Security GRC Lead
$180k - $258kCandid Health
About Candid HealthIn simple terms, healthcare in the U.S. has a massive, invisible problem behind the scenes: getting doctors paid by insurance companies is notoriously complicated. Insurance rules are constantly changing, and every bill (or "claim") requires mountains of paperwork. When mistakes happen, bills get rejected, patients end up with unexpected charges, and healthcare providers waste billions of dollars and countless hours on administrative bureaucracy instead of focusing on patient care. That is where Candid Health steps in. Founded by former Palantir leaders who experienced these pain points firsthand, we are building the modern financial backbone for American healthcare. Instead of relying on decades-old legacy software or attempting to patch broken systems with superficial tools, we've rebuilt the underlying infrastructure from the ground up.Our core product is an autonomous Revenue Cycle Management (RCM) platform. Powered by AI agents and a configurable rules engine, the platform unifies clinical, billing, and insurance data into a single smart system. It acts like an intelligent, automated back-office that handles complex medical claims from start to finish—submitting them accurately on the first pass, cutting down administrative costs, and dramatically increasing cash flow for healthcare providers.Today, we are trusted by over 200 fast-growing healthcare organizations—from digital health innovators to large enterprise medical groups—processing billions in claims annually. Backed by top investors like Sixth Street Growth, Oak HC/FT, 8VC, and Y Combinator, Candid Health recently raised a $120 million Series D to fuel the AI-driven transformation of healthcare payments and eliminate administrative friction for good.Role OverviewWe are seeking a Security GRC Lead to build our first in-house GRC program from the ground up. In this role, you won't just write policies or collect manual screenshots in spreadsheets; you will treat compliance as an engineering and data problem.You will build automated evidence pipelines, implement compliance-as-code, and establish continuous controls monitoring across our GCP infrastructure, identity systems, and CI/CD pipelines. You will turn point-in-time audits into a continuous compliance telemetry system that keeps our platform secure, resilient, and audit-ready at all times.Key Responsibilities1) Compliance Automation & EngineeringDevelop automated scripts and API integrations to collect compliance evidence directly from system sources instead of collecting manual screenshots.Write and deploy infrastructure-as-code and policy enforcement rules to enforce security baselines automatically.Maintain live compliance dashboards and alerts that flag configuration drift or policy violations in real time.Partnering with Legal on Medicare and Medicaid compliancePartnering closely with legal and finance teams on future due diligence and compliance projects2) Framework Mapping & Control ArchitectureConvert regulatory, security, and industry standards (SOC 2, HiTrust, PCI, HIPAA) into clear, testable technical controls.Map single technical controls across multiple overlapping frameworks to eliminate redundant work.Work alongside DevOps and Software Engineering teams to build compliance controls directly into CI/CD pipelines without slowing down delivery.3) Risk Management & AuditsLead technical audit readiness and external audit engagements using programmatic evidence pipelines.Automate vendor risk management workflows and API-driven vendor evaluations.Build continuous risk tracking tools fed by live vulnerability telemetry and identity logs rather than static quarterly surveys.Required Qualifications3+ years in a technical security role, such as Security Engineering, Cloud Security, or Technical GRC.Proficiency in Python, TypeScript, SQL and hands on experience interacting with APIs, parsing logs, and querying databases.Hands-on experience with at least one primary cloud platform, GCP Preferred and Infrastructure-as-Code tools such as TerraformDeep familiarity with core frameworks such as SOC 1/2, PCI, NIST, and/or HITRUST.Understanding of CI/CD pipelines, Git workflows, and container environments (Docker/Kubernetes).Preferred QualificationsCertifications such as CISSP, CISA, CRISC, AWS Certified Security – Specialty, or CCSP.Experience with Policy-as-Code enginesHITRUST experienceBackground in software development, DevOps, or platform engineering.Experience with modern continuous compliance platforms (e.g., Vanta, Drata, Anecdotes).Our valuesWe spend at least as much time with our coworkers as we do with our closest friends + family - if we intend to do the most important + challenging work of our lives, it’s important that these folks energize us, support us, inspire us, and push us to do our best work. This is what you can expect of your teammates at Candid (in no particular order):We put our customers firstWe take care of each other and ourselvesWe anchor on outcomes and work relentlessly and creatively to achieve themWe collectively prioritize building a diverse and inclusive workspaceWe believe humility is our greatest strengthWe are candid, kind, and