Source Job

$130,000–$150,000/yr
US

  • Own and mature security, privacy, and compliance programs across HIPAA, SOC 2, and HITRUST.
  • Lead HITRUST certification end to end, including scoping, evidence collection, and assessor coordination.
  • Partner with Engineering, Product, SRE, and IT to integrate security into architecture, SDLC, and cloud infrastructure.

HIPAA HITRUST SOC 2 Risk Management Cloud Security

20 jobs similar to Manager, Security & Compliance

Jobs ranked by similarity.

US Unlimited PTO

  • Serve as Compliance Officer and HIPAA Security Officer, leading compliance and information security programs.
  • Own HIPAA/HITECH compliance, SOC 2 Type II certifications, and policy framework governance.
  • Partner with Engineering, DevOps, Legal, and other functions to embed security and compliance into operations.

Prompt delivers highly automated modern software to rehab therapy businesses, revolutionizing healthcare technology. As one of the fastest-growing healthcare SaaS companies, it fosters an innovative, remote-friendly culture with a talented team.

$160,000–$180,000/yr
US

  • Lead and mature cybersecurity compliance programs including SOC 2 Type 2 and ISO 27001 readiness.
  • Drive cloud and application security across AWS and Azure, integrating secure SDLC and DevSecOps practices.
  • Manage corporate IT operations, identity and access, and build the cybersecurity team as the organization grows.

Genea is a leader in property technology, providing cloud-based physical security, submeter billing, and on-demand HVAC solutions to over 1 million users across 39 countries. It has been recognized as a Top Workplace from 2021-2025 with a 4.3 Glassdoor rating, fostering a team-oriented and transparent culture.

Global 4w PTO

  • Act as part vCISO and account manager, guiding clients through security and compliance programs.
  • Assess security posture, provide recommendations, and design programs using NIST, SOC 2, and ISO 27001.
  • Liaise with auditors and internal teams to translate programs into policies, procedures, and configurations.

Oneleet provides a platform for companies to build, manage, and monitor cybersecurity programs and achieve SOC 2 and ISO 27001. It raised a $33M Series A and is a fast-growing, remote-first team with an opinionated culture.

$104,000–$140,000/yr
US

  • Develops and maintains information security policies, procedures, and controls ensuring compliance with HITRUST, SOC 2, HIPAA, and other frameworks.
  • Leads audit readiness and execution, managing HITRUST and SOC 2 Type II examinations from planning through report issuance.
  • Drives continuous improvement of security processes, risk management, and incident response across the organization.

MRO specializes in information security assurance and regulatory compliance, helping organizations manage risk and maintain audit readiness. The company fosters a security-focused culture with a team of experienced professionals.

$160,000–$180,000/yr
US

  • Own and operationalize Avandra's compliance roadmap across HIPAA, HITRUST, and SOC 2, driving certifications and risk management.
  • Coordinate audit evidence, vendor security assessments, and customer due diligence while keeping audit-ready documentation.
  • Lead M&A compliance integration, including gap analyses and remediation plans for acquired entities.

Avandra Imaging is building the largest indexed data cloud of medical imaging to unlock clinical data for healthcare research. With over 5,000 customer integrations and roughly 70% market share, it is a growth-stage startup with a values-driven culture.

India

  • Maintain and enhance Anovia's ISO/IEC 27001 ISMS, including policies, controls, risks, and audit coordination.
  • Support SOC 2, HIPAA, and other compliance programs, including vendor assessments, vulnerability management, and incident response.
  • Lead ambiguous technical and operational initiatives from planning through implementation, coordinating stakeholders and driving completion.

Anovia is an industry-leading technology outsourcing support provider specializing in workflow and knowledge processes, technical support, helpdesk, and multilingual services. With over 200 experts globally, we serve Fortune 500 companies and value growth, learning, and work-life balance.

$135,000–$145,000/yr
Global

  • Own the IT evidence program across ISO 27001, SOC 1, SOC 2, PCI DSS, and HIPAA for approximately 13 operating sites, managing audits and remediation.
  • Manage vulnerability management end to end, oversee endpoint detection and response, and lead security incident response through to conclusion.
  • Contribute to identity governance across a hybrid cloud and on-premises IdP, overseeing access review and privileged access controls.

Serverfarm is a leading developer and operator of data centers with over 750 locations and key customer relationships in 45 countries. With Manulife Investment Management's acquisition in 2023, the company is positioned for explosive growth and offers a culture of innovation and career development.

US

  • Lead and mature the organization's governance, risk management, compliance, and audit programs.
  • Own cybersecurity compliance initiatives including CMMC Level 2, SOC audits, and SOX IT General Controls.
  • Partner with business, technology, and executive stakeholders to align security controls with regulatory and business requirements.

Loenbro is a trusted construction lifecycle partner serving thousands of customers across the U.S. with services including electrical, mechanical, structural, inspection, and fabrication. The company has a national presence with a local approach and fosters a culture of integrity, teamwork, and purpose.

$80,208–$83,372/yr
Poland

  • Lead the design, implementation, and maintenance of Hyland's enterprise ISO governance and certification program across multiple certifications, business units, and regions.
  • Drive strategic expansion of ISO scope, including advanced certifications like TISAX and C5, and establish governance models and control ownership across teams.
  • Measure and report ISO program health through metrics, dashboards, and reporting, while providing leadership and mentorship to compliance specialists.

Hyland is the pioneer of the Content Innovation Cloud, delivering enterprise intelligence through solutions that unlock actionable insights and drive automation. Trusted by thousands of organizations worldwide, including many Fortune 100 companies, Hyland has nearly 4,000 employees and fosters an employee-centric, inclusive culture.

