Source Job

$160,000–$180,000/yr
US

  • Own and operationalize Avandra's compliance roadmap across HIPAA, HITRUST, and SOC 2, driving certifications and risk management.
  • Coordinate audit evidence, vendor security assessments, and customer due diligence while keeping audit-ready documentation.
  • Lead M&A compliance integration, including gap analyses and remediation plans for acquired entities.

Compliance HIPAA HITRUST SOC 2 Vendor Risk Management

20 jobs similar to Compliance Lead

Jobs ranked by similarity.

$175,000–$210,000/yr
Global Unlimited PTO

  • Own the compliance programs and audits end to end, including SOC 2, PCI DSS, GDPR, and ISO 27001.
  • Manage identity and access, device fleet, and vendor security with ownership over control state.
  • Drive compliance as a sales enabler and own the customer-facing security package.

Footprint is the agentic platform that learns compliance programs and runs them end to end for banks and fintechs. The team is small, senior, and ships fast.

Canada

  • Lead and mature Fullscript's security compliance program across SOC 2, PCI DSS, and HITRUST frameworks.
  • Manage internal and external audits, coordinate remediation efforts, and maintain continuous audit-readiness.
  • Partner cross-functionally with Security, Engineering, Privacy, Legal, and Product to translate compliance requirements into scalable practices.

Fullscript is a health technology company that powers every part of care by providing practitioners with clinical insights, lab interpretations, and high-quality supplements. With over 125,000 practitioners and 10 million patients, they foster a culture of curiosity, collaboration, and putting people first.

$176,400–$196,000/yr
US

  • Set the strategic direction for Compliance Operations, transforming regulatory requirements into scalable practices that enable growth.
  • Partner with Product and Engineering to build tech-first, automated solutions that reduce manual effort and scale operations.
  • Lead state licensing audits, develop key compliance metrics, and build a high-performing team of 5-10 professionals.

Honor Technology is changing how society cares for older adults by providing technology, tools, and services that empower them to live life on their own terms. With over 100,000 Care Pros and a global franchise network, the company delivers over 50 million hours of personalized care annually, fostering a culture of innovation and compassion.

US

  • Own the compliance strategy and risk assessment for the business, including regulatory, corporate, and clinical compliance.
  • Build government programs compliance capability, including Medicare marketing and member communication requirements.
  • Partner with clinical, product, operations, data, and payer teams to embed compliance into new workflows, AI tools, and market expansions.

Chamber is rebuilding the system for cardiology by partnering with independent cardiologists to improve outcomes through technology, data, and operational tools. As an early-stage company, they value low ego, empathy, courage, ownership, and grit, fostering a culture of innovation and human-centered care.

US

  • Initiate and manage compliance onboarding for healthcare contractors, including credentialing verification.
  • Collaborate with staffing agencies and internal stakeholders to meet compliance deadlines.
  • Monitor credential expirations and maintain accurate records in the Vendor Management System.

Trio Workforce Solutions helps healthcare organizations manage workforce challenges through technology and services. The company is a mission-driven organization with a collaborative culture and growth opportunities nationwide.

US

  • Monitor operational activities for compliance with healthcare policies and established procedures
  • Support compliance reviews of billing, coding, claims, and documentation processes
  • Assist with internal audits, compliance assessments, and corrective action plans

Raventra Health is a medical services company providing outsourced billing, coding, and claims processing solutions for provider groups and hospitals. The company's size and culture are not specified in the posting.

$71,739–$129,644/yr
US Unlimited PTO

  • Manage third-party and FDR oversight, including due diligence, risk tiering, and ongoing monitoring.
  • Lead privacy and security incident response, including breach risk assessment and reporting.
  • Administer compliance program, including drafting policies, presenting training, and conducting internal audits.

Evermore is a technology company that administers Smart Benefits to connect people to products and services they need. It is a Series B stage company backed by leading investors, fostering a culture of innovation and health equity.

US

  • Influence entire compliance programs by translating strategic priorities into clear visions and executable programs with measurable outcomes.
  • Establish portfolio management frameworks and serve as the primary point of contact for executive leadership on mission-critical compliance programs.
  • Drive cross-functional delivery of regulatory compliance programs and improve audit processes for R&D.

Twilio is a leading communications platform that delivers innovative solutions to hundreds of thousands of businesses and empowers millions of developers worldwide. They are a remote-first company with a strong culture of connection and global inclusion.

US Unlimited PTO

  • Manage partner certifications and compliance across Microsoft, AWS, and Google Cloud programs.
  • Coordinate audits, evidence readiness, and certification tracking to maintain vendor designations.
  • Collaborate with practice leaders and cross-functional teams to align partner ecosystem strategies.

Myriad360 is a technology solutions provider that helps organizations implement and manage cloud and infrastructure solutions across leading platforms like Microsoft, AWS, and Google Cloud. The company is consistently recognized as a best place to work, fostering an inclusive, transparent culture with a strong focus on employee development and high-performing teams.

US

  • Manage governance forums, agendas, decision logs, and action tracking.
  • Support execution of strategic compliance priorities and monitor cross-functional dependencies.
  • Coordinate departmental KPIs and executive dashboarding.

