Security & Compliance Manager (GRC), US-based

Collectly

United States

On-site

USD 190,000 - 220,000

Full time

15 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Unlimited PTO
Comprehensive Health Coverage
Equity Opportunities
Retirement Planning (401k)
Student Loan Support
Competitive Compensation

Job summary

Collectly is seeking a senior security and compliance leader to own end-to-end security programs for a PHI-handling SaaS platform. You will automate evidence, streamline controls, and respond directly to customer inquiries with technical depth.

You’ll lead SOC 2 and HITRUST as the owner, drive HIPAA governance, and manage vendor risk and audits, collaborating with CTO and DevOps. Exceptional judgment and written communication are essential.

Qualifications

  • Extensive experience in security compliance or GRC, esp. in PHI-handling environments.
  • Has run SOC 2 and HITRUST as an owner, not a contributor.
  • Deep HIPAA knowledge: Security/Privacy/Breach rules, BAAs.
  • Hands-on with compliance automation (Vanta or similar).
  • Strong in frameworks; able to apply new frameworks without a playbook.
  • Writes clear, final-draft customer-facing prose.
  • Can follow technical conversations with DevOps/engineers unassisted.
  • Can reason about threat models and justify findings; escalate when needed.
  • Software/security engineering background is a plus; relevant certs welcomed.

Responsibilities

  • Own customer-facing security and compliance programs.
  • Lead AI governance questionnaires and reviews for the AI patient-billing agent.
  • Conduct live security calls with prospects' InfoSec teams.
  • Manage procurement portals (Archer, ProcessUnity, Venminder).
  • Oversee annual customer reattestation cycles.
  • Handle customer security escalations and RCAs.
  • Host customers exercising right-to-audit clauses.
  • Distribute SOC 2, HITRUST summaries and NDA-subprocessor notices.
  • Develop a public trust center and standard security package.

Skills

SOC 2 ownership
HITRUST ownership
HIPAA fluency
Vanta knowledge
GRC experience
Frameworks familiarity
Customer-facing prose

Tools

Vanta
Archer
ProcessUnity
Venminder

Job description

About Collectly

Collectly is a patient billing and payments platform for US healthcare providers. We handle protected health information and card payments at scale, integrate directly with major EHRs, and sell to health systems and large provider organizations buyers with real security programs and real diligence processes. We're HITRUST i1 Validated and SOC 2 Type 2.

About Collectly

Collectly is a patient billing and payments platform for US healthcare providers. We handle protected health information and card payments at scale, integrate directly with major EHRs, and sell to health systems and large provider organizations buyers with real security programs and real diligence processes. We're HITRUST i1 Validated and SOC 2 Type 2.

The role

You’ll own security and compliance end to end. Today it's split between the CTO and whichever engineer happens to be nearest. You’ll take all of it.

You’ll be the only person in this function, so the job is to build a program that scales without adding drag. Automate the evidence, delete the controls nobody can trace to a requirement, and answer the hard customer questions yourself instead of routing them to engineering.

