远程工作雷达

安全与合规经理(GRC)

Security & Compliance Manager (GRC)

AI开发工程限定地区(需当地身份)与中国几乎无重叠,需长期倒时差
公司Collectly
薪资$190,000 - $220,000/年
工作地点United States
地域资格限定地区(需当地身份)
时区要求与中国几乎无重叠,需长期倒时差
用工类型permanent
发布时间今天
数据来源4dayweek.io
前往 4dayweek.io 查看并投递 →
注意地域限制:该职位明确限定在 United States 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。
作息提示:与中国几乎无重叠,需长期倒时差。

关于Collectly
Collectly是美国医疗提供者的患者账单和支付平台。我们大规模处理受保护的健康信息和信用卡支付,直接与主要的电子病历系统集成,并向拥有真实安全计划和真实尽职调查流程的医疗系统和大型医疗机构销售。我们通过了HITRUST i1验证,并符合SOC 2 Type 2标准

职位职责
你将负责安全和合规的全流程。目前这部分工作由CTO和最近的工程师分担。你将接管全部内容

你是该职能中唯一的人,因此工作的重点是构建一个可以扩展而不会增加负担的体系。自动化证据收集,删除无法追溯到要求的控制措施,并亲自回答客户提出的难题,而不是转交给工程团队

你将负责的内容
面向客户的网络安全和合规
工作中最大的一部分

回答客户的网络安全问卷

AI治理问卷和负责任的AI审查,涵盖我们的AI患者账单代理

与潜在客户的信息安全团队进行实时安全通话——技术性对话,而非幻灯片阅读

医疗系统采购门户(Archer、ProcessUnity、Venminder等)

年度客户重新认证周期

客户安全升级、事件沟通和面向客户的根本原因分析(RCA)

接待行使审计权条款的客户

在保密协议(NDA)下分发SOC 2、HITRUST认证、渗透测试摘要和分包商通知

建立公开的信任中心、标准安全包和答案库——这样大部分上述内容变成查找而非项目

审计和认证

HITRUST i1和SOC 2 Type 2,全流程:准备、证据、审计师管理、整改跟踪

PCI DSS:SAQ所有者,从处理器处收集AOC,定义卡面和非卡面流程的范围

年度HIPAA安全风险分析和风险登记表

渗透测试生命周期:安排、范围定义、整改跟踪、面向客户的摘要

季度用户访问审查

BCP/DR桌面演练和年度测试协调

合规工具

作为管理员负责Vanta和我们的安全扫描器

从系统中提取证据——CI、基础设施即代码、身份提供商、终端检测与响应(EDR)、云配置——而不是收集截图

每年减少手动证据控制的数量

合同、BAA和供应商风险

双向的BAA,包括客户和分包商,从模板到谈判

查看英文原文

About Collectly
Collectly is a patient billing and payments platform for US healthcare providers. We handle protected health information and card payments at scale, integrate directly with major EHRs, and sell to health systems and large provider organizations buyers with real security programs and real diligence processes. We're HITRUST i1 Validated and SOC 2 Type 2.
The role
You'll own security and compliance end to end. Today it's split between the CTO and whichever engineer happens to be nearest. You'll take all of it.
You'll be the only person in this function, so the job is to build a program that scales without adding drag. Automate the evidence, delete the controls nobody can trace to a requirement, and answer the hard customer questions yourself instead of routing them to engineering.

What you'll own
Customer-facing security and compliance
The largest part of the job.

Answering customers’ security questionnaires

AI governance questionnaires and responsible-AI reviews covering our AI patient billing agent

Live security calls with prospects' InfoSec teams — technical conversations, not slide reading

Health-system procurement portals (Archer, ProcessUnity, Venminder and similar)

Annual customer reattestation cycles

Customer security escalations, incident communications, and customer-facing RCAs

Hosting customers who exercise right-to-audit clauses

Distribution of SOC 2, HITRUST certification, pen test summaries, and subprocessor notices under NDA

A public trust center, standard security package, and answer library — so most of the above becomes a lookup rather than a project

Audits and certifications

HITRUST i1 and SOC 2 Type 2, end to end: readiness, evidence, auditor management, remediation tracking

PCI DSS: SAQ ownership, AOC collection from processors, scope definition for card-present and card-not-present flows

Annual HIPAA Security Risk Analysis and risk register

Pen test lifecycle: scheduling, scoping, remediation tracking, customer-facing summary

