Security & Compliance Manager (GRC), US-based
Quick Summary
About Collectly Collectly is a patient billing and payments platform for US healthcare providers. We handle protected health information and card payments at scale, integrate directly with major EHRs,
Collectly is a patient billing and payments platform for US healthcare providers. We handle protected health information and card payments at scale, integrate directly with major EHRs, and sell to health systems and large provider organizations buyers with real security programs and real diligence processes. We're HITRUST i1 Validated and SOC 2 Type 2.
You'll own security and compliance end to end. Today it's split between the CTO and whichever engineer happens to be nearest. You'll take all of it.
You'll be the only person in this function, so the job is to build a program that scales without adding drag. Automate the evidence, delete the controls nobody can trace to a requirement, and answer the hard customer questions yourself instead of routing them to engineering.
The largest part of the job.
Answering customers’ security questionnaires
AI governance questionnaires and responsible-AI reviews covering our AI patient billing agent
Live security calls with prospects' InfoSec teams — technical conversations, not slide reading
Health-system procurement portals (Archer, ProcessUnity, Venminder and similar)
Annual customer reattestation cycles
Customer security escalations, incident communications, and customer-facing RCAs
Hosting customers who exercise right-to-audit clauses
Distribution of SOC 2, HITRUST certification, pen test summaries, and subprocessor notices under NDA
A public trust center, standard security package, and answer library — so most of the above becomes a lookup rather than a project
HITRUST i1 and SOC 2 Type 2, end to end: readiness, evidence, auditor management, remediation tracking
PCI DSS: SAQ ownership, AOC collection from processors, scope definition for card-present and card-not-present flows
Annual HIPAA Security Risk Analysis and risk register
Pen test lifecycle: scheduling, scoping, remediation tracking, customer-facing summary
Quarterly user access reviews
BCP/DR tabletops and annual test coordination
Own Vanta and our security scanners as an administrator
Pull evidence from systems — CI, infrastructure-as-code, identity provider, EDR, cloud config — instead of collecting screenshots
Reduce the count of manually evidenced controls every year
BAAs in both directions, customer and subcontractor, from template through negotiation
Security exhibits, DPAs, subprocessor inventory
Tiered vendor security review, so a no-PHI vendor gets a one-page checklist and a same-day answer
Annual vendor reattestation
Own and maintain the policy set
Security awareness and HIPAA training, phishing simulations, completion tracking
Own the incident response program: runbooks, tabletops, coordination during an incident
Breach notification clock management — the HIPAA window, state AG requirements, cyber insurance notice, and the per-contract customer notification windows in our MSAs
A documented exception process with a named approver, expiry date, and compensating control
HIPAA Privacy Officer designation
State privacy law tracking: CCPA/CPRA, Washington My Health My Data, and what follows
Stand up a durable AI governance framework for our AI patient billing agent — model inventory, human oversight, monitoring — replacing today's per-customer, from-scratch approach
Track emerging state rules on AI in healthcare and AI-generated patient communications
Extensive experience in security compliance or GRC, including time in healthcare SaaS or another PHI-handling environment
Has run SOC 2 and HITRUST as an owner, not a contributor
Deep HIPAA fluency: Security Rule, Privacy Rule, Breach Notification Rule, BAAs, minimum necessary
Hands-on with Vanta or a comparable compliance automation platform
Strong on frameworks generally, and able to pick up an unfamiliar one and apply it without a playbook — NIST AI RMF and ISO 42001 are where we're headed and neither has settled practice yet
Writes final-draft customer-facing prose: clear, accurate, no hedging
Able to follow a technical conversation with our DevOps and platform engineers unassisted — architecture diagrams, infrastructure-as-code, access control models, cloud configuration
Reasons about threat models, not finding titles. Given how a control is actually implemented in our system, you can work out whether a finding is exploitable, whether it's already mitigated elsewhere, and whether it matters for the data in question. You can close something as not applicable with a written rationale that survives an auditor, and you can tell when the opposite is true and it needs to be escalated hard.
A software engineering or security engineering background is a strong plus here, though not required — what matters is the judgment, however you acquired it.
Also a plus: PCI DSS in a payments context. Certifications we recognize: CIPP/US, HCISPP, CISSP, HITRUST CCSFP.
Intro with the CTO, then a working session where we answer a real inbound security questionnaire together, then a scenario conversation and cross-functional interviews. No take-home.
Please be prepared to actively research information during the exercise.
- Unlimited PTO: We believe in work-life balance and encourage you to recharge when you need it.
- Comprehensive Health Coverage: Fully paid medical, dental, and vision insurance for you and your dependents, because your well-being matters to us.
- Equity Opportunities: Share in our success with stock options - your hard work will drive our growth.
- Retirement Planning Made Easy: Enjoy a 401(k) with a generous company match to secure your future.
- Student Loan Support: We help lighten the load with contributions toward your student loans.
- Competitive Compensation: $190,000 - $220,000 per year
Location & Eligibility
Listing Details
- Posted
- September 17, 2026
- First seen
- September 17, 2026
- Last seen
- September 17, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 80%
- Scored at
- September 17, 2026
Signal breakdown
Please let Collectlyinc know you found this job on Jobera.
3 other jobs at Collectlyinc
View all →Explore open roles at Collectlyinc.
Similar Compliance Specialist jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.