Security and Compliance Manager

Clinically AI

San Diego (CA)

On-site

USD 110,000 - 165,000

Full time

13 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Healthcare coverage
Unlimited PTO
401(k) with company match
Equity

Job summary

Clinically AI is seeking a Security and Compliance Manager to own the day-to-day compliance program, keep frameworks audit-ready, and secure workforce systems. You will partner with engineering, product, and leadership to scale while maintaining rigorous remediation and risk controls.

This role emphasizes hands-on remediation, policy updates, and collaboration across teams in a fast-growing healthcare AI startup.

Qualifications

  • 3+ years in security compliance, GRC, or IT security administration.
  • Hands-on experience with a compliance automation platform (e.g., Vanta, Drata, Secureframe).
  • Direct experience with SOC2 Type II and/or HIPAA programs.
  • Experience administering Google Workspace for business.
  • Experience managing an MDM solution for endpoints.
  • Ability to write and operationalize security policies.

Responsibilities

  • Own the compliance platform of record and manage frameworks, controls, tests, and policies.
  • Triage failures, drive remediation to closure, and coordinate with owners.
  • Maintain security policies and system docs with regular reviews.
  • Coordinate external audits end-to-end and handle evidence requests.
  • Administer Google Workspace: lifecycle, security settings, access, and audits.
  • Operate MDM to keep endpoints enrolled, encrypted, and compliant.
  • Track risk and lead mitigation with stakeholders.

Skills

Security compliance
GRC
IT security administration
OAuth 2.0/SAML
Policy writing

Tools

Vanta
Drata
Secureframe
Google Workspace
MDM tooling (Kandji/Jamf/Mosyle)

Job description

About Clinically AI

Clinically AI is a rapidly scaling healthcare AI company transforming how behavioral health and healthcare organizations manage clinical documentation, compliance workflows, chart auditing, and operational efficiency through artificial intelligence.


Our platform helps clinicians, compliance teams, administrators, and healthcare organizations reduce administrative burden, improve documentation quality, strengthen audit readiness, and operate more efficiently. We operate at the intersection of AI, healthcare operations, workflow design, and real-world clinical execution, where adoption, trust, usability, and measurable outcomes matter.


The Opportunity

We are seeking a Security and Compliance Manager to own the day-to-day operation of our compliance program end to end, keeping our frameworks audit-ready, our policies current, and our workforce systems locked down.


This is a critical role for someone who can manage our compliance platform of record, drive remediation on failing controls to closure, and administer the workforce security layer (Google Workspace and MDM) that our compliance posture depends on. You will work closely with engineering, product, and executive leadership to keep the company continuously compliant as we scale at high velocity.


This is not a purely administrative, ticket-routing role. You should be comfortable owning remediation from detection to closure, operating with high rigor, and driving issues to resolution yourself rather than just flagging them, in a fast-moving startup environment.


We believe a successful compliance function is defined not by simply passing audits, but by continuous audit-readiness, strong workforce security hygiene, and trust earned with enterprise customers.


What You'll Own


  • Own our compliance platform of record — manage frameworks (SOC2 Type II, HIPAA, NIST, etc.), controls, tests, policies, and integrations.


  • Monitor compliance tests continuously; triage failures, remediate directly where possible, and drive owners to resolution where not.


  • Maintain and update security policies, procedures, and system documentation, ensuring they reflect actual practice and are reviewed/acknowledged on schedule.


  • Manage evidence collection and audit readiness, keeping automated evidence flowing and closing gaps in manual evidence before auditors ask.


  • Coordinate external audits (SOC2 Type II, HIPAA, NIST, ISO, etc.) end to end — auditor communication, evidence requests, findings, and remediation plans.


  • Administer Google Workspace, including user lifecycle management, access controls, 2FA/SSO enforcement, and audit log reviews.


  • Manage our MDM to ensure all endpoints are enrolled, encrypted, patched, and compliant with policy.


  • Track risk via risk assessments and the risk register, and lead mitigation planning with stakeholders.



What We're Looking For


  • Compliance Ownership: You treat a failing compliance test as a to-do item, not a ticket to route elsewhere — you drive remediation from detection to closure yourself.


  • Operational Rigor: You maintain accurate, up-to-date policies and documentation, and keep evidence collection running continuously rather than scrambling before an audit.