Quarterly user access reviews

BCP/DR tabletops and annual test coordination

Compliance tooling

Own Vanta and our security scanners as an administrator

Pull evidence from systems — CI, infrastructure-as-code, identity provider, EDR, cloud config — instead of collecting screenshots

Reduce the count of manually evidenced controls every year

Contracts, BAAs, and vendor risk

BAAs in both directions, customer and subcontractor, from template through negotiation

Security exhibits, DPAs, subprocessor inventory

Tiered vendor security review, so a no-PHI vendor gets a one-page checklist and a same-day answer

Annual vendor reattestation

Policies, training, and incident response

Own and maintain the policy set

Security awareness and HIPAA training, phishing simulations, completion tracking

Own the incident response program: runbooks, tabletops, coordination during an incident

Breach notification clock management — the HIPAA window, state AG requirements, cyber insurance notice, and the per-contract customer notification windows in our MSAs

A documented exception process with a named approver, expiry date, and compensating control

Privacy and AI governance

HIPAA Privacy Officer designation

State privacy law tracking: CCPA/CPRA, Washington My Health My Data, and what follows

Stand up a durable AI governance framework for our AI patient billing agent — model inventory, human oversight, monitoring — replacing today's per-customer, from-scratch approach

Track emerging state rules on AI in healthcare and AI-generated patient communications

What you won't own
Remediation engineering. Findings and fixes belong to DevOps. You own the SLA dashboard and the escalation path.

Shipping decisions. You document risk and escalate. The CTO decides on the priority.

A seat as a gate in design or code review.

What we're looking for
Extensive experience in security compliance or GRC, including time in healthcare SaaS or another PHI-handling environment

Has run SOC 2 and HITRUST as an owner, not a contributor

Deep HIPAA fluency: Security Rule, Privacy Rule, Breach Notification Rule, BAAs, minimum necessary

Hands-on with Vanta or a comparable compliance automation platform

Strong on frameworks generally, and able to pick up an unfamiliar one and apply it without a playbook — NIST AI RMF and ISO 42001 are where we're headed and neither has settled practice yet

Writes final-draft customer-facing prose: clear, accurate, no hedging

Able to follow a technical conversation with our DevOps and platform engineers unassisted — architecture diagrams, infrastructure-as-code, access control models, cloud configuration

Reasons about threat models, not finding titles. Given how a control is actually implemented in our system, you can work out whether a finding is exploitable, whether it's already mitigated elsewhere, and whether it matters for the data in question. You can close something as not applicable with a written rationale that survives an auditor, and you can tell when the opposite is true and it needs to be escalated hard.

A software engineering or security engineering background is a strong plus here, though not required — what matters is the judgment, however you acquired it.
Also a plus: PCI DSS in a payments context. Certifications we recognize: CIPP/US, HCISPP, CISSP, HITRUST CCSFP.
Process
Intro with the CTO, then a working session where we answer a real inbound security questionnaire together, then a scenario conversation and cross-functional interviews. No take-home.
Please be prepared to actively research information during the exercise.

Why you'll love it here
Unlimited PTO: We believe in work-life balance and encourage you to recharge when you need it.
Comprehensive Health Coverage: Fully paid medical, dental, and vision insurance for you and your dependents, because your well-being matters to us.
Equity Opportunities: Share in our success with stock options - your hard work will drive our growth.
Retirement Planning Made Easy: Enjoy a 401(k) with a generous company match to secure your future.
Student Loan Support: We help lighten the load with contributions toward your student loans.
Competitive Compensation: $190,000 - $220,000 per year

Collectly is a tech-enabled patient billing platform that works as an add-on for your EHR/PM. Collectly accelerates and increases patient cash flow, streamlines post-service billing operations, and provides the best patient experience that works for all demographics.
 
Please, see a short video about us

本页面信息整理自 4dayweek.io,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

分析工程师

CollectlySerbiapermanent23 天前
开发工程未标注地域日间重叠约 2 小时,需偶尔早起或晚睡

人才协调员及搜寻专员

CollectlyUnited Statespermanent27 天前
职能支持限定地区(需当地身份)与中国几乎无重叠,需长期倒时差

高级软件工程师

CollectlySerbia$84,000 - $108,000/年permanent2026-08-05
开发工程未标注地域日间重叠约 2 小时,需偶尔早起或晚睡

← 返回全部职位