parachutehealth

Lead Security & Compliance Analyst

Apply Now

At a Glance

Location
United States
Work Regime
remote
Experience
4+ years
Compensation
ased on experience and level) $80,000 - $130,000 California job applicants may
Posted
2026-07-29T17:05:46-04:00

Key Requirements

Required Skills

AWS

Certifications

  • CISA
  • CISM
  • CISSP

Domain Knowledge

  • Automation
  • Healthcare
  • Legal
  • Regulatory

Requirements

4+ years combined experience across security compliance/GRC and hands-on technical security

Direct experience supporting SOC 1/SOC 2 and/or HITRUST audits — you've been through at least one full audit cycle

Hands-on experience with vulnerability scanning and remediation, and comfort reading technical findings (CVEs, misconfigurations, cloud security issues)

Familiarity with AWS security concepts (IAM, security groups, logging, WAF)

Experience with compliance automation platforms (Drata, Vanta, or similar)

Experience with SIEM tools and log analysis

Compensation & Benefits

Medical, Dental, and Vision Coverage: Comprehensive plans with options for low-to-no-cost premiums.

Employer HSA Contribution: Company-funded contributions to your Health Savings Account.

401(k) Retirement Plan

Equity Incentive Plan

Annual Company-Wide Bonus: Opportunity for up to 15% bonus based on company performance.

Remote-First Culture: We are remote-first with a dedicated NYC office and reimbursement options for co-working spaces.

Responsibilities

This is a hybrid role: roughly half security compliance and audit, half hands-on technical security.

You'll own our compliance audit cycle end-to-end (SOC 1, SOC 2, HITRUST CSF, HITRUST AI), and you'll also work directly on the technical side: vulnerability management, security findings remediation, cloud security

reviews, and third-party risk.

Own SOC 1, SOC 2, HITRUST CSF, and HITRUST AI audits end-to-end: scoping, evidence collection, auditor coordination, and findings remediation

Develop, update, revise, and implement compliance policies, procedures, and practices for security frameworks (HIPAA, HITRUST, SOC) as well as general compliance and operations

Manage our compliance automation and trust platforms (Drata, SafeBase), including control monitoring and responses to customer security questionnaires.