Startups

Security & Compliance Manager (GRC), US-based

Collectly · Remote · Remote

← All jobs
About Collectly

Backed by Y Combinator and Sapphire.

About the role

You'll own security and compliance end to end. Today it's split between the CTO and whichever engineer happens to be nearest. You'll take all of it. You'll be the only person in this function, so the job is to build a program that scales without adding drag. Automate the evidence, delete the controls nobody can trace to a requirement, and answer the hard customer questions yourself instead of routing them to engineering.

What they're looking for

  • Extensive experience in security compliance or GRC, including time in healthcare SaaS or another PHI-handling environment
  • Has run SOC 2 and HITRUST as an owner, not a contributor
  • Deep HIPAA fluency: Security Rule, Privacy Rule, Breach Notification Rule, BAAs, minimum necessary
  • Hands-on with Vanta or a comparable compliance automation platform
  • Strong on frameworks generally, and able to pick up an unfamiliar one and apply it without a playbook — NIST AI RMF and ISO 42001 are where we're headed and neither has settled practice yet
  • Writes final-draft customer-facing prose: clear, accurate, no hedging
More about this role

Collectly is a patient billing and payments platform for US healthcare providers. We handle protected health information and card payments at scale, integrate directly with major EHRs, and sell to health systems and large provider organizations buyers with real security programs and real diligence processes. We're HITRUST i1 Validated and SOC 2 Type 2.

You'll own security and compliance end to end. Today it's split between the CTO and whichever engineer happens to be nearest. You'll take all of it.

You'll be the only person in this function, so the job is to build a program that scales without adding drag. Automate the evidence, delete the controls nobody can trace to a requirement, and answer the hard customer questions yourself instead of routing them to engineering.

The largest part of the job.

Answering customers’ security questionnaires

AI governance questionnaires and responsible-AI reviews covering our AI patient billing agent

Live security calls with prospects' InfoSec teams — technical conversations, not slide reading

Health-system procurement portals (Archer, ProcessUnity, Venminder and similar)

Annual customer reattestation cycles

Customer security escalations, incident...

Read the full posting on Collectly's site ↗

Engineering

Build your edge while you search

Free tools for founders and investors, plus VC Unfiltered, our take on startups, venture and the people who build them.