committedWe strive to be the most prepared person in the roomWe are truth seekersPay TransparencyThe estimated starting annual salary range for this position is $180,000 - 258,000 USD. The listed range is a guideline fromPave data, and the actual base salary may be modified based on factors including job-related skills, experience/qualifications, interview performance, market data, etc. Total compensation for this position may also include equity, sales incentives (for sales roles), and employee benefits. Given Candid Health’s funding and size, we heavily value the potential upside from equity in our compensation package. Further note that Candid Health has minimal hierarchy and titles, but has broad ranges of experience represented within roles.LocationSan Francisco; Denver; New York CityEmployment TypeFull timeLocation TypeHybridDepartmentEngineering
$172.5k - $215.63k
...by seamlessly integrating cutting-edge technology, compassionate service, and world-class user experience design.As our Lead Security Analyst - GRC, you’ll lead initiatives that address the company’s—and some of our industry’s—most sophisticated and meaningful security...SuggestedHourly payWork at officeFlexible hours2 days per week- ...operators in the valley. The Opportunity We’re hiring a Security Lead to build and own the security function at Petual. You’ll inherit... ...securing enterprise SaaS handling sensitive data, ideally in fintech, GRC, or another regulated space Experience with AWS, Kubernetes...Suggested
- ...OpenAI seeks a Program Manager to build and own cross-functional programs spanning Security, IT, and GRC, with a core focus on Mergers & Acquisitions. You’ll drive diligence, Day 1 readiness, onboarding, and post-close integration across multiple teams, applying AI/automation...SuggestedRemote job
$297k - $362k
...products that help builders move from idea to production with speed, security, and exceptional developer experience.Now, software is entering... ..., co-sell structures, or joint product initiativesComfortable leading cross-functional teams you do not manage across Product,...SuggestedWork at officeWork from homeWorldwideMonday to FridayFlexible hours$115k - $156k
...The IT team owns the systems that keep the company running and secure: identity, devices, email, conference rooms, and the SaaS stack.... ...and asset inventoryAbout You5+ years in IT, with at least 2 as a lead or sole admin at a SaaS or similar technology company with a hybrid...SuggestedFull timeTemporary workPart timeWork at officeRemote workFlexible hours$148k - $185k
...products that help builders move from idea to production with speed, security, and exceptional developer experience.Now, software is entering... ...comes next.About the RoleVercel is seeking a Startup Program Lead to build, lead, and scale our global startup program and startup...Work from homeWorldwideFlexible hours$180k - $220k
...need for experimentation, training, and production inference, with security, observability, and control built in. We serve solo... ...conversations help us move faster together. Build Great Teams: We lead by example, empower others, and create healthy teams where people...Temporary workWork at officeWork from homeFlexible hours2 days per week- ...products that help builders move from idea to production with speed, security, and exceptional developer experience. Now, software is... ...About the role Vercel is hiring a Strategic Partnerships Lead to develop first-of-a-kind partnerships that inflect the company...Work from homeWorldwideFlexible hours3 days per week
$172.5k - $313.7k
...the heart of it all.Ready to level-up your career at the company leading workforce transformation in the agentic era? You’re in the... ...future of AI, and you are the future of Salesforce.The MeshMesh Security Engineer safeguards the platform and its customers by building...Full time$114.1k - $268.18k
...development opportunities, a world-class training facility, and leading market tools, we help our people continue to grow both... ...in Advisory.KPMG is currently seeking a Lead Specialist, Cloud Security to join our Managed Services practice.Responsibilities:Manage cloud...H1bLocal area- Lead OfficerWe help make your world a safer place.Securitas is a global company that offers the most advanced and sustainable security solutions in the industry. We are located in 47 countries and have 355,000 employees worldwide and over 150,000 clients.Securitas plays...Weekly payWorldwideFlexible hoursShift work
$140k - $185k
Circle (NYSE: CRCL) is one of the world’s leading internet financial platform companies, building the foundation of a more open, global... ...stakeholder.What you’ll be responsible forAs Lead, Third Party Security, you will be a key member of Circle’s Security team,...Flexible hours- .../2026) Location: Americas Hi there! I’m Jaime , and I lead global recruiting for Zapier’s technical and product-building teams... ...including Applied AI, Software Engineering, Infrastructure, and Security. Strategic operational and systems thinking. You have strong...Full timeImmediate startRemote workFlexible hours
$43.67 - $44.97 per hour
