# Security & Compliance Manager (GRC), US-based at Collectly

- Company: Collectly
- What the company does: Backed by Y Combinator and Sapphire.
- Company website: http://collectly.co/
- Type: Startups
- Level: Senior
- Location: Remote
- Work setup: Remote
- Pay: $190K to $220K base salary per year (USD)
- Posted: 2026-09-17
- Apply by: 2026-11-01
- Apply: https://jobs.lever.co/CollectlyInc/27b5aeac-66dd-4213-8193-33266c665a10
- Page: https://www.1752.vc/careers/jobs/collectly-security-and-compliance-manager-grc-us-based/

## About the role

You'll own security and compliance end to end. Today it's split between the CTO and whichever engineer happens to be nearest. You'll take all of it. You'll be the only person in this function, so the job is to build a program that scales without adding drag. Automate the evidence, delete the controls nobody can trace to a requirement, and answer the hard customer questions yourself instead of routing them to engineering.

## What they're looking for

- Extensive experience in security compliance or GRC, including time in healthcare SaaS or another PHI-handling environment
- Has run SOC 2 and HITRUST as an owner, not a contributor
- Deep HIPAA fluency: Security Rule, Privacy Rule, Breach Notification Rule, BAAs, minimum necessary
- Hands-on with Vanta or a comparable compliance automation platform
- Strong on frameworks generally, and able to pick up an unfamiliar one and apply it without a playbook — NIST AI RMF and ISO 42001 are where we're headed and neither has settled practice yet
- Writes final-draft customer-facing prose: clear, accurate, no hedging

Tags: Engineering
