Director, Compliance

Brado AI

St. Louis (MO)

On-site

USD 150,000 - 230,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Brado AI seeks a Director of Compliance to own and advance its regulatory program as the company scales. You will bridge regulatory rigor with practical business execution, serving as the SME on HIPAA, HiTRUST, and SOC 2 while fostering a culture of compliance across all teams.

You will lead program ownership, policy development, and audit activities, partnering with executives and IT to ensure ongoing readiness and alignment with business goals.

Qualifications

  • 7+ years of health care regulatory compliance and leadership.
  • Deep HIPAA, HIPAA Privacy & Security Rules, and CRM domain knowledge.
  • Experience operating in SaaS or cloud-native environments (AWS/Azure).
  • Bachelor's degree or equivalent experience.

Responsibilities

  • Own end-to-end compliance program across HIPAA, SOC 2 II, and HiTRUST.
  • Develop, maintain, and improve policies, procedures, and controls.
  • Oversee external audits, assessments, and renewals from scoping to report issuance.
  • Monitor privacy and security frameworks to ensure audit readiness.
  • Coordinate with third‑party auditors and assessors.

Skills

Regulatory compliance
HIPAA knowledge
Leadership
Risk management
SaaS/cloud-native

Education

Bachelor's degree

Tools

Vanta

Job description

Description

Director, Compliance

Brado AI

Individual contributor, reporting to Chief Financial Officer

About The Role

The Director of Compliance owns and advances Brado AI's compliance program as we scale. This person bridges regulatory rigor with practical business execution, serving as our subject-matter authority on HIPAA, HiTRUST, and SOC 2. They build a culture of compliance across every team, partner with leaders and employees on day-to-day compliance activities, and keep the organization in a constant state of audit readiness.

What You'll Do
Program ownership & strategy
  • Manage the end-to-end compliance program across for the company’s client offerings: HIPAA Privacy and Security Rules, SOC 2 (Type II), and HiTRUST CSF.
  • Develop, maintain, and continuously improve policies, procedures, and controls to address evolving regulatory and contractual requirements.
  • Own execution of the compliance roadmap set jointly with the VP, Legal & Compliance; support preparation of executive and board updates as needed. Includes evaluating a potential move to a single HiTRUST certification across both platforms, a decision still pending.
  • Oversee development and ongoing maintenance of policies, guidelines, and systems for data privacy and security, working with domain experts to define and implement key controls.
  • Own and maintain the legislative matrix: monitor federal and state regulatory changes and updates, and document where and how each change impacts the business and any actions required.
Audit & certification management
  • Lead ISCC meetings.
  • Lead and manage all external audits, assessments, and renewals — including the annual SOC 2 Type II engagement and the HiTRUST engagement — from scoping through report issuance.
  • Coordinate with third‑party auditors and assessors.
  • Continuously monitor compliance with privacy and security frameworks so the organization is always audit‑ready and in compliance.
  • Manage and maintain Vanta as the system of record for continuous control monitoring and evidence collection.
  • Conduct quarterly department‑level compliance audits on a rotating basis, in addition to company‑wide audits, to spread documentation and remediation work evenly across the year.
Risk & incident management
  • Operate and mature the company's risk management framework, including regular risk assessments and risk register maintenance.
  • Own the HIPAA Breach Notification process; lead investigations and coordinate required notifications to Covered Entities and vendors.
  • Partner with Engineering and IT on vulnerability, patch management, and remediation prioritization.
  • Serve as the point of contact for incident reporting and management, coordinating investigation and resolution with IT and Legal.
  • Own disaster recovery and business continuity (DRBC) planning and execution, in partnership with IT.
Cross-functional collaboration
  • Work closely with sales and contract teams to support customer security and privacy questionnaires, enterprise procurement processes, and business associate agreement (BAA) review.
  • Partner with HR to deliver workforce compliance training, including annual HIPAA, privacy, and security awareness programs.
  • Advise Product and Engineering on privacy‑by‑design principles and secure development practices.
  • Facilitate the compliance committee, including developing agendas, reports, and information as requested by the committee, senior leadership, and/or the Board of Directors.
  • Offer coaching and mentorship for managers and employees throughout Brado AI on domain expertise.
Requirements
What we're looking for
  • 7+ years of experience in health care regulatory compliance and compliance leadership, with a deep understanding of HIPAA, key transactional systems (e.g. EMR), and ancillary communication systems (e.g. CRM).
  • Familiarity with the compliance and security expectations of health system and health payor clients in a B2B SaaS sales cycle, including vendor risk assessments and enterprise procurement review.
  • Experience operating in a SaaS or cloud‑native environment (AWS or Azure).
  • Bachelor's degree or equivalent experience.
  • Willingness to complete all Brado AI and client‑required training on healthcare industry regulations, including HCP processes and reporting, ethics, confidentiality, data privacy and security, and harassment prevention.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

HIPAA, SOC 2 & HiTrust Compliance Leader
HIPAA, SOC 2 & HiTrust Compliance Leader

Brado AI • St. Louis (MO)

On-site
USD 150,000 - 230,000
Head of Compliance
Head of Compliance

Baba • New York (NY)

Hybrid
USD 150,000 - 190,000
Security and Compliance Manager
Security and Compliance Manager

Clinically AI • San Diego (CA)

On-site
USD 110,000 - 165,000
Healthcare coverage
Unlimited PTO
401(k) with company match
+1
Compliance Manager
Compliance Manager

RightCapital Inc. • Shelton (CT)

On-site
USD 80,000 - 100,000
Director, Compliance
Director, Compliance

Claritas Rx • United States

On-site
USD 180,000 - 220,000
Unlimited PTO
Stock options
Flexible work environment
Director, Privacy and HIPAA Compliance
Director, Privacy and HIPAA Compliance

Fidelity • United States

On-site
USD 180,000 - 280,000
Director, Compliance & AI Governance
Director, Compliance & AI Governance

AKASA • South San Francisco (CA)

On-site
USD 150,000 - 185,000
Flexible PTO
Health insurance
HSA contribution
+7
Governance, Risk & Compliance Analyst
Governance, Risk & Compliance Analyst

B Capital • San Francisco (CA)

On-site
USD 140,000 - 200,000
Sr. Director, Compliance and Privacy
Sr. Director, Compliance and Privacy

American Health Partners • Franklin (TN)

On-site
USD 150,000 - 210,000
Security and Compliance Manager
Security and Compliance Manager

Rezilient Health • United States

On-site
USD 90,000 - 130,000
Generous PTO
Paid family leave
Comprehensive medical, dental, vision, and life insurance
+1