HealthEdge is a healthcare technology company that provides software solutions for health plans and payers. The company fosters a culture of accountability, transparency, and compliance, operating remotely across the US.

$114,800–$173,250/yr
US

  • Own assigned federal security and compliance workstreams from requirement interpretation through implementation, evidence collection, and remediation.
  • Drive recurring continuous monitoring and evidence workflows across multiple teams.
  • Support vulnerability detection and response, including reconciling findings from tools like Wiz, Nessus, and Burp.

Abnormal protects the humans behind the world's most critical organizations from AI-powered cybercrime. 4,500+ enterprises trust their behavioral AI platform.

US

  • Serve as primary escalation point for compliance representatives, researching and resolving escalated matters.
  • Develop and maintain compliance SOPs, training materials, and provide ongoing coaching to team members.
  • Assist with compliance reporting, monitoring, and ensure policies are followed consistently.

PeopleFinders.com is an online service for locating, contacting, and verifying people and businesses. Over the past couple of decades, it has become one of the largest owners of public records data in the country.

US

  • Lead security and IT for Cardlytics, overseeing security engineering, IT operations, and compliance for a fully remote team.
  • Manage SOX/SOC 2 compliance, identity and access management, and cloud security across AWS environment.
  • Drive AI adoption company-wide while partnering with executives and the board to align security priorities with business strategy.

Cardlytics is a purchase intelligence and incentives platform that helps businesses attract and incentivize consumers through digital reward programs. As a public company (NASDAQ: CDLX) with a lean, high-trust team, they prioritize integrity and growth.

India Unlimited PTO

  • Own the audit journey for a portfolio of global customers from gap assessment through external audit closure.
  • Identify security and compliance gaps, turning them into practical remediation plans with engineering and leadership teams.
  • Serve as the coordination point between customers and independent auditors, facilitating evidence requests and communication.

Sprinto is an autonomous trust platform that centralizes compliance and security requirements across frameworks, vendors, and customers. Backed by Accel and Elevation, with $31.8M in funding, Sprinto serves over 4,000 organizations and fosters a remote-first culture of ownership and impact.

$200,000–$240,000/yr
US Canada Unlimited PTO 12w maternity 12w paternity

  • Build and run Gauntlet's compliance program, including policies, monitoring, and governance.
  • Support regulatory registrations, examinations, and audits.
  • Partner with cross-functional teams to embed compliance and use AI for efficiency.

Gauntlet builds financial systems for on-chain finance, serving over $1.6B in client TVL. They are a Series C company with a team blending traditional finance and crypto expertise, offering a hands-on, ownership-driven culture.

Global

  • Own the IT evidence program across ISO 27001, SOC 1, SOC 2, PCI DSS, and HIPAA for approximately 13 operating sites, managing audits and remediation.
  • Manage vulnerability management end to end, oversee endpoint detection and response, and lead security incident response through to conclusion.
  • Contribute to identity governance across a hybrid cloud and on-premises IdP, overseeing access review and privileged access controls.

Serverfarm is a leading developer and operator of data centers with over 750 locations and key customer relationships in 45 countries. With Manulife Investment Management's acquisition in 2023, the company is positioned for explosive growth and offers a culture of innovation and career development.

$6,000–$7,500/mo
US

  • Build and maintain technical controls across security and compliance frameworks such as SOC 2, ISO 27001, HIPAA, and other enterprise requirements.
  • Automate compliance workflows, evidence collection, access reviews, and security checks.
  • Partner with Engineering and Security to implement controls around access management, infrastructure, data protection, logging, and vulnerability management.

Retell AI is reimagining the call center with cutting-edge voice AI. Backed by Y Combinator, the company has scaled to $60M ARR with a team of 40 people, and is looking for ambitious builders to tackle hard technical problems.

$105,000–$145,000/yr
United States Unlimited PTO

  • Serve as the go-to compliance resource for HSA, FSA, and HRA products, ensuring compliance with regulatory requirements.
  • Lead compliance risk assessments for new product features and platform developments, including AI-powered tools.
  • Monitor regulatory developments and produce actionable impact assessments for affected teams.

Lively set out to raise the bar on benefit solutions, offering a modern HSA and a full suite of benefits. It is a remote-first company with employees across the US, focused on user-centric design and innovation.

$150,000–$200,000/yr
US

  • Lead control implementation and audit readiness across multiple compliance frameworks including FedRAMP, SOC 2, ISO 27001, and TISAX.
  • Partner with engineering, product, and security teams to translate compliance requirements into practical controls.
  • Represent the compliance program in customer-facing discussions and security due diligence reviews.

Rescale is pioneering the future of engineering and scientific discovery through intelligent automation, applied AI, and data management. We are a diverse, collaborative, and mission-driven team that unlocks innovation across aerospace, energy, life sciences, and manufacturing industries.

US

  • Assess and mitigate privacy risks across enterprise operations and third-party relationships, including PIAs and DPAs.
  • Support responsible AI governance by conducting AI risk assessments and monitoring emerging regulations.
  • Collaborate with Legal, Security, IT, and business stakeholders to ensure compliance with global privacy laws like HIPAA and GDPR.

Accuray develops, manufactures, and sells radiotherapy systems for alternative cancer treatments. With a global presence, they foster an inclusive and collaborative work environment focused on patient-first outcomes.