Compliance Specialist
Keep our SOC 2 real, answer every customer's security review, and make our reports the ones auditors expect.
Why this role exists
We sell to hospitals, so we are audited before we are trusted. We completed a SOC 2 Type II across security, availability and confidentiality, and qualified prospects review it under NDA as part of their vendor diligence. Keeping that true every month, answering every questionnaire quickly and honestly, and shaping the compliance reporting our product generates for customers is a full-time job, and it is currently split across three people who have other jobs.
What you'll be doing
- Own our controls. Evidence collection, the annual audit, the controls that live in code and the ones that live in process, and the drift between them.
- Run customer security reviews. Questionnaires, BAAs, the NDA process for sharing our report, and the follow-up questions from a hospital's risk team.
- Be the domain expert behind the product's compliance packs: what a HIPAA, HITRUST or SOC 2 reviewer actually wants to see, in the order they want to see it.
- Keep our policies short, true and current. If a policy describes something we do not do, you fix one or the other.
- Work with the infrastructure and security teams so that "we have a control for that" means there is a test for it.
How we work
We are a small team and we would rather have twelve controls we can prove than sixty we cannot. We write things down and we keep them short. We are remote-first with a few hours of overlap with Tel Aviv.
What we need from you
- You have carried an organisation through a SOC 2 or ISO 27001 audit, not only participated in one.
- You know HIPAA well enough to tell a prospect what a BAA does and does not cover.
- You can read a technical control description and tell whether the evidence supports it.
- You are comfortable telling a salesperson no.
How hiring works
Apply with the form on this page; a resume and a few lines on why this role are enough. If it looks like a fit, you talk to the hiring manager, then spend a paid working session on a real problem from our backlog, then meet one of the founders. We tell you where you stand at each step, and the whole process takes two to three weeks.