Lead Security & Compliance Analyst

23 hours, 46 minutes ago
Full-time
Senior
Legal
Parachute Health

Parachute Health

Parachute Health provides a streamlined digital platform for ordering medical equipment and supplies, enhancing the efficiency of e-prescribing and facilitating better management of healthcare resources across the United States.

Health Care Providers & Services
51-250
Founded 2015
$15M raised

Description

  • Own SOC 1, SOC 2, HITRUST CSF, and HITRUST AI audits end-to-end, including scoping, evidence collection, auditor coordination, and findings remediation.
  • Develop, update, revise, and implement compliance policies, procedures, and practices for HIPAA, HITRUST, SOC, and general operations.
  • Manage compliance automation and trust platforms such as Drata and SafeBase, including control monitoring and responses to customer security questionnaires.
  • Coordinate with external vendors and clients to gather information needed for compliance reviews, validations, and audits.
  • Run third-party and vendor risk assessments and respond to customer security assessments and external inquiries.
  • Deliver HIPAA and security awareness training and measure control effectiveness through internal audits.
  • Run the vulnerability management program, including scanning, triage, prioritization, and remediation follow-up with engineering teams.
  • Investigate and remediate security findings across AWS and SaaS environments.
  • Review external attack surface findings and implement security fixes across web and cloud configurations.
  • Support security incident response, fraud investigations, and forensic evidence collection and preservation.
  • Improve security tooling and automate evidence collection using Python and Bash where possible.

Requirements

  • 4+ years of combined experience across security compliance/GRC and hands-on technical security.
  • Direct experience supporting SOC 1, SOC 2, and/or HITRUST audits, with at least one full audit cycle completed.
  • Working knowledge of HIPAA Security and Privacy requirements.
  • Hands-on experience with vulnerability scanning and remediation, including reading CVEs, misconfigurations, and cloud security issues.
  • Familiarity with AWS security concepts such as IAM, security groups, logging, WAF, EKS, Shield, and CloudFront.
  • Ability to write clear policies, procedures, and remediation tickets.
  • Experience with compliance automation platforms such as Drata, Vanta, or similar, preferred.
  • Experience in healthcare or another regulated industry, preferred.
  • Certifications such as CISSP, CISA, CRISC, HITRUST CCSFP, or CISM, preferred.
  • Experience with SIEM tools, log analysis, forensic investigations, or legal/eDiscovery support, preferred.
  • Authorization to work in the United States is required; the role is not eligible for employer visa sponsorship.

Benefits

  • Medical, dental, and vision coverage with low-to-no-cost premium options.
  • Employer HSA contribution.
  • 401(k) retirement plan.
  • Equity incentive plan.
  • Annual company-wide bonus of up to 15% based on company performance.
  • Remote-first culture with a dedicated NYC office and co-working reimbursement options.
  • Flexible vacation policy plus 5 additional Summer Fridays off.
  • Home office and wellness stipend, monthly internet stipend, and annual learning and development stipend.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior TPRM Security Lead

Gong 251-1K Internet Software & Services

Gong is seeking a Third Party Risk Manager to own and scale its vendor risk management program within the GRC team, ensuring third parties meet security, privacy, compliance, and resilience standards as the company grows.

Penetration Testing
16 minutes ago

Client Due Dilligence Analyst (DDQ)

Alphasense 51-250 Industrial Conglomerates

AlphaSense is hiring a DDQ Analyst to support its global sales process by managing client due diligence questionnaires and related compliance workflows.

Cybersecurity
23 hours, 16 minutes ago

FOIA Litigation Analyst

TechOp Solutions International 51-250 Internet Software & Services

TechOp Solutions International is hiring a FOIA Litigation Analyst to manage complex Freedom of Information Act litigation cases and support legal teams in ensuring compliance and transparency.

23 hours, 46 minutes ago

Regulatory Manager (Pharma)

CG Life 51-250 Professional Services

CG Life is seeking a Regulatory Manager to oversee client account regulatory operations, lead complex MLR and promotional review work, and ensure compliance across assigned projects.

1 day ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers