freed
freed1mo ago
New

Governance, Risk, and Compliance Officer (Part-Time)

U.s.Remotefull-timemid
Legal & ComplianceCompliance Specialist
0 views0 saves0 applied

Quick Summary

Overview

ABOUT FREED: Doctors are overworked, burnt out, and are quitting in masses. At Freed, we combine clinician love with the latest AI tech and intense execution to create products that make clinicians happier. Our first product is an AI scribe that automates medical documentation.

Technical Tools
Legal & ComplianceCompliance Specialist

Doctors are overworked, burnt out, and are quitting in masses.

At Freed, we combine clinician love with the latest AI tech and intense execution to create products that make clinicians happier.

Our first product is an AI scribe that automates medical documentation.

Since May of 2023, we have:

With the backing of Sequoia Capital and other world-class VC’s, we are rapidly expanding our product offering. Patient-facing assistants, patient insights, EHR integrations, and other products are being built and used by thousands of clinicians every day.

We are looking for entrepreneurs. Fast, ambitious, and smart individuals who want to take care of the people who care for our health. Expect intense, clinician-focused, and interesting co-workers who want to win.

With an office in San Francisco, we embrace a hybrid schedule that brings out the best in teamwork and innovation. Our teams come together in person three days a week to collaborate, connect, and have a little fun along the way.

About the Role

~1 min read

We are hiring a Fractional GRC Manager (part-time, ~20 hrs/week) to build and own our compliance function.

Freed operates in a highly regulated environment (SOC 2 Type 2, HIPAA) with PHI flowing across 150+ vendors. Today, compliance work is fragmented across senior leaders, creating inefficiencies, audit friction, and product delays.

This role will act as the single accountable owner for Governance, Risk, and Compliance, responsible for maintaining audit readiness, unblocking product and vendor workflows, and reducing the compliance burden on engineering and leadership.

This is a hands-on, embedded operator role - not advisory. You will work closely with Finance, Engineering, Infrastructure, Legal, and GTM teams.

  • Own SOC 2 and HIPAA programs end-to-end

  • Manage auditor relationships and streamline evidence collection

  • Maintain continuous audit readiness via Drata

  • Improve audit efficiency

    • Own vendor compliance intake (BAAs, DPAs, security reviews)

    • Build and maintain a centralized vendor registry with PHI exposure mapping

    • Establish fast, repeatable onboarding processes

    • Partner with Engineering on vendor security assessments

    • Audit and remediate ~30 existing policies with outdated ownership structures

    • Replace “phantom roles” (e.g., Security Officer) with real owners

    • Establish a meaningful policy review cadence

    • Draft new policies (data retention, vendor management, access controls)

    • Own and operate Drata (controls, evidence, personnel tasks)

    • Manage Trust Center accuracy and external posture

    • Handle customer security questionnaires

    • Support Sales with compliance documentation for enterprise deals

    • Document PHI data flows and system boundaries

    • Support incident response from a compliance perspective

    • Stay current on HIPAA and regulatory developments

    Responsibilities

    ~1 min read
    • 5+ years in GRC, security compliance, or related roles (startup experience strongly preferred)

    • Deep experience with SOC 2 and HIPAA (hands-on ownership, not advisory)

    • Strong familiarity with vendor risk management, BAAs, DPAs, and audits

    • Experience with tools like Drata or similar compliance platforms

    • Ability to operate independently in a fractional, high-ownership role

    • Strong judgment - able to make pragmatic tradeoffs, not over-engineer

    Nice to Have

    ~1 min read
    • Exposure to HITRUST or ISO 27001 frameworks

    • Experience working cross-functionally with Engineering and GTM teams

    • Background in scaling compliance functions from early-stage

    • Competitive salary and equity in a high-growth company

    • Opportunity to make an immediate impact

    • Medical, dental, and vision coverage

    • Unlimited paid time off

    • Company-sponsored annual retreats

    • 401(k) plan to support your long-term financial goals

    • Commuter stipend for San Francisco-based employees

    Location & Eligibility

    Where is the job
    Worldwide
    Fully remote, anywhere in the world
    Who can apply
    Same as job location

    Listing Details

    Posted
    April 2, 2026
    First seen
    May 6, 2026
    Last seen
    May 10, 2026

    Posting Health

    Days active
    0
    Repost count
    0
    Trust Level
    23%
    Scored at
    May 6, 2026

    Signal breakdown

    freshnesssource trustcontent trustemployer trust
    Newsletter

    Stay ahead of the market

    Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

    A
    B
    C
    D
    Join 12,000+ marketers

    No spam. Unsubscribe at any time.

    freedGovernance, Risk, and Compliance Officer (Part-Time)