Source Job

US Unlimited PTO

  • Serve as Compliance Officer and HIPAA Security Officer, leading compliance and information security programs.
  • Own HIPAA/HITECH compliance, SOC 2 Type II certifications, and policy framework governance.
  • Partner with Engineering, DevOps, Legal, and other functions to embed security and compliance into operations.

Security Compliance HIPAA Risk Management SOC 2

20 jobs similar to Senior Director, Security & Compliance

Jobs ranked by similarity.

$160,000–$180,000/yr
US

  • Own and operationalize Avandra's compliance roadmap across HIPAA, HITRUST, and SOC 2, driving certifications and risk management.
  • Coordinate audit evidence, vendor security assessments, and customer due diligence while keeping audit-ready documentation.
  • Lead M&A compliance integration, including gap analyses and remediation plans for acquired entities.

Avandra Imaging is building the largest indexed data cloud of medical imaging to unlock clinical data for healthcare research. With over 5,000 customer integrations and roughly 70% market share, it is a growth-stage startup with a values-driven culture.

Canada

  • Lead and mature Fullscript's security compliance program across SOC 2, PCI DSS, and HITRUST frameworks.
  • Manage internal and external audits, coordinate remediation efforts, and maintain continuous audit-readiness.
  • Partner cross-functionally with Security, Engineering, Privacy, Legal, and Product to translate compliance requirements into scalable practices.

Fullscript is a health technology company that powers every part of care by providing practitioners with clinical insights, lab interpretations, and high-quality supplements. With over 125,000 practitioners and 10 million patients, they foster a culture of curiosity, collaboration, and putting people first.

$6,000–$7,500/mo
US

  • Build and maintain technical controls across security and compliance frameworks such as SOC 2, ISO 27001, HIPAA, and other enterprise requirements.
  • Automate compliance workflows, evidence collection, access reviews, and security checks.
  • Partner with Engineering and Security to implement controls around access management, infrastructure, data protection, logging, and vulnerability management.

Retell AI is reimagining the call center with cutting-edge voice AI. Backed by Y Combinator, the company has scaled to $60M ARR with a team of 40 people, and is looking for ambitious builders to tackle hard technical problems.

Global Unlimited PTO

  • Lead complex healthcare and life sciences engagements by orchestrating end-to-end declarative technical delivery across Salesforce clouds.
  • Direct AI tools to generate automation logic and ensure HIPAA compliance, translating technical concepts for non-technical stakeholders.
  • Mentor junior consultants and champion knowledge sharing to drive continuous improvement across the practice.

Penrod is a consulting firm that drives innovation and client success through Salesforce solutions, particularly in healthcare and life sciences. The company fosters a high-octane, driven culture where team members are empowered to take ownership and accelerate their careers.

$175,000–$210,000/yr
Global Unlimited PTO

  • Own the compliance programs and audits end to end, including SOC 2, PCI DSS, GDPR, and ISO 27001.
  • Manage identity and access, device fleet, and vendor security with ownership over control state.
  • Drive compliance as a sales enabler and own the customer-facing security package.

Footprint is the agentic platform that learns compliance programs and runs them end to end for banks and fintechs. The team is small, senior, and ships fast.

US

  • Own the information-security risk register, risk appetite model, and exception processes, and deliver monthly executive risk reporting.
  • Operate the AI governance program, cross-functional incident management, and data security governance initiatives such as data segregation.
  • Represent Modern Health's risk posture to strategic clients, auditors, and assessors, providing second-line risk calibration and escalation support.

Modern Health is a mental health benefits platform for employers, offering a global solution for employees' emotional, professional, social, financial, and physical well-being needs. The company is a fully remote, hyper-growth organization that has raised over $170 million and achieved unicorn status, with a culture of high empathy and high accountability.

$112,000–$140,000/yr
US

  • Ensure day-to-day compliance activities across PCI DSS, SOC 2, NIST, GDPR, and ISO frameworks.
  • Lead preparation and execution of internal and external audits, including evidence collection and remediation tracking.
  • Perform technical security and compliance reviews of third-party vendors and service providers.

iSeatz drives enduring brand loyalty through digital commerce and technology solutions for travel and lifestyle bookings. The company processes over $9B per year in transactions and has been honored as an Inc. Magazine Best Workplace for three consecutive years, emphasizing transparency, trust, and open communication.

$135,000–$145,000/yr
Global

  • Own the IT evidence program across ISO 27001, SOC 1, SOC 2, PCI DSS, and HIPAA for approximately 13 operating sites, managing audits and remediation.
  • Manage vulnerability management end to end, oversee endpoint detection and response, and lead security incident response through to conclusion.
  • Contribute to identity governance across a hybrid cloud and on-premises IdP, overseeing access review and privileged access controls.

Serverfarm is a leading developer and operator of data centers with over 750 locations and key customer relationships in 45 countries. With Manulife Investment Management's acquisition in 2023, the company is positioned for explosive growth and offers a culture of innovation and career development.

$71,739–$129,644/yr
US Unlimited PTO

  • Manage third-party and FDR oversight, including due diligence, risk tiering, and ongoing monitoring.
  • Lead privacy and security incident response, including breach risk assessment and reporting.
  • Administer compliance program, including drafting policies, presenting training, and conducting internal audits.

Evermore is a technology company that administers Smart Benefits to connect people to products and services they need. It is a Series B stage company backed by leading investors, fostering a culture of innovation and health equity.

