Manage day-to-day privacy compliance program operations, including policies, procedures, records, documentation, and supporting processes.
Conduct and coordinate Privacy Impact Assessments (PIAs/DPIAs) and data protection assessments for new products, features, vendors, and business initiatives.
Support data subject rights requests and privacy incident response processes.
This company operates in the health technology space, focusing on privacy and compliance. It is a fast-growing, remote-first organization with a collaborative culture emphasizing transparency, empowerment, and evidence-based decisions.
Serve as the primary privacy program manager for wearable technology initiatives, ensuring privacy requirements are incorporated into product architecture and workflows.
Lead privacy-by-design initiatives, conduct and facilitate Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs) across cross-functional teams.
Partner with Legal to interpret privacy laws and translate complex regulations into practical, actionable business and technical requirements.
Jobgether is an AI-powered job matching platform that connects top candidates with hiring companies. While specific size and culture details are not shared, the partner company is a fast-moving technology environment focused on innovation and continuous improvement.
Lead compliance programs including SOC 2, GDPR, CCPA/CPRA, and Shopify partner security requirements.
Own security policies, risk management, business continuity, and incident response.
Manage IT operations, endpoint security, and cloud security across the company.
Rebuy revolutionizes shopping with intelligent, personalized experiences for DTC brands. They are a fully remote team with a culture rooted in ownership, drive, and empathy.
Build and lead Chamber's first compliance function, spanning regulatory, clinical, government programs, IT/security, and internal audit.
Partner with legal, clinical, security, and business teams to embed compliance into workflows, technology, and market expansion.
Serve as the strategic compliance expert for Medicare/Medicaid, HIPAA, CPOM, and risk-based program development.
Chamber is rebuilding the system for cardiology by partnering with independent cardiologists and equipping them with technology, data, and operational tools. The company is an early-stage, mission-driven team focused on transforming heart health through AI-enabled clinical workflows and human-centered care.
Own and mature security, privacy, and compliance programs across HIPAA, SOC 2, and HITRUST.
Lead HITRUST certification end to end, including scoping, evidence collection, and assessor coordination.
Partner with Engineering, Product, SRE, and IT to integrate security into architecture, SDLC, and cloud infrastructure.
IntusCare is an end-to-end ecosystem built specifically to help PACE programs deliver exceptional care, strengthen financial performance, and stay compliant. It is a growing healthcare SaaS organization that empowers teams to improve outcomes for dual-eligible seniors.
Support day-to-day execution of IT risk, compliance, privacy, and governance programs.
Review client agreements and security questionnaires, coordinating redlines with legal.
Manage control evidence, vendor risk, data retention, and compliance policies.
Our partner provides IT risk, compliance, privacy, and governance services for clients. They have a small, collaborative team and value diverse perspectives and authentic contributions.
Execute and quality-check cross-channel campaigns across email, direct mail, and SMS.
Support new client launches, campaign configurations, and operational readiness checks.
Maintain client content, process Do Not Contact requests, and improve QA controls.
Virta Health is on a mission to reverse metabolic disease in one billion people through technology, personalized nutrition, and virtual care delivery. The company has raised over $350 million from top-tier investors and partners with health plans, employers, and government organizations, fostering a values-driven, remote-first culture.
Conduct compliance reviews, monitoring, and testing across regulatory obligations.
Review and investigate potential compliance issues, document findings, and escalate as needed.
Support vendor compliance, customer due diligence, and AI governance programs.
April is an embedded, year-round tax platform that brings real-time tax intelligence into the platforms people already use. The company's AI-powered engine and API-first infrastructure serve complex tax situations, with a culture emphasizing ownership, judgment, and professionalism.
Manage privacy verticals and advise on U.S. healthcare privacy laws, including HIPAA and state data breach rules.
Advise on AI regulations and governance, integrating AI tools into legal workflows.
Review privacy terms in commercial agreements and partner cross-functionally to mitigate risks.
Aledade PBC is a public benefit corporation empowering independent primary care to thrive in value-based care. Founded in 2014, it is the largest network of independent primary care in the country, with a remote-first, inclusive culture.
Act as part vCISO and account manager, guiding clients through security and compliance programs.
Assess security posture, provide recommendations, and design programs using NIST, SOC 2, and ISO 27001.
Liaise with auditors and internal teams to translate programs into policies, procedures, and configurations.
Oneleet provides a platform for companies to build, manage, and monitor cybersecurity programs and achieve SOC 2 and ISO 27001. It raised a $33M Series A and is a fast-growing, remote-first team with an opinionated culture.