Senior Compliance Specialist

3 hours, 16 minutes ago
Full-time
Senior
Cybersecurity
Spring Health

Spring Health

Spring Health is a company that offers a comprehensive and personalized mental healthcare solution for teams and families. They provide clinically proven technology and world-class providers to deliver precise care tailored to individual needs, elimina...

Health Care Providers & Services
1K-5K
Founded 2016
$366M raised

Description

  • Support compliance programs for SOC 2 Type II, HITRUST, HIPAA, GDPR, ISO 27001, ISO 42001, and ITGC-SOX readiness efforts.
  • Execute audit and assessment work including evidence collection, internal interview coordination, documentation review, and remediation tracking.
  • Partner with engineering, IT, security, and business teams to validate that controls are implemented and operating effectively.
  • Assist with third-party risk management and vendor due diligence activities, including ongoing monitoring.
  • Contribute to customer assurance work by drafting questionnaire responses and joining customer calls with senior team members.
  • Support business continuity and disaster recovery planning through documentation updates and testing coordination.
  • Operate and maintain GRC tooling to keep evidence accurate, complete, and audit-ready.
  • Perform internal control testing and risk assessments, document gaps, and track remediation follow-up.
  • Draft and maintain policies, procedures, and SOPs aligned with relevant standards and frameworks.
  • Carry out continuous monitoring activities such as access reviews, control testing, and artifact updates.

Requirements

  • Bachelor’s degree plus 5+ years of experience in a GRC, IT compliance, security, or risk-focused role.
  • Hands-on experience supporting audits and assessments for SOC 2, HITRUST, HIPAA, GDPR, ISO 27001, and/or SOX ITGCs.
  • Foundational experience supporting Business Continuity and Disaster Recovery activities, including documentation maintenance and testing coordination.
  • Working knowledge of control execution, evidence requirements, and audit processes.
  • Ability to work independently within a defined scope while escalating complex or novel issues as needed.
  • Strong organizational skills and attention to detail in managing documentation and deadlines.
  • Clear written and verbal communication skills with the ability to collaborate across technical and non-technical teams.
  • Experience supporting third-party risk management or supply chain compliance is preferred.
  • Experience with GRC tooling is preferred.

Benefits

  • Target base salary of $125,000-$138,000, plus a competitive total rewards package including equity and benefits.
  • Health, dental, and vision coverage starting on day one, with access to One Medical.
  • HSA and FSA options, with Spring contributing up to $1,000 to HSAs depending on plan type.
  • Employer-sponsored 401(k) match of up to 2%.
  • Annual allotment of no-cost visits for the employee and dependents to Spring Health network providers.
  • Competitive paid time off, including vacation, sick leave, and company holidays.
  • Parental leave of 18 weeks for birthing parents and 16 weeks for non-birthing parents after 6 months of tenure.
  • Up to $1,000 per year in professional development reimbursement.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Analyst, Fraud Intelligence

Extend 251-1K Air Freight & Logistics

Extend is hiring a Fraud Intelligence team member to analyze large-scale post-purchase data and help design fraud prevention strategies that protect merchants, improve customer trust, and support revenue growth.

E-commerce NumPy Pandas Python Scikit-learn SQL
1 minute ago

Senior Security Operations Analyst

Extend 251-1K Air Freight & Logistics

Extend is hiring a Security Operations professional to help protect its post-purchase commerce platform by monitoring threats, strengthening controls, and improving detection and incident response across cloud and security systems.

AWS AWS CDK DynamoDB OpenTelemetry SIEM Terraform
46 minutes ago

IT Auditor I

Pathward 251-1K Diversified Financial Services

Pathward is hiring an Information Technology Audit professional to perform IT audits that ensure compliance with regulations and internal policies while communicating findings to stakeholders.

1 hour, 1 minute ago

Member of Information & Security

Anchorage Digital 251-1K Capital Markets

Anchorage Digital is hiring a Member of the Global Information & Security Team to help build and scale its information security and IT risk management program for institutional digital asset services in a heavily regulated environment.

Cybersecurity Encryption
10 hours, 1 minute ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers