parachutehealth
Lead Security & Compliance Analyst
At a Glance
- Location
- United States
- Work Regime
- remote
- Experience
- 4+ years
- Compensation
- ased on experience and level) $80,000 - $130,000 California job applicants may
- Posted
- 2026-07-29T17:05:46-04:00
Key Requirements
Required Skills
Certifications
- CISA
- CISM
- CISSP
Domain Knowledge
- Automation
- Healthcare
- Legal
- Regulatory
Requirements
4+ years combined experience across security compliance/GRC and hands-on technical security
Direct experience supporting SOC 1/SOC 2 and/or HITRUST audits — you've been through at least one full audit cycle
Hands-on experience with vulnerability scanning and remediation, and comfort reading technical findings (CVEs, misconfigurations, cloud security issues)
Familiarity with AWS security concepts (IAM, security groups, logging, WAF)
Experience with compliance automation platforms (Drata, Vanta, or similar)
Experience with SIEM tools and log analysis
Compensation & Benefits
Medical, Dental, and Vision Coverage: Comprehensive plans with options for low-to-no-cost premiums.
Employer HSA Contribution: Company-funded contributions to your Health Savings Account.
401(k) Retirement Plan
Equity Incentive Plan
Annual Company-Wide Bonus: Opportunity for up to 15% bonus based on company performance.
Remote-First Culture: We are remote-first with a dedicated NYC office and reimbursement options for co-working spaces.
Responsibilities
This is a hybrid role: roughly half security compliance and audit, half hands-on technical security.
You'll own our compliance audit cycle end-to-end (SOC 1, SOC 2, HITRUST CSF, HITRUST AI), and you'll also work directly on the technical side: vulnerability management, security findings remediation, cloud security
reviews, and third-party risk.
Own SOC 1, SOC 2, HITRUST CSF, and HITRUST AI audits end-to-end: scoping, evidence collection, auditor coordination, and findings remediation
Develop, update, revise, and implement compliance policies, procedures, and practices for security frameworks (HIPAA, HITRUST, SOC) as well as general compliance and operations
Manage our compliance automation and trust platforms (Drata, SafeBase), including control monitoring and responses to customer security questionnaires.