Compliance Lead
Quick Summary
gap analysis, remediation roadmap, and timeline to bring acquired entities under the Avandra compliance umbrella. Assess and rationalize subsidiary compliance programs; identify redundancies,
Aegis Ventures partners with entrepreneurs and industry leaders to launch and scale transformative companies in digital health and artificial intelligence. Our platform brings together market-shaping ideas, growth capital, and ambitious individuals to solve major societal problems. With a focus on innovations in healthcare, Aegis has launched four successful portfolio companies in partnership with Northwell Health and recently announced the Digital Consortium to co-develop, invest in, and launch new companies.
Avandra Imaging's mission is to unlock clinical data to overcome previously impossible medical challenges, bringing hope and medical breakthroughs that transform patient lives. Avandra is poised to revolutionize healthcare research and innovation by creating the largest indexed data cloud of medical imaging. This platform will unlock unprecedented access to real-world imaging data, essential for biopharma research, medical device innovation, AI model training, and improved patient care.
Leveraging its strategic acquisitions, Avandra aims to aggregate and de-identify vast amounts of imaging data, providing frictionless access to this invaluable resource. With a national footprint of over 5,000 customer integrations and a market share of approximately 70%, this robust infrastructure supports their core business, ensuring continued growth and cash flow to fuel their innovative data cloud platform.
About the Role
~1 min readAs our Compliance Lead, you'll own and operationalize our compliance program — turning our regulatory obligations into a scalable, audit-ready system that earns the trust of health systems, investors, and the patients behind the data. Avandra handles protected health information across a growing network of health system partners.
This is a build role. You'll work alongside our IT & Security Manager, contributing to security posture while owning the compliance workstream end-to-end. If you're energized by standing up programs — not just maintaining them — this is your role.
Responsibilities
~2 min readCompliance Program Management
- →Own Avandra's compliance roadmap across HIPAA, HITRUST, and SOC 2; drive certification timelines and recertification cycles.
- →Maintain the risk register and conduct company-wide risk assessments on a defined cadence.
- →Author, publish, and maintain security and compliance policies and procedures.
- →Evaluate emerging frameworks (ISO 27001, NIST CSF) for relevance as we scale.
Audit & Evidence Readiness
- →Coordinate evidence collection, gap assessments, and control testing across Engineering, Operations, and People teams.
- →Manage audit relationships with external assessors and compliance-automation platforms.
- →Maintain audit-ready documentation at all times — not just at audit season.
Vendor Risk Management
- →Own the vendor security intake and assessment process.
- →Respond to customer security questionnaires, RFPs, and due diligence requests; represent Avandra'scompliance posture credibly to health system partners.
M&A Compliance Integration
- →Conduct compliance assessments for acquisition targets — evaluate PHI handling practices, existing certifications, policy maturity, and open audit findings.
- →Own the post-acquisition compliance integration playbook: gap analysis, remediation roadmap, and timeline to bring acquired entities under the Avandra compliance umbrella.
- →Assess and rationalize subsidiary compliance programs; identify redundancies, coverage gaps, and certification consolidation opportunities.
- →Serve as the compliance integration contributor in cross-functional M&A workstreams alongside Legal, Finance, and Engineering.
- →Maintain a consolidated compliance posture across all entities — ensuring no subsidiary operates outside Avandra's policy and control framework.
Training & Culture
- →Develop and deliver company-wide compliance training, including onboarding programs tailored to acquired teams.
- →Translate complex regulatory requirements into clear, actionable guidance for non-compliance teams.
Required
- 5+ years of hands-on compliance experience at a B2B SaaS or healthcare technology company.
- Demonstrated ownership of HIPAA compliance programs; working knowledge of HITRUST (i1 or r2).
- SOC 2 Type II experience — you've coordinated evidence, managed auditors, and closed gaps.
- Ability to work cross-functionally with Engineering on technical controls without needing a translator.
- Strong written communication — policy writing, questionnaire responses, and executive summaries are all in your wheelhouse.
- Self-starter mentality; you build structure in ambiguity.
Preferred
- Experience supporting compliance assessments or integration work in M&A contexts.
- Familiarity with multi-entity or subsidiary compliance program management.
- CISSP, CISM, HCISPP, or equivalent certification.
- Experience with compliance automation tooling (Vanta, Drata, Tugboat Logic, etc.).
- Familiarity with PHI data flows, health data integrations, and healthcare data contracts.
- Prior experience at a growth-stage startup where the compliance program was being created, not inherited.
- SOC2 Type 2 re-certification for Avandra with two subsidiaries incorporated into the recertification.
- Roadmap for HITRUST established.
- Vendor risk assessment program operational with clear SLAs.
- Security questionnaire response time cut in half with a repeatable, high-quality process.
- Acquired entities are assessed and on a documented integration roadmap within 90 days of close.
- All staff — including acquired teams — trained; policies current and audit-accessible.
What We Offer
~1 min readLocation & Eligibility
Listing Details
- Posted
- August 12, 2026
- First seen
- August 12, 2026
- Last seen
- August 12, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 68%
- Scored at
- August 12, 2026
Signal breakdown
Please let Aegisventures know you found this job on Jobera.
4 other jobs at Aegisventures
View all →Explore open roles at Aegisventures.
Similar Compliance Lead jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.