waypointjobs

Collectly

Security & Compliance Manager (GRC), US-based

Remote — United States (see country and timezone requirements)

Check who can apply and the requirements below before continuing.

Job description

About Collectly

Collectly is a patient billing and payments platform for US healthcare providers. We handle protected health information and card payments at scale, integrate directly with major EHRs, and sell to health systems and large provider organizations buyers with real security programs and real diligence processes. We're HITRUST i1 Validated and SOC 2 Type 2.

The role

You'll own security and compliance end to end. Today it's split between the CTO and whichever engineer happens to be nearest. You'll take all of it.

You'll be the only person in this function, so the job is to build a program that scales without adding drag. Automate the evidence, delete the controls nobody can trace to a requirement, and answer the hard customer questions yourself instead of routing them to engineering.

What you'll own

Customer-facing security and compliance

The largest part of the job.

Answering customers’ security questionnaires

AI governance questionnaires and responsible-AI reviews covering our AI patient billing agent

Live security calls with prospects' InfoSec teams — technical conversations, not slide reading

Health-system procurement portals (Archer, ProcessUnity, Venminder and similar)

Annual customer reattestation cycles

Customer security escalations, incident communications, and customer-facing RCAs

Hosting customers who exercise right-to-audit clauses

Distribution of SOC 2, HITRUST certification, pen test summaries, and subprocessor notices under NDA

A public trust center, standard security package, and answer library — so most of the above becomes a lookup rather than a project

Audits and certifications

HITRUST i1 and SOC 2 Type 2, end to end: readiness, evidence, auditor management, remediation tracking

PCI DSS: SAQ ownership, AOC collection from processors, scope definition for card-present and card-not-present flows

Annual HIPAA Security Risk Analysis and risk register

Pen test lifecycle: scheduling, scoping, remediation tracking, customer-facing summary

Quarterly user access reviews

BCP/DR tabletops and annual test coordination

Compliance tooling

Own Vanta and our security scanners as an administrator

Pull evidence from systems — CI, infrastructure-as-code, identity provider, EDR, cloud config — instead of collecting screenshots

Reduce the count of manually evidenced controls every year

Contracts, BAAs, and vendor risk

BAAs in both directions, customer and subcontractor, from template through negotiation

Security exhibits, DPAs, subprocessor inventory

Tiered vendor security review, so a no-PHI vendor gets a one-page checklist and a same-day answer

Annual vendor reattestation

Policies, training, and incident response

Own and maintain the policy set

Security awareness and HIPAA training, phishing simulations, completion tracking

Own the incident response program: runbooks, tabletops, coordination during an incident

Breach notification clock management — the HIPAA window, state AG requirements, cyber insurance notice, and the per-contract customer notification windows in our MSAs

A documented exception process with a named approver, expiry date, and compensating control

Privacy and AI governance

HIPAA Privacy Officer designation

State privacy law tracking: CCPA/CPRA, Washington My Health My Data, and what follows

Stand up a durable AI governance framework for our AI patient billing agent — model inventory, human oversight, monitoring — replacing today's per-customer, from-scratch approach

Track emerging state rules on AI in healthcare and AI-generated patient communications

What you won't own

Remediation engineering. Findings and fixes belong to DevOps. You own the SLA dashboard and the escalation path.

Shipping decisions. You document risk and escalate. The CTO decides on the priority.

A seat as a gate in design or code review.

What we're looking for

Extensive experience in security compliance or GRC, including time in healthcare SaaS or another PHI-handling environment

Has run SOC 2 and HITRUST as an owner, not a contributor

Deep HIPAA fluency: Security Rule, Privacy Rule, Breach Notification Rule, BAAs, minimum necessary

Hands-on with Vanta or a comparable compliance automation platform

Strong on frameworks generally, and able to pick up an unfamiliar one and apply it without a playbook — NIST AI RMF and ISO 42001 are where we're headed and neither has settled practice yet

Writes final-draft customer-facing prose: clear, accurate, no hedging

Able to follow a technical conversation with our DevOps and platform engineers unassisted — architecture diagrams, infrastructure-as-code, access control models, cloud configuration

Reasons about threat models, not finding titles. Given how a control is actually implemented in our system, you can work out whether a finding is exploitable, whether it's already mitigated elsewhere, and whether it matters for the data in question. You can close something as not applicable with a written rationale that survives an auditor, and you can tell when the opposite is true and it needs to be escalated hard.

A software engineering or security engineering background is a strong plus here, though not required — what matters is the judgment, however you acquired it.

Also a plus: PCI DSS in a payments context. Certifications we recognize: CIPP/US, HCISPP, CISSP, HITRUST CCSFP.

Process

Intro with the CTO, then a working session where we answer a real inbound security questionnaire together, then a scenario conversation and cross-functional interviews. No take-home.

Please be prepared to actively research information during the exercise.

Why you'll love it here

Unlimited PTO: We believe in work-life balance and encourage you to recharge when you need it.

Comprehensive Health Coverage: Fully paid medical, dental, and vision insurance for you and your dependents, because your well-being matters to us.

Equity Opportunities: Share in our success with stock options - your hard work will drive our growth.

Retirement Planning Made Easy: Enjoy a 401(k) with a generous company match to secure your future.

Student Loan Support: We help lighten the load with contributions toward your student loans.

Competitive Compensation: $190,000 - $220,000 per year

Collectly is a tech-enabled patient billing platform that works as an add-on for your EHR/PM. Collectly accelerates and increases patient cash flow, streamlines post-service billing operations, and provides the best patient experience that works for all demographics.

Please, see a short video about us

Originally posted on Himalayas

Who can apply

Eligible countries: United States. Accepted UTC offsets: UTC-10, UTC-9, UTC-8, UTC-7, UTC-6, UTC-5, UTC+14. Review the full description for employer-specific work authorization, residency and schedule requirements.

Ready for your next step?Apply on the official website
Apply on Himalayas ↗

Explore related searches

Current related jobs

Red Wine and Blue

Himalayas

General Interest Application

Remote — United States (see country and timezone requirements)

Salary not specifiedfull timeRemote

WHO THE HECK ARE WE? Red Wine & Blue is a national community of over 600,000 diverse suburban women working together to defeat extremism, one fr…

Listing expires 2026-12-04View job

Carle Health

Himalayas

Finance Systems Analyst

Remote — United States (see country and timezone requirements)

$26.41 – $44.10 per hourfull timeRemote

OverviewThe Finance Systems Analyst assists with supporting assigned finance/accounting applications for the enterprise such as costing, producti…

Listing expires 2026-12-04View job

Kyowa Kirin

Himalayas

Scientific Relations Manager

Remote — Worldwide (see timezone requirements)

Salary not specifiedfull timeRemote

OverviewWE PUSH THE BOUNDARIES OF MEDICINE. LEAPING FORWARD TO MAKE PEOPLE SMILE At Kyowa Kirin International (KKI), our purpose is to make peop…

Listing expires 2026-12-04View job

Belden, Inc

Himalayas

Solution Consultant - Cybersecurity Practice (US)

Remote — United States (see country and timezone requirements)

$125,000.00 – $160,000.00 per yearfull timeRemote

Innovation Starts With YouPropel your career at Belden, where innovation creates possibilities—for our people, our customers, and the communities…

Listing expires 2026-12-04View job