Compliance Lead

3 weeks, 2 days ago
Full-time
Senior
Cybersecurity
Aegis Ventures

Aegis Ventures

Aegis Ventures operates as a next generation venture studio that collaborates with entrepreneurs and industry leaders to create, launch, and expand innovative companies aimed at addressing significant societal challenges.

Professional Services
51-250
Founded 2020

Description

  • Own and operationalize Avandra's compliance program across HIPAA, HITRUST, and SOC 2.
  • Maintain the risk register and conduct company-wide risk assessments on a regular cadence.
  • Author, publish, and maintain security and compliance policies and procedures.
  • Evaluate emerging frameworks such as ISO 27001 and NIST CSF as the company scales.
  • Coordinate evidence collection, gap assessments, and control testing across cross-functional teams.
  • Manage audit relationships with external assessors and compliance automation platforms.
  • Own the vendor security intake and assessment process.
  • Respond to customer security questionnaires, RFPs, and due diligence requests.
  • Lead compliance assessments for acquisition targets and evaluate their PHI handling, certifications, and audit findings.
  • Own post-acquisition compliance integration planning, remediation, and rollout across subsidiaries.
  • Develop and deliver company-wide compliance training, including onboarding for acquired teams.

Requirements

  • 5+ years of hands-on compliance experience at a B2B SaaS or healthcare technology company.
  • Demonstrated ownership of HIPAA compliance programs and working knowledge of HITRUST (i1 or r2).
  • SOC 2 Type II experience, including coordinating evidence, managing auditors, and closing gaps.
  • Ability to work cross-functionally with Engineering on technical controls.
  • Strong written communication for policy writing, questionnaire responses, and executive summaries.
  • Self-starter mentality with the ability to build structure in ambiguity.
  • Experience supporting compliance assessments or integration work in M&A contexts (preferred).
  • Familiarity with multi-entity or subsidiary compliance program management (preferred).
  • CISSP, CISM, HCISPP, or equivalent certification (preferred).
  • Experience with compliance automation tools such as Vanta, Drata, or Tugboat Logic (preferred).
  • Familiarity with PHI data flows, health data integrations, and healthcare data contracts (preferred).
  • Prior experience at a growth-stage startup building a compliance program from the ground up (preferred).

Benefits

  • Competitive salary.
  • Equity package.
  • Comprehensive benefits.
  • Hybrid work flexibility.
  • Meaningful impact on healthcare breakthroughs and patient outcomes.
  • Career-defining exposure to strategy, operations, fundraising, M&A, and scaling.
  • Opportunity to work with an experienced founder and strong investor partners.
  • Values-driven culture.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Legal & Compliance Specialist – Auto Retail

KPA 251-1K Professional Services

KPA is seeking an Automotive Retail Legal & Compliance Specialist to strengthen federal and 50-state Advertising, Sales, and Finance & Insurance compliance through regulatory analysis, knowledge management, consultant enablement, and AI-enabled solutions.

1 hour, 50 minutes ago

Senior Compliance Analyst, Canada

Crypto.com 1K-5K Capital Markets

Crypto.com is seeking a Compliance Senior Analyst to strengthen its Canadian compliance program within a fast-moving digital asset and securities business by translating regulatory requirements into effective policies, controls, training, and operations.

2 hours, 20 minutes ago

Compliance Analyst - KYB

Binance 5K-10K Capital Markets

Binance is seeking a Corporate Compliance specialist to support onboarding, AML/CFT reviews, risk assessments, and regulatory compliance across its global blockchain and digital-asset business.

Blockchain
2 hours, 20 minutes ago

Governance, Risk & Compliance (GRC) Manager

Fullscript 251-1K Health Care Providers & Services

Fullscript, a health technology company, is seeking a hands-on GRC Manager to lead its security compliance program, manage a two-person team, and scale governance, risk, and audit readiness across the organization.

HIPAA
2 hours, 35 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers