Hiring.Camp

Security & Compliance Associate

Healthie

·

Today

Salary
$100k – $130k
Location
Remote
Workplace
Remote
Department
Security/IT
Seniority
Entry
Source
Greenhouse

Description

Our Mission

Healthie is an AI-Native, ONC Certified EHR for modern outpatient healthcare. 

Healthie is proud to power clinically excellent healthcare for over 40,000 providers who deliver clinically excellent healthcare - longitudinal and collaboratively, with patient and provider experiences at the center. Both healthcare and technology are undergoing unparalleled industry innovation, and it’s incredible to see the momentum - from consumers, from providers, and from reimbursement for this type of healthcare - grow exponentially. 

We provide the powerful infrastructure every care delivery organization needs. On the surface this includes EHR, Scheduling, Engagement, Billing, Data, and much more. Underneath the iceberg are thousands of configurations, settings, widgets, automations, and limitless capabilities because we are an API-first platform. Our fully brandable platform makes it easy for clinics and organizations of any size to scale and never reach a limit. 

Today, over 3 billion API calls are made to Healthie every month, as thousands of organizations who work with more than 21 million patients in total, rely on Healthie to deliver clinically excellent healthcare in over 35 specialties, from behavioral healthcare to complex chronic care management and personalized medicine.

We believe in the power of technology to improve access to healthcare and we’re building the rails that make this a reality. We work fast and with quality because we provide business-critical, healthcare-critical software that clinicians and patients need for a better healthcare system. We’re customer-obsessed, operate with lightning-fast processes and responses, and always share our product roadmap publicly-  so customers can see what we’re building, and remain relentlessly focused on how care gets delivered.

Healthie is backed by leading investors, and while we've $42M raised to date, more importantly, we operate with fiscal responsibility and have been profitable for more than half of our time as a company. We know that building an ONC-Certified EHR is a lifetime’s body of work, and we are here to build for our customers forever.

Learn more at https://www.gethealthie.com/

About the role

As a Security and Compliance Associate, you’ll work closely with Healthie’s VP of Security and Compliance to help operate and strengthen the security and compliance programs that support our business, customers, and platform. This is a hands-on role for someone who is highly organized, detail-oriented, and comfortable owning work from intake through completion.

You’ll support third-party audits, assess vendor risk, respond to customer and internal security and compliance requests, and help keep the day-to-day work of the function moving. You’ll collaborate across technical and business teams and will be trusted to work with sensitive information, follow through on open items, and know when something needs to be escalated.

The work will include:

  • Helping with third party audits such as SOC 2, annual HIPAA assessment, and HITRUST, including gathering evidence and following-up on the artifacts that are missing
  • Assessing third party’s security risk, interacting with  vendors and driving remediation items to closure
  • Answering internal and customer questions regarding security and compliance
  • Answering security and compliance questionnaires from customers and prospective customers
  • Prioritizing incoming requests across multiple channels to security and compliance, and answering, escalating, or delegating them. Some of this is routing, and some is assigning compliance work to people senior to you and following up until it is done
  • Collaborating with other departments, primarily IT, Operations, Platform, R&D, and the offices of the CEO and CTO

What a week may look like: A few customer questionnaires, a vendor review or two, and evidence pulled for whatever audit is in flight. The queue gets cleared daily, including whatever Vanta  flags and the questions from other teams who are blocked until they get an answer. Audit season is the exception. When evidence requests land, that is the week.

Note that you will have access to some of the company's most sensitive information, including data entrusted to our protection by customers and their clients. You must follow access rules exactly, raise your own mistakes before anyone else finds them, and keep confidence when it would be easier not to. Colleagues should be able to watch how you work and copy it.

This position might be suitable for someone with work experience in compliance and/or IT SOX work. But you might also be a fresh JD, BA, or MA that has an affinity for this kind of work in a dynamic, challenging, and exciting environment.

 


 

About you 

  • You must be based in the United States. (The reason for this is that on occasion you may need to see protected health information [PHI], and our customers have contracts that forbid access to such information from outside the United States.)
  • You must be an excellent and fluent writer, speaker, and communicator in English. Those skills must be at least as good as any AI (in other words, you should be able to write, speak, and communicate without the aid of AI). You can compress a dense control requirement into two sentences a customer's security team will accept, and document an exception so it still holds up when someone audits it next year.
  • You must understand or have an aptitude for the scope of the security and compliance challenges faced by a modern healthcare software company.
  • You must be adept with AI. You are not an expert, but you are able to write useful prompts that get answers to the questions you want. You are also skilled at identifying AI slop and wading through and correcting AI bloviation. You can spot when a model is confidently wrong, and you know when to rewrite it rather than pass it along.
  • You are interested in software, technology, and its impact on humans. You are curious and will ask why a control exists before you enforce it, creative at finding a workable answer when the framework doesn’t give you one, and empathetic enough to understand why the person on the other end of the request is frustrated. Healthie's scope is quite large, and you will be asked to provide perspective with regard to how the technology fits with human expectations, both of Healthie's customers, and the clients of Healthie's customers.
  • You can hold a position with people more senior than you when the requirement is clear, and change it when someone gives you a better reason. You will be new to a lot of this and expected to ask early rather than guess.