$80,000–$90,000/yr
US

  • Support day-to-day execution of IT risk, compliance, privacy, and governance programs.
  • Review client agreements and security questionnaires, coordinating redlines with legal.
  • Manage control evidence, vendor risk, data retention, and compliance policies.

Our partner provides IT risk, compliance, privacy, and governance services for clients. They have a small, collaborative team and value diverse perspectives and authentic contributions.

Global

  • Own the compliance function as its sole occupant, reporting to the Head of Engineering and partnering with the Security Lead on policies, audits, and evidence.
  • Manage the Q&A library, customer security reviews, audit calendar, and third-party risk to keep Duvo reviewable for buyers and auditors.
  • Deliver precise, evidenced answers that stand up to hostile reviewers and keep the trust center and subprocessor list current.

Duvo builds an AI operations platform for large enterprises, enabling customers to create AI agents that automate business-critical processes across systems like SAP, spreadsheets, and supplier portals. The company is growing fast and values velocity, direct feedback, autonomy, and heavy use of AI tools.

Global Unlimited PTO

  • Lead and grow a small security team while owning Canary's security and compliance program end-to-end.
  • Serve as the primary security voice to customers, partners, and auditors, translating security posture for varied audiences.
  • Set technical direction for security tooling and stay hands-on in architecture and threat-model reviews.

Canary Technologies is a leading agentic AI platform for hotel and guest management, powering digital infrastructure for over 20,000 hotels in 125+ countries. With nearly $200M raised, they are a top-funded hotel tech company, recognized for growth and workplace excellence.

Global

  • Lead and expand the security function across application security, security compliance, infrastructure & cloud security, and business application security.
  • Build and run the AppSec program with AI-assisted code review and integrate security into CI/CD pipelines.
  • Own ISO 27001 and SOC 2 certification, manage audits, and secure cloud and business applications.

Constructor provides an all-in-one platform for education and research using machine intelligence and data science to address educational challenges like access inequality and low engagement. The company is led by a gender-balanced board and fosters an inclusive culture, though employee size is not specified.

$200,000–$245,000/yr
US

  • Own the overall security posture, including policy, standards, and risk framework.
  • Manage ISO 27001, SOC 2, FedRAMP, and CMMC compliance programs.
  • Lead incident response, vulnerability management, and customer security assurance.

RapidFort is a cybersecurity company that helps organizations secure and optimize their software supply chain and containerized environments. As a fast-growing startup, we foster a culture of ownership and direct communication, where every team member contributes to our mission of securing cloud-native applications for regulated industries.

$130,000–$180,000/yr

  • Protect clients' digital assets by designing and implementing security solutions across multi-cloud environments.
  • Work closely with senior leadership and mentor junior team members while contributing across cybersecurity engineering, GRC, and security strategy.
  • Take ownership of client relationships and bring people along, adapting between engineering, strategy, and compliance conversations.

Riveron helps organizations implement leading governance, risk and compliance practices by combining deep expertise with pragmatic partnership. The firm serves startups, mid-market companies, and PE-backed portfolios with a collaborative and entrepreneurial culture.

Global

  • Monitor security systems, logs, and alerts to detect and respond to threats.
  • Run vulnerability scans and coordinate remediation with IT and engineering.
  • Maintain compliance with SOC 2 and support security awareness programs.

Power Digital is an AI-native growth firm combining talent and proprietary technology to help brands drive measurable business outcomes. With a people-first culture, the company values diversity and collaboration, using its AI operating system Omega to amplify capacity for strategy, creativity, and analysis.

US

  • Lead and mature the information security program, building on ISO 27001 and SOC 2 foundations.
  • Develop and operationalize security policies, risk management, and incident response.
  • Partner with Engineering and Product to integrate security into software development.

This is a partner company role managed by Jobgether, a platform that uses AI-powered matching to connect candidates with hiring companies. The partner is a rapidly scaling SaaS and cloud technology environment, with a growing security team and established ISO 27001 and SOC 2 programs.

$150,000–$160,000/yr
US Unlimited PTO

  • Implement and maintain AWS security configurations across development, staging, and production environments.
  • Operate SAST, DAST, and SCA tools integrated into CI/CD pipelines to remediate vulnerabilities.
  • Support compliance efforts such as SOC 2 Type II and ISO 27001 audits and improve security processes.

Pacvue is a leading software suite for eCommerce advertising, sales, and intelligence, helping brands grow on Amazon, Walmart, Instacart, and other marketplaces. The team is energetic, passionate, and focused on innovation, with a mission to help brands and sellers succeed.

Germany 6w PTO

  • Lead ISO 27001 and SOC 2 audit cycles end-to-end, owning compliance and audit.
  • Own customer trust by responding to security questionnaires and representing InfoSec to enterprise clients.
  • Drive risk management, vendor security, and incident response while building AI-assisted workflows.

We are the first AI-native Employee Experience Platform, helping organizations unlock inspirational communication. Our diverse team of 550+ employees supports over 1,500 customers, and we are a unicorn company valued at over $1 billion.

$135,000–$155,000/yr
US

  • Establish and enforce a unified security posture across GCP and OCI, including guardrails, IAM policies, and centralized monitoring.
  • Validate cloud deployments meet FedRAMP High, FISMA, and NIST 800-53 requirements, working with governance and audit teams.
  • Identify vulnerabilities, policy deviations, and architectural risks, and drive remediation.

Latitude is a growing Service-Disabled Veteran Owned company within the Federal Sector, working with various federal clients across multiple agencies. They foster a remote work-from-home culture, invest in employee growth, and strive for innovation to break through technology and government barriers.