Security & Compliance Associate

Healthie

United States

Hybrid

USD 100,000 - 130,000

Full time

6 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Healthie is seeking a Security and Compliance Associate to join our NYC-hybrid team. You will support audits, assess vendor risk, and respond to security questions from customers and internal stakeholders.

You must be based in the United States, fluent in English, and capable of handling sensitive information with care. This role offers growth in a fast-moving healthcare software company with strong governance practices.

Qualifications

  • Excellent written and verbal English communication suitable for security and compliance responses.
  • Experience supporting third-party audits (SOC 2, HIPAA, HITRUST) and vendor risk.
  • Ability to manage multiple requests across teams and vendors.

Responsibilities

  • Assist in third-party audits (SOC 2, HIPAA, HITRUST) with evidence collection.
  • Assess and remediate vendor security risks and drive items to closure.
  • Answer security and compliance questions from customers and internal teams.
  • Handle security/compliance questionnaires from customers and prospects.
  • Coordinate requests across IT, Operations, Platform, R&D and executive offices.

Skills

Security awareness
Audit support
Vendor risk
Policy writing
Clear communication
AI prompts
English fluency

Tools

Vanta
Drata
SecureFrame
Thoropass

Job description

Our Mission

Healthie is an AI-Native, ONC Certified EHR for modern outpatient healthcare.

Healthie is proud to power clinically excellent healthcare for over 40,000 providers who deliver clinically excellent healthcare - longitudinal and collaboratively, with patient and provider experiences at the center. Both healthcare and technology are undergoing unparalleled industry innovation, and it’s incredible to see the momentum - from consumers, from providers, and from reimbursement for this type of healthcare - grow exponentially.

We provide the powerful infrastructure every care delivery organization needs. On the surface this includes EHR, Scheduling, Engagement, Billing, Data, and much more. Underneath the iceberg are thousands of configurations, settings, widgets, automations, and limitless capabilities because we are an API-first platform. Our fully brandable platform makes it easy for clinics and organizations of any size to scale and never reach a limit.

Today, over 3 billion API calls are made to Healthie every month, as thousands of organizations who work with more than 21 million patients in total, rely on Healthie to deliver clinically excellent healthcare in over 35 specialties, from behavioral healthcare to complex chronic care management and personalized medicine.

We believe in the power of technology to improve access to healthcare and we’re building the rails that make this a reality. We work fast and with quality because we provide business-critical, healthcare‑critical software that clinicians and patients need for a better healthcare system. We’re customer‑obsessed, operate with lightning‑fast processes and responses, and always share our product roadmap publicly- so customers can see what we’re building, and remain relentlessly focused on how care gets delivered.

Healthie is backed by leading investors, and while we've $42M raised to date, more importantly, we operate with fiscal responsibility and have been profitable for more than half of our time as a company. We know that building an ONC‑Certified EHR is a lifetime’s body of work, and we are here to build for our customers forever.

Learn more at https://www.gethealthie.com/

About the role

As a Security and Compliance Associate, you’ll work closely with Healthie’s VP of Security and Compliance to help operate and strengthen the security and compliance programs that support our business, customers, and platform. This is a hands‑on role for someone who is highly organized, detail‑oriented, and comfortable owning work from intake through completion.

You’ll support third‑party audits, assess vendor risk, respond to customer and internal security and compliance requests, and help keep the day‑to‑day work of the function moving. You’ll collaborate across technical and business teams and will be trusted to work with sensitive information, follow through on open items, and know when something needs to be escalated.

The work will include:

  • Helping with third party audits such as SOC 2, annual HIPAA assessment, and HITRUST, including gathering evidence and following‑up on the artifacts that are missing
  • Assessing third party’s security risk, interacting with vendors and driving remediation items to closure
  • Answering internal and customer questions regarding security and compliance
  • Answering security and compliance questionnaires from customers and prospective customers
  • Prioritizing incoming requests across multiple channels to security and compliance, and answering, escalating, or delegating them. Some of this is routing, and some is assigning compliance work to people senior to you and following up until it is done
  • Collaborating with other departments, primarily IT, Operations, Platform, R&D, and the offices of the CEO and CTO

What a week may look like: A few customer questionnaires, a vendor review or two, and evidence pulled for whatever audit is in flight. The queue gets cleared daily, including whatever Vanta flags and the questions from other teams who are blocked until they get an answer. Audit season is the exception. When evidence requests land, that is the week.

Note that you will have access to some of the company's most sensitive information, including data entrusted to our protection by customers and their clients. You must follow access rules exactly, raise your own mistakes before anyone else finds them, and keep confidence when it would be easier not to. Colleagues should be able to watch how you work and copy it.

