Compliance Program Manager responsible for day-to-day execution of compliance programs at healthcare data company. Managing SOC 2, ISO 27001, and HITRUST compliance operations with cross-functional coordination.
Responsibilities
Own the compliance calendar, including timelines, milestones, check-ins, and recurring evidence collection across SOC 2, ISO 27001, and HITRUST.
Drive audit readiness end-to-end by maintaining compliance roadmaps, dependencies, and deliverables to ensure work stays on track throughout the year.
Operate Thoropass day-to-day by assigning evidence requests, sending reminders, maintaining clean artifacts, managing dashboards, and supporting basic workflows and access as needed.
Coordinate audit activities by tracking auditor requests, managing deadlines, and ensuring responses are complete, accurate, and submitted on time.
Partner cross-functionally with IT, Engineering, Product, HR, Legal, and Operations to assign ownership, align expectations, and drive follow-through.
Draft, update, and maintain security and compliance policies and procedures that align required controls with real operational practices.
Create new security and compliance policies as needed to support evolving business practices, audit requirements, and control gaps, ensuring policies are practical, clear, and aligned with how the company actually operates.
Run compliance operations by managing policy review cycles, control narratives, version control, and evidence consistency across frameworks.
Track findings and remediation by logging gaps, assigning owners and due dates, and validating closure and remediation evidence.
Requirements
4+ years of experience in program management, compliance coordination, security operations, or a similar cross-functional role
Strong familiarity with SOC 2; exposure to ISO 27001 and/or HITRUST (hands-on experience is a plus, not required)
Solid project and program management fundamentals, including task tracking, dependency management, and stakeholder follow-up
Excellent documentation skills and attention to detail (naming conventions, versioning, evidence quality)
Experience drafting and maintaining policies and procedures aligned to operational reality
Experience using compliance tools such as Thoropass, Drata, or Vanta (Thoropass preferred)
Benefits
Full suite of health insurance options, in addition to generous paid time off
Pre-planned company-wide wellness holidays
Retirement options
Health & charitable donation stipends
Impactful Business Resource Groups
Flexible work hours & the opportunity to work from anywhere
The opportunity to work with leading biotech and life sciences companies in an innovative industry with a mission to improve healthcare around the globe
Senior Cyber Security Project Manager at Airbus Protect managing medium complexity projects in Cyber Security Consulting. Focusing on project leadership and team management in diverse client settings.
Security Architect responsible for designing cloud security architectures for leading brands. Ensuring compliance and guiding incident response strategies in AWS environments.
Senior Security Consultant for ISMS Management at Bundesdruckerei GmbH in Berlin. Responsible for security analysis, management, and advisory roles on cybersecurity issues.
IT - Systemadministrator managing Video Surveillance and Alarm Systems at Mühlbauer. Supporting technical solutions for multimedia and conference systems with project involvement and ticket handling.
AI Application Security Architect in charge of driving secure development lifecycle for AI systems across multi - cloud environments and hybrid platforms.
Security Project Manager responsible for managing cyber - security project delivery and ensuring quality execution in Bulgaria. Requires excellent communication skills and fluency in English.
Information Security professional managing governance, audit, and compliance in banking domain. Collaborating across teams to enhance security posture and control effectiveness.
IT Security Manager providing operational leadership for ICBC’s IT security program. Enhancing cyber security practices and managing security initiatives in a dynamic, hybrid cloud environment.
Security Officer ensuring safety and security of Yankee Candle assets and personnel. Responsiblities include monitoring, patrols, incident response, and safety training at the corporate campus.
IT Audit Consultant joining Baker Tilly to manage technology risks for clients, offering strategic advice and audit support. Engaging with client executives to ensure compliance and operational efficacy.