Compliance Lead
HybridColumbus, Ohio, United States
Job Summary
Own Avandra's compliance program end-to-end, driving HIPAA, HITRUST, and SOC 2 certification timelines while maintaining the risk register and conducting company-wide assessments. Author and maintain security policies, coordinate evidence collection for external audits, and manage vendor risk assessments and security questionnaires for health system partners. Lead compliance integrations for M&A targets, evaluating PHI practices and establishing remediation roadmaps for acquired entities. Develop and deliver company-wide training, translating complex regulatory requirements into actionable guidance for engineering and operations teams.
Required Qualifications
- 5+ years of hands-on compliance experience at a B2B SaaS or healthcare technology company
- Demonstrated ownership of HIPAA compliance programs
- Working knowledge of HITRUST (i1 or r2)
- SOC 2 Type II experience — you've coordinated evidence, managed auditors, and closed gaps
- Ability to work cross-functionally with Engineering on technical controls without needing a translator
- Strong written communication — policy writing, questionnaire responses, and executive summaries are all in your wheelhouse
- Self-starter mentality; you build structure in ambiguity
Desired Qualifications
- Experience supporting compliance assessments or integration work in M&A contexts
- Familiarity with multi-entity or subsidiary compliance program management
- CISSP, CISM, HCISPP, or equivalent certification
- Experience with compliance automation tooling (Vanta, Drata, Tugboat Logic, etc.)
- Familiarity with PHI data flows, health data integrations, and healthcare data contracts
- Prior experience at a growth-stage startup where the compliance program was being created, not inherited
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.