$100,000–$135,000/yr
US 4w PTO

  • Collaborate closely with the Senior Security Engineer to scope, design, and implement security initiatives across cloud, endpoint, identity, and application security.
  • Administer and tune core security platforms including endpoint detection, email security, and vulnerability management.
  • Respond to security incidents and ensure compliance with HITRUST, HIPAA, and other industry standards.

Imagine Pediatrics is a tech-enabled, pediatrician-led medical group reimagining care for children with special health care needs by delivering 24/7 virtual-first and in-home medical, behavioral, and social care. They operate as a small, collaborative team that values curiosity and an unwavering commitment to children with medical complexity.

$120,000–$220,000/yr
Global Unlimited PTO 22w maternity 16w paternity

  • Own and build Flodesk's security program end to end, including policies, controls, and governance.
  • Lead SOC 2, ISO 27001, and CCPA readiness while partnering with engineering on secure development.
  • Manage IT operations, vendor vetting, and security tooling to scale the program.

Flodesk is a fast-growing email marketing company that helps creators and small businesses design emails and monetize their email lists. It is a remote-first company with a globally distributed team and offices in San Francisco, Menlo Park, and Da Nang.

Global

  • Manage the Compliance and Security workstream, coordinating SOC 2, ISO 27001, GDPR, and related audit-readiness activities.
  • Build and maintain execution plans with clear owners, milestones, dependencies, risks, and decision points.
  • Facilitate workshops, track evidence, and escalate risks to keep audits on schedule.

Miratech is a global IT services and consulting company that helps visionaries change the world through digital transformation. With nearly 1000 full-time professionals across 25+ countries, the company maintains a culture of Relentless Performance and has achieved over 99% project success since 1989.

US 4w PTO 12w maternity 12w paternity

  • Lead the development, implementation, and ongoing maintenance of comprehensive security strategies and solutions.
  • Design and deploy advanced security controls to protect the business across disciplines.
  • Mentor and galvanize engineers to uphold security process standards.

Aledade PBC empowers independent primary care practices, helping them deliver better care and thrive in value-based care. Founded in 2014, Aledade has become the largest network of independent primary care in the US, with a collaborative, remote-first culture.

US

  • Own the compliance strategy and risk assessment for the business, including regulatory, corporate, and clinical compliance.
  • Build government programs compliance capability, including Medicare marketing and member communication requirements.
  • Partner with clinical, product, operations, data, and payer teams to embed compliance into new workflows, AI tools, and market expansions.

Chamber is rebuilding the system for cardiology by partnering with independent cardiologists to improve outcomes through technology, data, and operational tools. As an early-stage company, they value low ego, empathy, courage, ownership, and grit, fostering a culture of innovation and human-centered care.

US

  • Lead cross-functional regulatory compliance initiatives across globally distributed teams.
  • Translate compliance priorities into technical requirements and executable programs.
  • Establish portfolio management frameworks and governance practices.

The company is a global organization that manages regulatory compliance, technology strategy, and product innovation across multiple functions. It has a large, globally distributed workforce and fosters a culture of collaboration, innovation, and continuous learning.

$150,000–$200,000/yr
US

  • Lead control implementation and audit readiness across multiple compliance frameworks including FedRAMP, SOC 2, ISO 27001, and TISAX.
  • Partner with engineering, product, and security teams to translate compliance requirements into practical controls.
  • Represent the compliance program in customer-facing discussions and security due diligence reviews.

Rescale is pioneering the future of engineering and scientific discovery through intelligent automation, applied AI, and data management. We are a diverse, collaborative, and mission-driven team that unlocks innovation across aerospace, energy, life sciences, and manufacturing industries.

$100,000–$120,000/yr
US

  • Manage day-to-day privacy compliance program operations, including policies, procedures, records, documentation, and supporting processes.
  • Conduct and coordinate Privacy Impact Assessments (PIAs/DPIAs) and data protection assessments for new products, features, vendors, and business initiatives.
  • Support data subject rights requests and privacy incident response processes.

This company operates in the health technology space, focusing on privacy and compliance. It is a fast-growing, remote-first organization with a collaborative culture emphasizing transparency, empowerment, and evidence-based decisions.

$150,000–$180,000/yr
US

  • Serve as acting CISO for multiple client organizations and SGP, providing strategic security leadership and executive guidance.
  • Lead cybersecurity and compliance programs aligned with NIST SP 800-171, CMMC Levels 1-2, and ISO/IEC 27001.
  • Conduct security assessments, gap analyses, and risk reviews; develop SSPs, POA&Ms, and policies.

Strategic Growth Partners provides cybersecurity and compliance services to clients across multiple time zones. They foster a collaborative, innovative, and diverse work environment.

US

  • Lead security and IT for Cardlytics, overseeing security engineering, IT operations, and compliance for a fully remote team.
  • Manage SOX/SOC 2 compliance, identity and access management, and cloud security across AWS environment.
  • Drive AI adoption company-wide while partnering with executives and the board to align security priorities with business strategy.

Cardlytics is a purchase intelligence and incentives platform that helps businesses attract and incentivize consumers through digital reward programs. As a public company (NASDAQ: CDLX) with a lean, high-trust team, they prioritize integrity and growth.

US

  • Own the security program end-to-end, including identity, IT, compliance, and application security.
  • Drive SOC 2 Type II readiness and map FERPA, COPPA, and state privacy controls.
  • Establish zero-trust access, automated provisioning, and human-centered security processes.

OpenEd provides customized, world-class education and resources to over 100,000 students, empowering families across the US. The company is growing rapidly with a values-driven culture focused on customer obsession, action, and transparency, reflected in a top 0.1% employee net promoter score.