedRemote jobWork experience placementLocal areaNight shift$75k - $95k
...NextgenID is hiring a GRC Analyst to do the hands... ...on work that keeps our compliance program running. We verify... ..., and complete the security questionnaires our customers... ...to the GRC Lead and management for review before submission... ...agencies in the US Defense, intelligence,...SuggestedFull timeFor contractorsInternshipLocal areaRemote workWorldwide- ...innovation. THE POSITION NMC² is hiring a GRC Analyst to join the Information Security team, reporting to the GRC & Privacy Manager and based at our Dallas, TX offices at Victory... ...-functional coordination that keep our compliance posture current and our risk exposure...Suggested
$163k - $203.8k
...growth is built. At Mercury, we believe compliance is the infrastructure of trust—a way... ...’re hiring a Senior Compliance Risk Manager, Securities to help us continue this tradition: someone who... ...rewards package at Mercury includes base salary, equity (stock options/RSUs),...SuggestedRemote work- # Governance, Risk & Compliance (GRC) AnalystAlignerrFull timeMiami, FLCyber... ..., risk frameworks, or security audits, your expertise is exactly... ...in GRC, compliance, or risk management• Familiar with one or more... ...platforms Why Join Us • Work directly on frontier...SuggestedHourly payOngoing contractContract workFor contractorsFreelanceRemote workFlexible hours
- Governance, Risk & Compliance (GRC) Analyst Washington D.C. CHAOS Industries... ...IT, Cybersecurity, Physical Security, and Manufacturing - teams... ...controls people adopt. Build and manage cybersecurity risk processes,... ...Components: Competitive base salaries, generous pre-IPO stock...Contract workFor subcontractorCasual workRelocation package
- ...accommodation or an alternative application process. Compliance Manager Full Time Managers, All Other San Antonio, TX, US Experience The EMBREY Way by joining our dynamic... ...compliance policies, procedures, and standards based on business and contractual requirements....Full timeContract workTemporary workFor subcontractorWork at office
- Home / Jobs / Compliance & Sustainability Intelligence... Compliance & Sustainability Intelligence Manager (EPR) Remote Full-time EHS & Compliance... ...accelerating. Producers count on us to help them navigate this... .... We do not discriminate based on race, color, religion,...Full timeContract workLive inWork at officeRemote workWorldwideFlexible hoursShift work3 days per week
- ...high bar for itself - keep reading. Compliance Operations Manager ABOUT THE ROLE The line between compliance... ...across Socure's growing customer base. Work with Sales and Customer Success... ...and quality control. Familiarity with GRC frameworks and AML taxonomy structures...
$212.4k
...opportunity The Global Lead Security Compliance & Enforcement owns the... ...business-as-usual GRC operations and talent... ...measurable outcomes, managing a portfolio of... ...conversion of published US salary ranges. At EY,... ...where you’ll be rewarded based on your performance and...Summer holidayLocal areaFlexible hours$212.4k
...Location: Hoboken, NJ, US, 07030Salary: $212,400... ...Global Lead Security Compliance & Enforcement owns the... ...sustaining business-as-usual GRC operations and talent... ...measurable outcomes, managing a portfolio of concurrent... ...where you’ll be rewarded based on your performance...Summer holidayLocal areaFlexible hours- ...Leading the Way in Water Management Inframark's Operations... ...your career and join us at Inframark. Apply today... ..., and wellness plan. Compliance Manager The Environmental... ...To support a safe and secure workplace, all offers... ...discriminated against based on disability. #J-1880...Work at officeLocal areaRemote work
- ...modern franchised dealerships in eleven US markets, including Houston, TX, Rancho Mirage... ...Auto Group is seeking a full-time Compliance Manager to join our indiGO Auto Group Corporate... ...Conduct internal audits and assessments based on priority areas identified by leadership...Full timeLocal areaFlexible hours
$78.7k - $138.2k
...1.5 trillion in assets under management, administration and advisement... ...world. Job Description The Compliance Manager will support the day-... ...client-centric, relationship-based business. Working together, in... ...breadth of our capabilities sets us apart. It also creates unique...Full timePart timeWork experience placementH1bWork at officeWork from homeVisa sponsorship1 day per week- ...supervised AI agent that manages chronic diseases. We... ...physicians. We are seeking a Compliance Manager to build and... ...data privacy and security, healthcare fraud and abuse... ...a thoughtful, risk-based approach to compliance,... ...such as CHC, CHPC, CIPP/US, or RAC. JD, MPH, MHA,...Remote work
- Yahoo is seeking a Senior Security GRC Analyst to join The Paranoids Cyber Risk team in a fast... ...security risks, guiding risk-based decisions across Yahoo properties. You will... ...scale governance while maintaining confidentiality and compliance. #J-18808-Ljbffr Yahoo Inc.