This position might be suitable for someone with work experience in compliance and/or IT SOX work. But you might also be a fresh JD, BA, or MA that has an affinity for this kind of work in a dynamic, challenging, and exciting environment.

About you
  • You must be based in the United States. (The reason for this is that on occasion you may need to see protected health information [PHI], and our customers have contracts that forbid access to such information from outside the United States.)
  • You must be an excellent and fluent writer, speaker, and communicator in English. Those skills must be at least as good as any AI (in other words, you should be able to write, speak, and communicate without the aid of AI). You can compress a dense control requirement into two sentences a customer's security team will accept, and document an exception so it still holds up when someone audits it next year.
  • You must understand or have an aptitude for the scope of the security and compliance challenges faced by a modern healthcare software company.
  • You must be adept with AI. You are not an expert, but you are able to write useful prompts that get answers to the questions you want. You are also skilled at identifying AI slop and wading through and correcting AI bloviation. You can spot when a model is confidently wrong, and you know when to rewrite it rather than pass it along.
  • You are interested in software, technology, and its impact on humans. You are curious and will ask why a control exists before you enforce it, creative at finding a workable answer when the framework doesn’t give you one, and empathetic enough to understand why the person on the other end of the request is frustrated. Healthie's scope is quite large, and you will be asked to provide perspective with regard to how the technology fits with human expectations, both of Healthie's customers, and the clients of Healthie's customers.
  • You can hold a position with people more senior than you when the requirement is clear, and change it when someone gives you a better reason. You will be new to a lot of this and expected to ask early rather than guess.

Nice to Have

  • You are familiar with modern GRC tooling such as Vanta, Drata, SecureFrame, or Thoropass.
  • You are familiar with some of the regulatory frameworks in healthcare security and compliance: HIPAA, state level regulations, GDPR, the EU AI Act.
  • Any of CISA, CISM, CISSP, CIPP/US, CIPP/E. Note that this is not a requirement and a narrow professional background in these areas is not what we are looking for.
Details, details
  • This is a full-time, NYC-Hybrid position.
  • U.S. work authorization is required.
  • The salary for this position is a base between $100,000 - $130,000.
Interview Process
  • Quick chat with Katie from our Talent team (15 minutes)
  • Interview with John, VP Security & Compliance (30 minutes)
  • Talk with Edgar, Director of IT & Cindy, Director of People Operations: (30 minutes)
  • Interview with Sean, Staff AppSec Engineer(20 minutes)
  • Exec Interview with Cavan, CTO + cofounder (20 minutes)
  • Reference checks

Learn more at gethealthie.com/careers.

Healthie is subject to HIPAA and other security and privacy frameworks, and this job entails training and conformance to expectations regarding security and compliance.

Healthie participates in e-verify.

Healthie is committed to equal employment opportunity. All qualified applicants will receive consideration for employment without regard to and will not be discriminated against based on age, race, gender, color, religion, national origin, sexual orientation, gender identity, veteran status, disability or any other protected category. We're proud to building a diverse and inclusive environment that encourages collaboration, creativity, and growth. Whatever your background, please apply if this is a role that would make you excited to come into work every day.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Staff Engineer, New Products
Staff Engineer, New Products

Worky • Los Angeles (CA)

On-site
USD 150,000 - 190,000
Clinical Operations Specialist (EST) New
Clinical Operations Specialist (EST) New

Healthie • Northern (KY)

Hybrid
USD 85,000 - 103,000
Clinical Operations Specialist
Clinical Operations Specialist

Healthie • United States

Remote
USD 90,000 - 130,000
Staff Engineer, New Products New
Staff Engineer, New Products New

Healthie • Northern (KY)

Hybrid
USD 205,000 - 235,000
Clinical Operations Specialist (EST)
Clinical Operations Specialist (EST)

Healthie • United States

Remote
USD 85,000 - 103,000
Senior Data Engineer
Senior Data Engineer

Neara • United States

On-site
USD 150,000 - 190,000
Senior Software Engineer (Ruby/Full-Stack) - Hybrid New NYC or LA
Senior Software Engineer (Ruby/Full-Stack) - Hybrid New NYC or LA

Healthie • New York (NY), Northern (KY)

On-site
USD 185,000 - 205,000
Senior Technical Recruiter
Senior Technical Recruiter

Healthie • Los Angeles (CA)

Hybrid
USD 145,000 - 165,000
Senior Frontend Engineer
Senior Frontend Engineer

Worky • Los Angeles (CA)

On-site
USD 140,000 - 190,000
Engineering Manager, Billing New NYC or LA
Engineering Manager, Billing New NYC or LA

Healthie • New York (NY), Northern (KY)

Hybrid
USD 190,000 - 210,000