# Security GRC Lead at Candid Health

- Company: Candid Health
- What the company does: Candid Health is your source of truth for revenue cycle management—track claims end-to-end, automate fixes, unlock insights, and scale digital health payments. Backed by Y Combinator.
- Company website: https://www.joincandidhealth.com
- Type: Startups (AI role)
- Level: Senior
- Location: San Francisco
- Work setup: Remote
- Pay: $180K to $258K base salary per year (USD)
- Posted: 2026-08-25
- Apply by: 2026-10-09
- Apply: https://jobs.ashbyhq.com/candidhealth/0c627953-8164-42f8-a4a3-b625c66dead2
- Page: https://www.1752.vc/careers/jobs/candid-health-security-grc-lead/

## About the role

We are seeking a Security GRC Lead to build our first in-house GRC program from the ground up. In this role, you won't just write policies or collect manual screenshots in spreadsheets; you will treat compliance as an engineering and data problem.

## What they're looking for

- 3+ years in a technical security role, such as Security Engineering, Cloud Security, or Technical GRC
- Proficiency in Python, TypeScript, SQL and hands on experience interacting with APIs, parsing logs, and querying databases
- Hands-on experience with at least one primary cloud platform, GCP Preferred and Infrastructure-as-Code tools such as Terraform
- Deep familiarity with core frameworks such as SOC 1/2, PCI, NIST, and/or HITRUST
- Understanding of CI/CD pipelines, Git workflows, and container environments (Docker/Kubernetes)
- Certifications such as CISSP, CISA, CRISC, AWS Certified Security – Specialty, or CCSP

Tags: Engineering