$130k - $143k
...journey. Job Overview The Strategic Partner Manager position represents a key role for our... ...enterprise fintech architectures. Why Work With Us? Visionary Team, Proven Results Our... ...this role is eligible for commission; the base pay offered is based on comparable market...Work at officeImmediate startRemote work$50k - $60k
...or an alternative application process. Community-Based Services Manager FullTime Salt Lake City, UT, US 7 days ago Requisition ID: 1317 Salary Range: $50... ...required state submissions Regulatory and program compliance Vehicle oversight Program site standards and cleanliness...Full timeSummer workWork at office$118.13k - $173.25k
...Trade Compliance ManagerThe Trade Compliance Manager will lead a small team compliance analysts... ...our employees. The typical base salary for this position... ...Join ZT Systems and help us build technology infrastructure... ...well-being, financial security, and professional...Permanent employmentWork at officeLocal area$100k - $120k
...the entire supply chain. Join us and be part of a team where your... ...Description Responsible for compliance with U.S. Customs & Border Protection... ...business operations. Program Management: Develop and implement trade... ...automotive, chore products or base metal products with a deep...Full timeLocal areaWorldwideFlexible hours$150.1k - $225.15k
...Strategic Planning & Execution, US Medical Affairsis responsible... ...will apply good project management techniques toinsure inscope,on... ...continuous improvement Liaise with Compliance and Legal to resolve... .... As is typical of an office-based role, employees must be able,...Contract workTemporary workWork at office- EHS Program Compliance Manager Full Time Fort Worth, TX, US 18 days ago Requisition ID: 2283 MP Materials (NYSE: MP) is rebuilding American industrial capability... ...and magnet manufacturing. Develop and maintain risk‑based environmental compliance programs, including air...Permanent employmentFull timeWork at officeLocal area
$150k - $180k
...Native Agentic SOC Platform — unifying a security data lake, the world's largest IOC... ...self-driven Senior Technical Account Manager (TAM) to join the US Customer Success team. The TAM is the... ...,000 USD Please note that the annual base salary range is a guideline and, for...Remote jobLocal areaFlexible hours- ICE Clear Europe Limited is seeking an Analyst, Information Security GRC to join the global Information Security program. The role supports governance, risk, and compliance across the ICE group with exposure to multiple businesses and products. Responsibilities include...
$55 - $80 per hour
IT GRC Analyst Remote, USA Compensation: $55 - $80 per hour... ...IT GRC Analyst to join the IT Security and Governance team on a 6-month... ...'s IT Governance, Risk, and Compliance (GRC) program, focusing on... ...regulatory compliance, risk management, audit readiness, policy administration...Hourly payFull timeContract workWork at officeLocal areaImmediate startRemote workFlexible hours$217.8k - $326.8k
...solutions - to help sellers sell online, manage inventory, offer buy now, pay later functionality... ...is a massive opportunity in front of us. We’re building a significant, meaningful,... ...in payments, fintech, or a consumption-based business model. You've stood up a net-new...For contractorsLocal areaRemote workWorldwideFlexible hours- Lactalis American Group is seeking an Associate Manager, US Compensation in the U.S. market. This role can be based in New York, NY or Chicago, IL. You will shape compensation programs, lead cycles, and partner with HR and Finance to attract, retain, and reward talent....
- Why join us Brex is the intelligent finance platform that enables... ...banking with intuitive spend management, bill pay, and travel... ...you need to grow your career. Compliance at Brex The Compliance team helps... ...’ll work This role will be based in our San Francisco office....Fixed term contractWork at officeRemote workWork from home
- ...has an exciting opportunity for an Export Compliance Manager at our Chandler, AZ location. About... ...leading aerospace & electronics manufacturer based in beautiful, sunny Chandler, Arizona.... ...shoulder‑to‑shoulder with prime OEMs and help us develop state‑of‑the‑art solutions - all...Work at office
$115k - $120k
...headquarters are located) or anywhere in the US, including in any of our US offices listed... ...the same level, starting compensation is based on years of relevant experience. Our... ...efficient as possibleYou have an ability to manage multiple priorities You are experimental...Remote jobTemporary workWork at officeWork from homeVisa sponsorshipFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security & Compliance Manager (GRC), US-based. Be the first to apply!
- corporate security manager Brooklyn, NY
- surveillance manager Brooklyn, NY
- security manager Brooklyn, NY
- program manager with security clearance Brooklyn, NY
- director information security Brooklyn, NY
- director global security Brooklyn, NY
- security systems manager Brooklyn, NY
- security operations manager Brooklyn, NY
- physical security manager Brooklyn, NY
- training and compliance manager Brooklyn, NY

