
51 - 200 employees
Founded 2017
🏥 Healthcare
⚕️ Healthcare Insurance
💳 Fintech
Healthcare • Healthcare Insurance • Fintech
Collectly is a healthcare technology company that provides an AI-powered financial assistant designed to streamline the medical billing process for patients. The platform helps healthcare providers improve patient engagement by making it easier for them to understand and pay their medical bills, resulting in faster collections and better patient satisfaction. Collectly integrates with existing electronic health records and practice management systems, allowing healthcare organizations to enhance their billing processes without changing their current software solutions.
🔥 5 minutes ago
🇺🇸 United States – Remote
💵 $190k - $220k / year
⏰ Full Time
🟡 Mid-level
🟠 Senior
🚔 Compliance
👻 Ghost score 9%
Improve your chances of getting an interview by checking your resume score before you apply.

51 - 200 employees
Founded 2017
🏥 Healthcare
⚕️ Healthcare Insurance
💳 Fintech
Healthcare • Healthcare Insurance • Fintech
Collectly is a healthcare technology company that provides an AI-powered financial assistant designed to streamline the medical billing process for patients. The platform helps healthcare providers improve patient engagement by making it easier for them to understand and pay their medical bills, resulting in faster collections and better patient satisfaction. Collectly integrates with existing electronic health records and practice management systems, allowing healthcare organizations to enhance their billing processes without changing their current software solutions.
• Own security and compliance end to end as the sole person in the function • Build a scalable security and compliance program without adding unnecessary operational drag • Answer customer security questionnaires • Complete AI governance questionnaires and responsible-AI reviews for the AI patient billing agent • Lead live security calls with prospects’ InfoSec teams • Manage health-system procurement portals, including Archer, ProcessUnity, and Venminder • Manage annual customer reattestation cycles • Handle customer security escalations, incident communications, and customer-facing RCAs • Host customers exercising right-to-audit clauses • Distribute SOC 2, HITRUST certification, penetration-test summaries, and subprocessor notices under NDA • Create and maintain a public trust center, standard security package, and answer library • Own HITRUST i1 and SOC 2 Type 2 readiness, evidence, auditor management, and remediation tracking • Own PCI DSS SAQs, collect processor AOCs, and define scope for card-present and card-not-present flows • Conduct the annual HIPAA Security Risk Analysis and maintain the risk register • Manage the penetration-test lifecycle, including scheduling, scoping, remediation tracking, and customer-facing summaries • Conduct quarterly user access reviews • Coordinate BCP/DR tabletops and annual testing • Administer Vanta and security scanners • Pull evidence from CI, infrastructure-as-code, identity provider, EDR, and cloud configuration systems • Reduce manually evidenced controls annually • Manage BAAs, security exhibits, DPAs, and the subprocessor inventory • Conduct tiered vendor security reviews and annual vendor reattestation • Maintain policies; manage security awareness, HIPAA training, phishing simulations, and completion tracking • Own the incident response program, including runbooks, tabletops, and incident coordination • Manage breach-notification timelines and contractual notification windows • Maintain a documented exception process with approver, expiry date, and compensating control • Serve as HIPAA Privacy Officer • Track state privacy laws including CCPA/CPRA and Washington My Health My Data • Establish AI governance for the AI patient billing agent, including model inventory, human oversight, and monitoring • Track emerging state rules on AI in healthcare and AI-generated patient communications • Do not own remediation engineering; DevOps owns findings and fixes • Do not own shipping decisions; document risk and escalate while the CTO sets priorities • Do not serve as a gate in design or code review
• Extensive experience in security compliance or GRC, including time in healthcare SaaS or another PHI-handling environment • Has run SOC 2 and HITRUST as an owner, not a contributor • Deep HIPAA fluency: Security Rule, Privacy Rule, Breach Notification Rule, BAAs, minimum necessary • Hands-on with Vanta or a comparable compliance automation platform • Strong knowledge of security frameworks; ability to apply unfamiliar frameworks independently • Ability to work with NIST AI RMF and ISO 42001 • Ability to write final-draft customer-facing prose • Ability to follow technical conversations involving architecture diagrams, infrastructure-as-code, access control models, and cloud configuration • Ability to reason about threat models and assess exploitability, mitigations, applicability, and escalation needs • Software engineering or security engineering background is a strong plus, though not required • PCI DSS in a payments context is a plus • Recognized certifications include CIPP/US, HCISPP, CISSP, and HITRUST CCSFP • Ability to actively research information during the working-session exercise
• Unlimited PTO • Fully paid medical, dental, and vision insurance for you and your dependents • Stock options • 401(k) with a generous company match • Contributions toward student loans
Apply Now🔥 14 minutes ago
Privacy compliance analyst supporting Stryker’s global medical-device privacy program. Managing assessments, regulatory obligations, audits, and individual rights requests.
🇺🇸 United States – Remote
💵 $69.5k - $144.2k / year
⏰ Full Time
🟢 Junior
🟡 Mid-level
🚔 Compliance
🦅 H1B Visa Sponsor
🔥 7 hours ago
Compliance Associate supporting Medicare/ACA regulatory operations at Senior Market Sales. Managing investigations, audits, marketing approvals, training, and compliance reporting.
🇺🇸 United States – Remote
💰 $690M Debt Financing - Alliant Insurance Services on 2019-10
⏰ Full Time
🟢 Junior
🟡 Mid-level
🚔 Compliance
🔥 7 hours ago
Compliance Associate supporting Senior Market Sales’ Medicare/ACA insurance compliance operations. Managing investigations, audits, marketing approvals, training, regulatory monitoring, and corrective actions.
🇺🇸 United States – Remote
💰 $690M Debt Financing - Alliant Insurance Services on 2019-10
⏰ Full Time
🟢 Junior
🟡 Mid-level
🚔 Compliance
🔥 8 hours ago
Compliance Specialist supporting broker-dealer compliance programs and registered representative supervision. Conducting regulatory reviews, audits, AML monitoring, and client inquiries.
🔥 10 hours ago
Regulatory Representative managing Globalstar’s satellite communications compliance and licensing. Coordinating FCC, ITU, spectrum, export-control, and agency matters across global markets.