Director, Compliance

Brado AI

United States

On-site

USD 180,000 - 280,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Brado AI is seeking a Director of Compliance who will own and advance the company’s compliance program as we scale. You will serve as the subject-matter authority on HIPAA, HiTRUST, and SOC 2, building a culture of compliance across teams and driving audit readiness.

You will oversee end-to-end programs, policies, and controls, coordinate external audits, and monitor regulatory changes, partnering with IT and Legal to ensure ongoing compliance and risk management.

Qualifications

  • 7+ years in health care regulatory compliance and leadership.
  • Familiarity with health system and health payor client expectations in B2B SaaS.
  • Experience in SaaS/cloud environments (AWS or Azure).
  • Bachelor's degree or equivalent experience.
  • Willingness to complete training on healthcare regulations (HIPAA, etc.).

Responsibilities

  • Own end-to-end compliance program across HIPAA Privacy & Security Rules, SOC 2 Type II, and HiTRUST CSF.
  • Develop and maintain policies, procedures, and controls.
  • Lead audits and renewals through SOC 2 Type II and HiTRUST engagements.
  • Monitor regulatory changes and document impacts for the business.
  • Maintain Vanta as the system of record for evidence collection.
  • Collaborate with Engineering/IT on privacy-by-design and secure development.

Skills

HIPAA
Regulatory leadership
SaaS compliance
Cloud (AWS/Azure)
Vendor risk assessment
Data privacy & security

Education

Bachelor's degree

Tools

Vanta

Job description

Brado AI · Individual contributor, reporting to Chief Financial Officer

About the role

The Director of Compliance owns and advances Brado AI's compliance program as we scale. This person bridges regulatory rigor with practical business execution, serving as our subject-matter authority on HIPAA, HiTRUST, and SOC 2. They build a culture of compliance across every team, partner with leaders and employees on day-to-day compliance activities, and keep the organization in a constant state of audit readiness.

What you'll do
  • Manage the end-to-end compliance program across for the company’s client offerings: HIPAA Privacy and Security Rules, SOC 2 (Type II), and HiTRUST CSF.
  • Develop, maintain, and continuously improve policies, procedures, and controls to address evolving regulatory and contractual requirements.
  • Own execution of the compliance roadmap set jointly with the VP, Legal & Compliance; support preparation of executive and board updates as needed. Includes evaluating a potential move to a single HiTRUST certification across both platforms, a decision still pending.
  • Oversee development and ongoing maintenance of policies, guidelines, and systems for data privacy and security, working with domain experts to define and implement key controls.
  • Own and maintain the legislative matrix: monitor federal and state regulatory changes and updates, and document where and how each change impacts the business and any actions required.
  • Lead and manage all external audits, assessments, and renewals — including the annual SOC 2 Type II engagement and the HiTRUST engagement — from scoping through report issuance.
  • Coordinate with third-party auditors and assessors.
  • Continuously monitor compliance with privacy and security frameworks so the organization is always audit-ready and in compliance.
  • Manage and maintain Vanta as the system of record for continuous control monitoring and evidence collection.
  • Conduct quarterly department-level compliance audits on a rotating basis, in addition to company-wide audits, to spread documentation and remediation work evenly across the year.
  • Operate and mature the company's risk management framework, including regular risk assessments and risk register maintenance.
  • Own the HIPAA Breach Notification process; lead investigations and coordinate required notifications to Covered Entities and vendors.
  • Partner with Engineering and IT on vulnerability, patch management, and remediation prioritization.
  • Serve as the point of contact for incident reporting and management, coordinating investigation and resolution with IT and Legal.
  • Own disaster recovery and business continuity (DRBC) planning and execution, in partnership with IT.
Cross-functional collaboration
  • Work closely with sales and contract teams to support customer security and privacy questionnaires, enterprise procurement processes, and business associate agreement (BAA) review.
  • Partner with HR to deliver workforce compliance training, including annual HIPAA, privacy, and security awareness programs.
  • Advise Product and Engineering on privacy-by-design principles and secure development practices.
  • Facilitate the compliance committee, including developing agendas, reports, and information as requested by the committee, senior leadership, and/or the Board of Directors.
  • Offer coaching and mentorship for managers and employees throughout Brado AI on domain expertise.
Requirements
What we're looking for
  • 7+ years of experience in health care regulatory compliance and compliance leadership, with a deep understanding of HIPAA, key transactional systems (e.g. EMR), and ancillary communication systems (e.g. CRM).
  • Familiarity with the compliance and security expectations of health system and health payor clients in a B2B SaaS sales cycle, including vendor risk assessments and enterprise procurement review.
  • Experience operating in a SaaS or cloud-native environment (AWS or Azure).
  • Bachelor's degree or equivalent experience.
  • Willingness to complete all Brado AI and client-required training on healthcare industry regulations, including HCP processes and reporting, ethics, confidentiality, data privacy and security, and harassment prevention.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director, Compliance
Director, Compliance

Brado AI • St. Louis (MO)

On-site
USD 150,000 - 230,000
HIPAA, SOC 2 & HiTrust Compliance Leader
HIPAA, SOC 2 & HiTrust Compliance Leader

Brado AI • St. Louis (MO)

On-site
USD 150,000 - 230,000
Senior Compliance Leader — HIPAA, SOC 2 & HiTRUST
Senior Compliance Leader — HIPAA, SOC 2 & HiTRUST

Brado AI • United States

On-site
USD 180,000 - 280,000
Compliance Manager
Compliance Manager

UpDoc, Inc. • San Francisco (CA), Northern (KY)

Hybrid
USD 150,000 - 210,000
Security and Compliance Manager
Security and Compliance Manager

Clinically AI • San Diego (CA)

On-site
USD 110,000 - 165,000
Healthcare coverage
Unlimited PTO
401(k) with company match
+1
Director, Compliance
Director, Compliance

Claritas Rx • United States

On-site
USD 180,000 - 220,000
Unlimited PTO
Stock options
Flexible work environment
Director, Compliance & Privacy
Director, Compliance & Privacy

Nashville Public Radio • New York (NY)

On-site
USD 150,000 - 165,000
Health Care Plan (Medical, Dental & Vision)
Retirement Plan (Roth 401k)
Flexible PTO Policy
+3
Compliance Manager
Compliance Manager

RightCapital Inc. • Shelton (CT)

On-site
USD 80,000 - 100,000
Compliance and Privacy Director
Compliance and Privacy Director

Nashville Public Radio • New York (NY)

On-site
USD 100,000 - 150,000
Health Care Plan (Medical, Dental & Vision)
Retirement Plan (Roth 401k)
Flexible PTO Policy
+1
VP, Cybersecurity
VP, Cybersecurity

XpertDox • Scottsdale (AZ)

On-site
USD 160,000 - 210,000