- Salary
- $100k – $130k
- Location
- Remote
- Workplace
- Remote
- Department
- Security/IT
- Seniority
- Entry
- Source
- Greenhouse
Description
Our Mission
Healthie is an AI-Native, ONC Certified EHR for modern outpatient healthcare.
Healthie is proud to power clinically excellent healthcare for over 40,000 providers who deliver clinically excellent healthcare - longitudinal and collaboratively, with patient and provider experiences at the center. Both healthcare and technology are undergoing unparalleled industry innovation, and it’s incredible to see the momentum - from consumers, from providers, and from reimbursement for this type of healthcare - grow exponentially.
We provide the powerful infrastructure every care delivery organization needs. On the surface this includes EHR, Scheduling, Engagement, Billing, Data, and much more. Underneath the iceberg are thousands of configurations, settings, widgets, automations, and limitless capabilities because we are an API-first platform. Our fully brandable platform makes it easy for clinics and organizations of any size to scale and never reach a limit.
Today, over 3 billion API calls are made to Healthie every month, as thousands of organizations who work with more than 21 million patients in total, rely on Healthie to deliver clinically excellent healthcare in over 35 specialties, from behavioral healthcare to complex chronic care management and personalized medicine.
We believe in the power of technology to improve access to healthcare and we’re building the rails that make this a reality. We work fast and with quality because we provide business-critical, healthcare-critical software that clinicians and patients need for a better healthcare system. We’re customer-obsessed, operate with lightning-fast processes and responses, and always share our product roadmap publicly- so customers can see what we’re building, and remain relentlessly focused on how care gets delivered.
Healthie is backed by leading investors, and while we've $42M raised to date, more importantly, we operate with fiscal responsibility and have been profitable for more than half of our time as a company. We know that building an ONC-Certified EHR is a lifetime’s body of work, and we are here to build for our customers forever.
Learn more at https://www.gethealthie.com/
About the role
As a Security and Compliance Associate, you’ll work closely with Healthie’s VP of Security and Compliance to help operate and strengthen the security and compliance programs that support our business, customers, and platform. This is a hands-on role for someone who is highly organized, detail-oriented, and comfortable owning work from intake through completion.
You’ll support third-party audits, assess vendor risk, respond to customer and internal security and compliance requests, and help keep the day-to-day work of the function moving. You’ll collaborate across technical and business teams and will be trusted to work with sensitive information, follow through on open items, and know when something needs to be escalated.
The work will include:
- Helping with third party audits such as SOC 2, annual HIPAA assessment, and HITRUST, including gathering evidence and following-up on the artifacts that are missing
- Assessing third party’s security risk, interacting with vendors and driving remediation items to closure
- Answering internal and customer questions regarding security and compliance
- Answering security and compliance questionnaires from customers and prospective customers
- Prioritizing incoming requests across multiple channels to security and compliance, and answering, escalating, or delegating them. Some of this is routing, and some is assigning compliance work to people senior to you and following up until it is done
- Collaborating with other departments, primarily IT, Operations, Platform, R&D, and the offices of the CEO and CTO
What a week may look like: A few customer questionnaires, a vendor review or two, and evidence pulled for whatever audit is in flight. The queue gets cleared daily, including whatever Vanta flags and the questions from other teams who are blocked until they get an answer. Audit season is the exception. When evidence requests land, that is the week.
Note that you will have access to some of the company's most sensitive information, including data entrusted to our protection by customers and their clients. You must follow access rules exactly, raise your own mistakes before anyone else finds them, and keep confidence when it would be easier not to. Colleagues should be able to watch how you work and copy it.
This position might be suitable for someone with work experience in compliance and/or IT SOX work. But you might also be a fresh JD, BA, or MA that has an affinity for this kind of work in a dynamic, challenging, and exciting environment.
About you
- You must be based in the United States. (The reason for this is that on occasion you may need to see protected health information [PHI], and our customers have contracts that forbid access to such information from outside the United States.)
- You must be an excellent and fluent writer, speaker, and communicator in English. Those skills must be at least as good as any AI (in other words, you should be able to write, speak, and communicate without the aid of AI). You can compress a dense control requirement into two sentences a customer's security team will accept, and document an exception so it still holds up when someone audits it next year.
- You must understand or have an aptitude for the scope of the security and compliance challenges faced by a modern healthcare software company.
- You must be adept with AI. You are not an expert, but you are able to write useful prompts that get answers to the questions you want. You are also skilled at identifying AI slop and wading through and correcting AI bloviation. You can spot when a model is confidently wrong, and you know when to rewrite it rather than pass it along.
- You are interested in software, technology, and its impact on humans. You are curious and will ask why a control exists before you enforce it, creative at finding a workable answer when the framework doesn’t give you one, and empathetic enough to understand why the person on the other end of the request is frustrated. Healthie's scope is quite large, and you will be asked to provide perspective with regard to how the technology fits with human expectations, both of Healthie's customers, and the clients of Healthie's customers.
- You can hold a position with people more senior than you when the requirement is clear, and change it when someone gives you a better reason. You will be new to a lot of this and expected to ask early rather than guess.
Nice to Have
- You are familiar with modern GRC tooling such as Vanta, Drata, SecureFrame, or Thoropass.
- You are familiar with some of the regulatory frameworks in healthcare security and compliance: HIPAA, state level regulations, GDPR, the EU AI Act.
- Any of CISA, CISM, CISSP, CIPP/US, CIPP/E. Note that this is not a requirement and a narrow professional background in these areas is not what we are looking for.
Details, details
- This is a full-time, NYC-Hybrid position.
- U.S. work authorization is required.
- The salary for this position is a base between $100,000 - $130,000.
Interview Process
- Quick chat with Katie from our Talent team (15 minutes)
- Interview with John, VP Security & Compliance (30 minutes)
- Talk with Edgar, Director of IT & Cindy, Director of People Operations: (30 minutes)
- Interview with Sean, Staff AppSec Engineer(20 minutes)
- Exec Interview with Cavan, CTO + cofounder (20 minutes)
- Reference checks
Learn more at gethealthie.com/careers.
Healthie is subject to HIPAA and other security and privacy frameworks, and this job entails training and conformance to expectations regarding security and compliance.
Healthie participates in e-verify.
Healthie is committed to equal employment opportunity. All qualified applicants will receive consideration for employment without regard to and will not be discriminated against based on age, race, gender, color, religion, national origin, sexual orientation, gender identity, veteran status, disability or any other protected category. We're proud to be building a diverse and inclusive environment that encourages collaboration, creativity, and growth. Whatever your background, please apply if this is a role that would make you excited to come into work every day.