What You’ll Own
Customer-facing security and compliance
  • Answering customers’ security questionnaires
  • AI governance questionnaires and responsible-AI reviews covering our AI patient billing agent
  • Live security calls with prospects' InfoSec teams - technical conversations, not slide reading
  • Health-system procurement portals (Archer, ProcessUnity, Venminder and similar)
  • Annual customer reattestation cycles
  • Customer security escalations, incident communications, and customer-facing RCAs
  • Hosting customers who exercise right-to-audit clauses
  • Distribution of SOC 2, HITRUST certification, pen test summaries, and subprocessor notices under NDA
  • A public trust center, standard security package, and answer library - so most of the above becomes a lookup rather than a project
Audits and certifications
  • HITRUST i1 and SOC 2 Type 2, end to end: readiness, evidence, auditor management, remediation tracking
  • PCI DSS: SAQ ownership, AOC collection from processors, scope definition for card-present and card-not-present flows
  • Annual HIPAA Security Risk Analysis and risk register
  • Pen test lifecycle: scheduling, scoping, remediation tracking, customer-facing summary
  • Quarterly user access reviews
  • BCP/DR tabletops and annual test coordination
Compliance tooling
  • Own Vanta and our security scanners as an administrator
  • Pull evidence from systems - CI, infrastructure-as-code, identity provider, EDR, cloud config - instead of collecting screenshots
  • Reduce the count of manually evidenced controls every year
Contracts, BAAs, and vendor risk
  • BAAs in both directions, customer and subcontractor, from template through negotiation
  • Security exhibits, DPAs, subprocessor inventory
  • Tiered vendor security review, so a no-PHI vendor gets a one-page checklist and a same-day answer
  • Annual vendor reattestation
Policies, training, and incident response
  • Own and maintain the policy set
  • Security awareness and HIPAA training, phishing simulations, completion tracking
  • Own the incident response program: runbooks, tabletops, coordination during an incident
  • Breach notification clock management - the HIPAA window, state AG requirements, cyber insurance notice, and the per-contract customer notification windows in our MSAs
  • A documented exception process with a named approver, expiry date, and compensating control
Privacy and AI governance
  • HIPAA Privacy Officer designation
  • State privacy law tracking: CCPA/CPRA, Washington My Health My Data, and what follows
  • Stand up a durable AI governance framework for our AI patient billing agent - model inventory, human oversight, monitoring - replacing today's per-customer, from-scratch approach
  • Track emerging state rules on AI in healthcare and AI-generated patient communications
What You Won't Own
  • Remediation engineering. Findings and fixes belong to DevOps. You own the SLA dashboard and the escalation path.
  • Shipping decisions. You document risk and elevate. The CTO decides on the priority.
  • A seat as a gate in design or code review.
What We're Looking For
  • Extensive experience in security compliance or GRC, including time in healthcare SaaS or another PHI-handling environment
  • Has run SOC 2 and HITRUST as an owner, not a contributor
  • Deep HIPAA fluency: Security Rule, Privacy Rule, Breach Notification Rule, BAAs, minimum necessary
  • Hands-on with Vanta or a comparable compliance automation platform
  • Strong on frameworks generally, and able to pick up an unfamiliar one and apply it without a playbook - NIST AI RMF and ISO 42001 are where we're headed and neither has settled practice yet
  • Writes final-draft customer-facing prose: clear, accurate, no hedging
  • Able to follow a technical conversation with our DevOps and platform engineers unassisted - architecture diagrams, infrastructure-as-code, access control models, cloud configuration
  • Reasons about threat models, not finding titles. Given how a control is actually implemented in our system, you can work out whether a finding is exploitable, whether it's already mitigated elsewhere, and whether it matters for the data in question. You can close something as not applicable with a written rationale that survives an auditor, and you can tell when the opposite is true and it needs to be escalated hard.

A software engineering or security engineering background is a strong plus here, though not required — what matters is the judgment, however you acquired it.

Also a plus: PCI DSS in a payments context. Certifications we recognize: CIPP/US, HCISPP, CISSP, HITRUST CCSFP.

Process

Intro with the CTO, then a working session where we answer a real inbound security questionnaire together, then a scenario conversation and cross-functional interviews. No take-home.

Please be prepared to actively research information during the exercise.

Why you'll love it here
  • Unlimited PTO: We believe in work-life balance and encourage you to recharge when you need it.
  • Comprehensive Health Coverage: Fully paid medical, dental, and vision insurance for you and your dependents, because your well-being matters to us.
  • Equity Opportunities: Share in our success with stock options - your hard work will drive our growth.
  • Retirement Planning Made Easy: Enjoy a 401(k) with a generous company match to secure your future.
  • Student Loan Support: We help lighten the load with contributions toward your student loans.
  • Competitive Compensation: $190,000 - $220,000 per year

Collectly is a tech-enabled patient billing platform that works as an add-on for your EHR/PM. Collectly accelerates and increases patient cash flow, streamlines post-service billing operations, and provides the best patient experience that works for all demographics.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security & Compliance Manager (GRC), US-based
Security & Compliance Manager (GRC), US-based

Collectly, Inc. • Northern (KY)

Hybrid
USD 190,000 - 220,000
Unlimited PTO
Health coverage
Equity opportunities
+3
Senior SW Engineer (USA based)
Senior SW Engineer (USA based)

Collectly • United States

Hybrid
USD 180,000 - 200,000
Unlimited PTO
Comprehensive health coverage
Equity opportunities
+3
Security Engineer, GRC
Security Engineer, GRC

Candid Health • New York (NY)

On-site
USD 180,000 - 258,000
Security Engineer, GRC
Security Engineer, GRC

Candid Health • Denver (CO)

On-site
USD 180,000 - 258,000
Security GRC Lead
Security GRC Lead

candidhealth • San Francisco (CA)

On-site
USD 180,000 - 258,000
Security GRC Lead
Security GRC Lead

Candid Health • San Francisco (CA)

On-site
USD 180,000 - 258,000
Security GRC Lead
Security GRC Lead

Candid Health • New York (NY), Northern (KY)

Hybrid
USD 180,000 - 258,000
Sales Development Representative
Sales Development Representative

Collectly • San Francisco (CA)

Hybrid
USD 90,000 - 110,000
Unlimited PTO
Health coverage
Equity opportunities
+3
Engineering Manager, Payments & Reconciliation
Engineering Manager, Payments & Reconciliation

Quiet Capital • San Francisco (CA)

On-site
USD 180,000 - 280,000
Strategic Account Executive
Strategic Account Executive

Collectly • United States

Remote
USD 180,000 - 350,000
Unlimited PTO
Comprehensive Health Coverage
Equity Opportunities
+3