  • Security & IT Administration Fluency: You're comfortable administering Google Workspace and MDM tooling directly — user lifecycle, access reviews, and endpoint compliance are second nature to you.


  • Cross-Functional Collaboration: You partner effectively with engineering, product, and leadership, scoping remediation work and reporting compliance posture clearly to non-technical stakeholders.


  • High Ownership Mindset: You operate with follow-through in a high-velocity, fast-scaling environment, without needing heavy oversight.



Required Qualifications


  • 3+ years of experience in security compliance, GRC, IT security administration, or similar roles.


  • Hands-on experience administering a compliance automation platform (e.g., Vanta, Drata, or Secureframe), including frameworks, tests, policies, and remediation workflows.


  • Direct experience with SOC2 Type II and/or HIPAA compliance programs — evidence collection, audits, and continuous control operations.


  • Experience administering Google Workspace in a business environment (user lifecycle, security settings, access controls).


  • Experience managing an MDM solution (e.g., Kandji, Jamf, Mosyle, or similar) for endpoint compliance.


  • Ability to write, maintain, and operationalize security policies and compliance documentation.


  • Strong organizational and follow-through skills — comfortable owning remediation from detection to closure.



Preferred Qualifications


  • Experience in healthcare, healthtech, or another regulated data environment.


  • Familiarity with additional frameworks (HITRUST, ISO27001, NIST) and experience adding new frameworks to a compliance platform.


  • Experience supporting enterprise customer security reviews, RFPs, and partner compliance requirements.


  • Working knowledge of cloud environments (GCP preferred) sufficient to coordinate remediation with engineering teams.


  • Experience with identity and access tooling (SSO/SAML, Google Cloud Identity, Okta, or similar).


  • Certifications such as CISA, CISM, Security+, CCSK, or equivalent practical experience.



Compensation & Benefits

Base salary: $110,000–$165,000 + equity


Actual compensation will depend on experience, scope, and overall alignment with the role.


We offer competitive compensation, equity participation, healthcare coverage (medical, dental, vision), unlimited PTO, and a 401(k) with company match plus Roth option.


Equal Employment Opportunity

Clinically AI provides equal employment opportunities to all employees and applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, genetics, or any other characteristic protected by applicable law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Manager
IT Manager

Clinical Notes Inc. • San Diego (CA), Northern (KY)

Hybrid
USD 85,000 - 120,000
Healthcare coverage (medical, dental,
Unlimited PTO
401(k) with company match
+2
Director, Compliance & AI Governance
Director, Compliance & AI Governance

AKASA • South San Francisco (CA)

On-site
USD 150,000 - 185,000
Flexible PTO
Health insurance
HSA contribution
+7
Senior Application Security Engineer
Senior Application Security Engineer

Monograph • Mountain View (CA)

Hybrid
USD 150,000 - 210,000
DevOps Engineer
DevOps Engineer

Clinically AI • San Diego (CA)

On-site
USD 125,000 - 160,000
Senior Application Security Engineer
Senior Application Security Engineer

Commure • United States

Hybrid
USD 120,000 - 180,000
Security & Compliance Lead — HIPAA, SOC2, Equity & PTO
Security & Compliance Lead — HIPAA, SOC2, Equity & PTO

Clinically AI • San Diego (CA)

On-site
USD 110,000 - 165,000
Healthcare coverage
Unlimited PTO
401(k) with company match
+1
Lead Security & Compliance Analyst
Lead Security & Compliance Analyst

Parachute Health • New York (NY)

Hybrid
USD 80,000 - 135,000
Medical Insurance
Dental Insurance
Vision Insurance
+7
GRC/IT Compliance Analyst
GRC/IT Compliance Analyst

Socket.dev • United States

Remote
USD 108,000 - 130,000
Stock options
Clinical AI Implementation Specialist
Clinical AI Implementation Specialist

Clinical Notes Inc. • San Diego (CA), Northern (KY)

Hybrid
USD 70,000 - 100,000
Equity (stock options)
Unlimited PTO
Medical, dental, vision coverage
+3
Clinical AI Implementation Lead
Clinical AI Implementation Lead

Clinically AI • California (MO)

Hybrid
USD 100,000 - 150,000
Competitive compensation
Performance-based incentives
Healthcare coverage
+1