...Lead Transportation Security OfficerPosition at VMD Corp Join VMD Corp (VMD), an Xcelerate Solutions company, a recognized leader in transportation security since 2002, providing advanced screening solutions that leverage the latest technology to protect travelers and...Contract workRemote workRelocationShift work$155k - $175k
...trace illicit activity, build cases, and construct operating pictures of threat networks. Leading agencies and businesses worldwide rely on TRM to make the world safer and more secure. TRM Labs is on a mission to build a safer world by fighting crime and protecting the...Work at officeLocal areaWorldwide$25 - $50 per hour
...Role Overview TSA is accepting applications for Lead and Supervisory Transportation Security Officers at airports in Daly City. These roles are ideal for individuals looking to step into leadership positions within airport security operations. TSA provides training...Shift workNight shiftWeekend work- ...At Vector Security We Think Big, Do the Right Thing, and Make a Difference Every Day! If this is how you like to work, we’d like to invite you to join our team as a Lead Systems Technician! We offer great benefits, a competitive salary, and growth opportunities. We think...Temporary workLocal area
$117.2k - $260.1k
...the heart of it all.Ready to level-up your career at the company leading workforce transformation in the agentic era? You’re in the... ...Salesforce.Location: NY, Bellevue, SFThe ExperienceOur Enterprise Security organization is looking for Security Partner professionals spanning...Full timeRemote work- ...popular DJ music venue on the weekends, all while retaining a welcoming living room atmosphere. Responsibilities: To lead the security team on a nightly basis To assist management in scheduling needs for the security department To understand and respond...Immediate startShift workNight shiftWeekend workAfternoon shift
$175k - $270k
...products that help builders move from idea to production with speed, security, and exceptional developer experience. Now, software is entering... ...Accelerate, AWS Marketplace, and other funding initiatives. Lead strategic account mapping sessions, executive business reviews,...Work at officeWork from homeWorldwideMonday to FridayFlexible hours- ...Turo is seeking a Manager, Information Security in San Francisco to lead a team of Security Engineers and advance Zero Trust across the organization. You will guide Advanced Email Security, DLP, Insider Threat, Endpoint Security, and IAM governance while ensuring SOX/SOC...Work at office
- ...Amazon Web Services, Inc. in San Francisco seeks a Head of Product Marketing for AWS Security & Identity to set the category narrative and lead a high-growth product marketing team. You will own the overall marketing strategy for the portfolio, including positioning...
- ...Serval is seeking a Detection and Response Lead to scale our cybersecurity operations and embed secure by design practices across our platform. You will set strategy, build a high-performing team, and partner with Engineering and Product to ensure proactive detection and...
- ...Channel Account Manager to accelerate its channel strategy in the NorCal/Northwest region. You will cultivate relationships with security VARs, GSIs, Google Marketplace partners, and technical alliances to drive revenue and extend Doppel's market presence. Collaborate...Remote jobFlexible hours
- ...America. We're building that for AI. AIUC-1, our standard for agent security, serves frontier builders like Cursor, Lovable, ElevenLabs, and... ..., and OpenAI. Come join us. The Role AIUC is growing into the leading voice on enterprise AI trust: ~250 F1000 CISOs in our...RelocationVisa sponsorship
- ...Lead Fire Alarm Technician Commercial Fire Protection is seeking experienced Lead Fire Alarm Technician. There's never been a more exciting time to join our team! We are in an accelerated growth phase in a rapidly expanding industry and are seeking motivated, self-...Hourly payFlexible hours
$172.5k - $285.8k
...Join Salesforce as a Security Engineer (Senior/Lead) in San Francisco, CA (onsite) , helping protect the platform and customers by embedding security across infrastructure and application code . You will contribute to how new capabilities are designed, validated,...- ...manage tasks related to user, database, and profile setup. The ideal candidate should have experience in security management, performance monitoring, and the ability to lead in application sectors. This full-time position with a major client offers a chance to engage in...Full time
- ...Postman’s security team seeks a Principal Offensive Security Engineer to shape the future of defensive AI testing and adversarial evaluation... ...leadership on threat-informed defense strategy. You will lead a team of AI red team engineers, drive continuous validation across...
- ...to provide strategic leadership across cybersecurity, risk and governance. You will guide security strategy, oversee architecture and risk decisions, and advance a comprehensive GRC program across our data centers and cloud solutions. You’ll coordinate with IT, Legal,...Remote job
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security GRC Lead. Be the first to apply!





