Lead Security & Compliance Analyst

Remote Jobs

United States

Hybrid

USD 80,000 - 135,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Remote-first culture
Office in NYC (optional)
Home office stipend
Learning & development stipend
Annual bonus up to 15%

Job summary

Parachute Health in the United States is seeking a hybrid Security Compliance & Technical Security professional to own our audit cycle and strengthen our cloud defenses. You will lead SOC 1/2 and HITRUST audits end-to-end, develop security policies, manage automation platforms like Drata and SafeBase, and coordinate with vendors.

The role combines compliance work with hands-on security engineering in AWS.

Qualifications

  • 4+ years combined experience across security compliance/GRC and hands-on security.
  • Direct experience supporting SOC 1/SOC 2 and/or HITRUST audits – you've been through at least one full audit cycle.
  • Working knowledge of HIPAA Security and Privacy requirements.
  • Hands-on experience with vulnerability scanning and remediation, and comfort reading technical findings (CVEs, misconfigurations, cloud security issues).
  • Familiarity with AWS security concepts (IAM, security groups, logging, WAF).
  • Ability to write clear policies and remediation tickets.

Responsibilities

  • Own SOC 1, SOC 2, HITRUST CSF, and HITRUST AI audits end-to-end: scoping, evidence collection, auditor coordination, and findings remediation.
  • Develop, update, revise, and implement compliance policies, procedures, and practices for security frameworks (HIPAA, HITRUST, SOC) as well as general compliance and operations.
  • Manage our compliance automation and trust platforms (Drata, SafeBase), including control monitoring and responses to customer security questionnaires.
  • Coordinate with external vendors and clients to gather information needed for compliance reviews, validations, and audits.
  • Run third-party/vendor risk assessments and respond to customer security assessments and external inquiries.
  • Deliver HIPAA and security awareness training and measure control effectiveness through internal audits.
  • Run the vulnerability management program: scanning, triage, prioritization, and driving remediation with engineering teams.
  • Investigate and remediate security findings across our AWS environment (EKS, WAF, Shield, CloudFront, IAM) and SaaS stack.
  • Review external attack surface findings and implement fixes from CSP headers to TLS configuration.
  • Support security incident response: log analysis, forensic evidence collection, and containment.
  • Support fraud and forensic investigations authentication log analysis, targeted data extraction, and evidence preservation in support of legal and compliance matters.
  • Improve our security tooling and automate evidence collection, using scripting (Python, Bash) where manual work can be eliminated.

Skills

SOC audits
HIPAA security
Vulnerability management
AWS security concepts
Policy writing

Tools

Drata
SafeBase
SIEM tools

Job description

Parachute Health is transforming post-acute care as the leading digital ordering platform for medical equipment and supplies. We connect major health systems, health plans, and suppliers to help patients get the life-saving products they need at home. Since launching, we've connected 300,000+ clinicians and 3,000+ supplier locations across all 50 states and helped 15M+ patients. What started as a DME ePrescribing tool has become the order management platform of choice for home medical equipment.

Join our team and make a difference in patient care.

About the Role

This is a hybrid role: roughly half security compliance and audit, half hands-on technical security. You'll own our compliance audit cycle end-to-end (SOC 1, SOC 2, HITRUST CSF, HITRUST AI), and you'll also work directly on the technical side: vulnerability management, security findings remediation, cloud security reviews, and third-party risk.

