Lead Security & Compliance Analyst

Job not on LinkedIn

🔥 1 minute ago

🇺🇸 United States – Remote

💵 $80k - $130k / year

⏰ Full Time

🟠 Senior

🔐 Security Analyst

🦅 H1B Visa Sponsor

info
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Parachute Health

Parachute Health

201 - 500 employees

Founded 2015

💼 Consulting

📦 Logistics

🏥 Healthcare

Consulting • Logistics • Healthcare

Parachute Health is a healthcare technology company that provides a SaaS platform for digitizing and streamlining Durable Medical Equipment (DME) ordering and ePrescribing. Its platform connects clinicians, DME/HME suppliers, and payors to accelerate order entry, automate intake (including AI-based fax digitization), integrate with EHRs and ERPs, and improve order accuracy and compliance. Parachute emphasizes security and regulatory compliance (HIPAA, SOC 1/2, HITRUST) while serving B2B healthcare customers across the care continuum.

📋 Description

• Own SOC 1, SOC 2, HITRUST CSF, and HITRUST AI audits end-to-end: scoping, evidence collection, auditor coordination, and findings remediation • Develop, update, revise, and implement compliance policies, procedures, and practices for security frameworks (HIPAA, HITRUST, SOC) as well as general compliance and operations • Manage our compliance automation and trust platforms (Drata, SafeBase), including control monitoring and responses to customer security questionnaires. • Coordinate with external vendors and clients to gather information needed for compliance reviews, validations, and audits • Run third-party/vendor risk assessments and respond to customer security assessments and external inquiries • Deliver HIPAA and security awareness training and measure control effectiveness through internal audits • Run the vulnerability management program: scanning, triage, prioritization, and driving remediation with engineering teams • Investigate and remediate security findings across our AWS environment (EKS, WAF, Shield, CloudFront, IAM) and SaaS stack • Review external attack surface findings (e.g., SecurityScorecard) and implement fixes from CSP headers to subresource integrity to TLS configuration • Support security incident response: log analysis, forensic evidence collection, and containment • Support fraud and forensic investigations authentication log analysis, targeted data extraction, and evidence preservation in support of legal and compliance matters • Improve our security tooling and automate evidence collection, using scripting (Python, Bash) where manual work can be eliminated

🎯 Requirements

• 4+ years combined experience across security compliance/GRC and hands-on technical security • Direct experience supporting SOC 1/SOC 2 and/or HITRUST audits — you've been through at least one full audit cycle • Working knowledge of HIPAA Security and Privacy requirements • Hands-on experience with vulnerability scanning and remediation, and comfort reading technical findings (CVEs, misconfigurations, cloud security issues) • Familiarity with AWS security concepts (IAM, security groups, logging, WAF) • Ability to write clear policies and procedures and equally clear remediation tickets.

🏖️ Benefits

• Medical, Dental, and Vision Coverage: Comprehensive plans with options for low-to-no-cost premiums. • Employer HSA Contribution: Company-funded contributions to your Health Savings Account. • 401(k) Retirement Plan • Equity Incentive Plan • Annual Company-Wide Bonus: Opportunity for up to 15% bonus based on company performance. • Remote-First Culture: We are remote-first with a dedicated NYC office and reimbursement options for co-working spaces. • Flexible Vacation Policy • Summer Fridays: 5 additional Fridays off during the summer (separate from PTO). • Home Office and Wellness Stipend • Monthly Internet Stipend • Annual Learning and Development Stipend

Apply Now

Similar Jobs

🔥 5 minutes ago

Digit7

201 - 500

🛒 Retail

Tier 3 Security Analyst leading investigations of malicious activities for a security company. Collaborating with teams and mentoring junior analysts while maintaining focus on providing customer security outcomes.

🔥 3 hours ago

WVU Online

1001 - 5000

📚 Education

👥 B2C

🛍️ eCommerce

Remote Information Security Analyst maintaining and securing WVU’s IT environment. Supporting security operations, collaborating on security assessments, and responding to incidents.

🔥 3 hours ago

WVU Online

1001 - 5000

📚 Education

👥 B2C

🛍️ eCommerce

Remote Information Security Analyst at West Virginia University working on information security program. Ensuring security of IT environment and responding to incidents with a focus on continuous improvement.

🔥 16 hours ago

Presidio

1001 - 5000

💼 Consulting

📦 Logistics

🤖 Artificial Intelligence

Manage security documentation and compliance initiatives supporting SLED customers. Develop and maintain security frameworks, policies, and various compliance documentation.

🔥 17 hours ago

Presidio

1001 - 5000

💼 Consulting

🏥 Healthcare

📦 Logistics

Managing security compliance and documentation for State, Local, Education, and Government customers at Presidio. Leading development of security architecture and governance frameworks.