Nice to Have

  • You are familiar with modern GRC tooling such as Vanta, Drata, SecureFrame, or Thoropass.
  • You are familiar with some of the regulatory frameworks in healthcare security and compliance: HIPAA, state level regulations, GDPR, the EU AI Act.
  • Any of CISA, CISM, CISSP, CIPP/US, CIPP/E. Note that this is not a requirement and a narrow professional background in these areas is not what we are looking for.

 


 

Details, details

  • This is a full-time, NYC-Hybrid position. 
  • U.S. work authorization is required.
  • The salary for this position is a base between $100,000 - $130,000.

 


 

Interview Process

  • Quick chat with Katie from our Talent team (15 minutes)
  • Interview with John, VP Security & Compliance (30 minutes)
  • Talk with Edgar, Director of IT & Cindy, Director of People Operations: (30 minutes)
  • Interview with Sean, Staff AppSec Engineer(20 minutes)
  • Exec Interview with Cavan, CTO + cofounder (20 minutes)
  • Reference checks

 

Learn more at gethealthie.com/careers.

Healthie is subject to HIPAA and other security and privacy frameworks, and this job entails training and conformance to expectations regarding security and compliance.

Healthie participates in e-verify.

Healthie is committed to equal employment opportunity. All qualified applicants will receive consideration for employment without regard to and will not be discriminated against based on age, race, gender, color, religion, national origin, sexual orientation, gender identity, veteran status, disability or any other protected category. We're proud to be building a diverse and inclusive environment that encourages collaboration, creativity, and growth. Whatever your background, please apply if this is a role that would make you excited to come into work every day. 

Skills

SOCEHRSOXComplianceSOC 2HIPAAGDPRCISSP

Similar Jobs

30

Senior Information Security Compliance Analyst

Motorola Solutions·Ontario, Canada Offsite +2

2d ago

Senior Information Security Compliance Analyst

motorolasolutions·Ontario, Canada Offsite +2

2d ago

IT & Security Compliance Manager

Warp·New York·Onsite

2d ago

Senior Analyst, Security Compliance & Obligations

Nab·Tower A The Hallmark Building, VNM +1

2d ago

Security & Compliance Manager

Familywell·Remote +1·Remote

2d ago

Head - Payments Security Compliance, Security & Privacy Regulatory Enablement (SPRe)

Amazon·Remote

3d ago

Information Security Compliance Specialist

Docebo·Toronto, Ontario·Hybrid

3d ago

Information Security & Compliance Engineer

OfficeRnD·Sofia, Hybrid·Hybrid

3d ago

Security & Compliance Analyst Manager

Eastern Bank·Brockton, MA·Hybrid

3d ago

Microsoft Security, Compliance & Identity Architect Senior Consultant

Roberthalf·HOUSTON, US +1

4d ago

Software Development Engineer, AWS Artifact, AWS Compliance & Security Assurance

Amazon·Remote

4d ago

Director, Security Compliance and Trust

Gomotive·United States - Remote·Remote

4d ago

Security Compliance Analyst

GDIT·USA DC Home Office, US·Remote

1w ago

Security & Compliance Administrator

SOSi·Remote, US·Remote

1w ago

Microsoft Security, Compliance & Identity Architect Manager 

Roberthalf·HOUSTON, US +1

1w ago

Microsoft Security, Compliance & Identity Architect Associate Director

Roberthalf·SEATTLE, US

1w ago

Application Security Compliance Lead

Ncratleos·Gurgaon Office, India +1

1w ago

Security Compliance Analyst

Comscore·IND - Pune, India

1w ago

Information Security Compliance Analyst

Vestwell·New York, NY +1·Hybrid, Onsite

1w ago

Security/Compliance SME (REMOTE)

Koniag Government Services·Remote

1w ago

Senior Application Engineer (Compliance Security BSA/OFAC)

Navy Federal Financial Group·Vienna, VA·Hybrid

1w ago

Senior Security Compliance Analyst

Netbrain·Burlington, MA +1·Hybrid

2w ago

IT Networking & Information Security Compliance Administrator

"Eagle Creek Renewable Energy, LLC"·Badin, NC·Remote, Hybrid

2w ago

Assistant Director of Airport Security: Compliance and Enforcement - Denver International Airport

Denver means seeing yourself working·DEN CONA East Lvl 04, US

2w ago

Senior Director, Security & Compliance

Prompt·Remote·Remote

2w ago

Director of IT, Information Security & Compliance

Sciens Logistics·Dallas, TX·Onsite

2w ago

Tech Governance - Security Compliance & Governance Engineer (Mandarin Bilingual Required)

Okx·San Jose, California

2w ago

Cyber Security & Compliance Manager

Rivell·Sewell, New Jersey

2w ago

Business Security Compliance Officer

Securitas·Luton, England

2w ago

Federal Compliance & Security Architect

Salesforce·Virginia - Washington DC Metro - Remote, US +10·Onsite, Remote

2w ago