Responsibilities
Compliance & Audit
  • Own SOC 1, SOC 2, HITRUST CSF, and HITRUST AI audits end-to-end: scoping, evidence collection, auditor coordination, and findings remediation
  • Develop, update, revise, and implement compliance policies, procedures, and practices for security frameworks (HIPAA, HITRUST, SOC) as well as general compliance and operations
  • Manage our compliance automation and trust platforms (Drata, SafeBase), including control monitoring and responses to customer security questionnaires.
  • Coordinate with external vendors and clients to gather information needed for compliance reviews, validations, and audits
  • Run third-party/vendor risk assessments and respond to customer security assessments and external inquiries
  • Deliver HIPAA and security awareness training and measure control effectiveness through internal audits
Technical Security
  • Run the vulnerability management program: scanning, triage, prioritization, and driving remediation with engineering teams
  • Investigate and remediate security findings across our AWS environment (EKS, WAF, Shield, CloudFront, IAM) and SaaS stack
  • Review external attack surface findings (e.g., SecurityScorecard) and implement fixes from CSP headers to subresource integrity to TLS configuration
  • Support security incident response: log analysis, forensic evidence collection, and containment
  • Support fraud and forensic investigations authentication log analysis, targeted data extraction, and evidence preservation in support of legal and compliance matters
  • Improve our security tooling and automate evidence collection, using scripting (Python, Bash) where manual work can be eliminated
What We're Looking For
  • 4+ years combined experience across security compliance/GRC and hands-on technical security
  • Direct experience supporting SOC 1/SOC 2 and/or HITRUST audits - you've been through at least one full audit cycle
  • Working knowledge of HIPAA Security and Privacy requirements
  • Hands-on experience with vulnerability scanning and remediation, and comfort reading technical findings (CVEs, misconfigurations, cloud security issues)
  • Familiarity with AWS security concepts (IAM, security groups, logging, WAF)
  • Ability to write clear policies and procedures and equally clear remediation tickets
Nice to Have
  • Experience with compliance automation platforms (Drata, Vanta, or similar)
  • Experience in healthcare or another regulated industry
  • Certifications such as CISSP, CISA, CRISC, HITRUST CCSFP, or CISM
  • Experience with SIEM tools and log analysis
  • Experience with forensic log analysis, fraud investigations, or supporting legal/eDiscovery requests
Benefits
  • Medical, Dental, and Vision Coverage: Comprehensive plans with options for low-to-no-cost premiums.
  • Employer HSA Contribution: Company-funded contributions to your Health Savings Account.
  • 401(k) Retirement Plan
  • Equity Incentive Plan
  • Annual Company-Wide Bonus: Opportunity for up to 15% bonus based on company performance.
  • Remote-First Culture: We are remote-first with a dedicated NYC office and reimbursement options for co-working spaces.
  • Flexible Vacation Policy
  • Summer Fridays: 5 additional Fridays off during the summer (separate from PTO).
  • Home Office and Wellness Stipend
  • Monthly Internet Stipend
  • Annual Learning and Development Stipend
Base Salary Band (based on experience and level)

$80,000 - $135,000

California job applicants may access the Notice of Collection of Personal Information and Privacy Policy with information and rights required by the California Privacy Rights Act (CPRA) the link here.

We are proud to be an equal opportunity employer that does not discriminate on the basis of actual or perceived race, color, creed, religion, national origin, ancestry, citizenship status, age, sex or gender (including pregnancy, childbirth related medical conditions and lactation), gender identity or gender expression (including transgender status), sexual orientation, marital status, military service and veteran status, disability, genetic information, or any other characteristic protected by applicable federal, state, or local laws and ordinances.

Visa Sponsorship

This role is not eligible for employer visa sponsorship. Applicants must be legally authorized to work in the United States at the time of application and for the duration of employment. The Company does not sponsor employment authorization for this position.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Security & Compliance Analyst
Lead Security & Compliance Analyst

Parachute Health • New York (NY)

Hybrid
USD 80,000 - 135,000
Medical Insurance
Dental Insurance
Vision Insurance
+7
Lead Security & Compliance Analyst
Lead Security & Compliance Analyst

Parachute Health • United States

On-site
USD 80,000 - 130,000
Health coverage
HSA contributions
401(k) plan
+3
Lead Security & Compliance Analyst U.S. Remote
Lead Security & Compliance Analyst U.S. Remote

Parachute Health, LLC • United States

Hybrid
USD 80,000 - 135,000
Remote-first culture
Health insurance
401(k) plan
+2
IT & Security Engineer (Contract)
IT & Security Engineer (Contract)

Alumni Ventures • New York (NY)

On-site
USD 48,216,000 - 68,880,000
Lead Data Analyst
Lead Data Analyst

Jobless • Northern (KY)

Hybrid
USD 160,000 - 200,000
Remote-first culture
Annual company-wide bonus
Home office stipend
+3
Lead Data Analyst U.S. Remote
Lead Data Analyst U.S. Remote

Parachute Health, LLC • Northern (KY)

Hybrid
USD 160,000 - 200,000
Medical, Dental, Vision coverage
Remote-first culture
Annual performance bonus up to 15%
+2
Senior Software Engineer at Parachute Health
Senior Software Engineer at Parachute Health

Feedinkoo • United States

Remote
USD 125,000 - 170,000
Medical, Dental, and Vision Coverage
401(k) Retirement Plan
Equity Incentive Plan
+7
Customer Experience Associate
Customer Experience Associate

Parachute Health • New York (NY)

Hybrid
USD 50,000 - 61,000
Medical, Dental, Vision coverage
Employer HSA contribution
401(k) retirement plan
+6
DevSecOps Engineer
DevSecOps Engineer

Claritas Rx • Northern (KY)

Hybrid
USD 130,000 - 160,000
Staff Product Designer
Staff Product Designer

Doist • United States

Hybrid
USD 155,000 - 210,000
Medical coverage
401(k) retirement plan
Equity incentive plan
+1