ApplySarthi

Manager of Security and Compliance

Jobgether

Tailor my CV for this job, freeView job and applyYour CV rewritten for this role, from your real experience. Sign in with Google, nothing to install.

Got this interview? Our apps help you get the job.

Skills named in this job

Read from the description itself, not inferred.

This role on the market

1,066 open compliance roles across 220 companies are on ApplySarthi right now, most of them in Bengaluru (82), Hyderabad (35), Mumbai (13).

What compliance roles keep asking for: Stakeholder management (16%), Excel (13%) — counted across their open postings here.

Azure jobs · IAM jobs · Kubernetes jobs · SaaS jobs

Jobgether has 3,788 open roles listed here.

Counted across 14 company job boards, updated as roles open and close.

Preparing for this interview

Interviews for compliance roles keep coming back to Stakeholder management, Excel. Practise those questions before you sit with Jobgether.

Questions you are likely to be asked

  1. Why do you want to join Jobgether?
  2. What is your experience with SaaS? Tell me one thing you learned the hard way.
  3. How would you cut the cloud bill of a system without hurting it?
  4. How do you keep secrets and access safe in your infrastructure?
  5. Walk me through how code gets from a commit to production where you work.

Prep Sarthi gives you a free mock interview: an AI interviewer asks you questions like these out loud, from your own CV and this job, and shows your score and your weakest answer.

Practise the Manager of Security and Compliance at Jobgether interview free →

Accountabilities: Own and continuously mature security, privacy, and compliance programs covering HIPAA, SOC 2, HITRUST, and applicable healthcare privacy requirements. Lead HITRUST certification end to end, including scoping, readiness assessments, evidence collection, assessor coordination, remediation, and corrective action plans. Manage internal and external audits, risk assessments, penetration tests, security reviews, evidence collection, and remediation activities. Build a path toward continuous, system-generated compliance rather than relying primarily on point-in-time evidence collection. Manage external security and compliance partners, including advisors, assessors, and penetration-testing providers, ensuring clear scopes, priorities, accountability, and remediation ownership. Maintain the security and compliance roadmap, ensuring vulnerabilities, risks, audit findings, and control gaps have defined owners and resolution plans. Partner with Engineering, Product, Platform, SRE, and IT to integrate security into architecture, infrastructure, product development, and the software development lifecycle. Establish security and PHI-handling standards and guardrails, including considerations for AI-assisted development. Oversee critical controls including identity and access management, logging and monitoring, encryption, vulnerability management, data retention, data protection, and vendor risk. Lead security incident response, including investigation, stakeholder communication, post-incident reviews, and corrective actions within a unified incident-management framework. Maintain security policies, procedures, Business Associate Agreements, data-handling requirements, and breach-response plans. Serve as the operational lead for HIPAA Security Rule obligations while supporting the designated HIPAA Security Official and collaborating with the Privacy Officer. Support customer security reviews, due diligence, onboarding, and security and privacy requirements during contract negotiations. Establish security and compliance metrics that provide leadership with clear visibility into risks, incidents, vulnerabilities, remediation progress, and audit readiness. Lead security awareness and compliance training while managing, developing, and mentoring the security and compliance team. Requirements 7+ years of experience in information security, healthcare compliance, privacy, risk management, or a closely related discipline, preferably within healthcare SaaS or health technology. Strong working knowledge of HIPAA, SOC 2, HITRUST, healthcare privacy requirements, and security control frameworks. Demonstrated experience leading audits, risk assessments, compliance programs, remediation initiatives, and external security or compliance partners. Proven experience serving as the accountable owner for at least one HITRUST certification, either i1 or r2, from scoping through evidence collection, assessor management, and corrective action planning. Practical knowledge of cloud and SaaS security, identity and access management, vulnerability management, encryption, logging, data protection, and incident response. Experience partnering with Engineering and Product teams to integrate security into technology architecture and development processes. Experience with vendor risk management and third-party security assessments. Strong communication skills, with the ability to translate technical, regulatory, and security requirements for both technical and non-technical stakeholders. Experience working with healthcare technology, electronic medical records, clinical systems, or sensitive healthcare data environments. Experience in PACE, value-based care, Medicare/Medicaid, or other regulated healthcare environments is a plus. Experience building or scaling security and compliance programs within a growing SaaS organization is preferred. Familiarity with cloud-native environments, particularly Azure and Kubernetes/AKS, as well as DevSecOps and security automation, is advantageous. Experience leading a small security/compliance team or cross-functional security initiatives is a plus. Relevant certifications such as CCSFP, CISSP, CISM, or HCISPP are preferred. Strong organizational skills, sound judgment, ownership, and the ability to operate effectively in a growing and evolving environment are essential. This is a fully remote role for candidates based in the United States and is not eligible for sponsorship. Benefits Base salary range of $130,000–$150,000 , with final compensation determined by experience, skills, and organizational needs. Fully remote position within the United States. Opportunity to lead and mature security, privacy, and compliance programs within a growing healthcare technology organization. High-impact role with significant cross-functional exposure across Engineering, Product, SRE, IT, Legal, and customer-facing teams. Opportunity to lead HITRUST certification and build scalable, proactive security and compliance capabilities. Meaningful leadership responsibility, including team development and mentorship. Opportunity to influence security architecture, compliance automation, incident management, and organizational risk strategy.

Match this job to your CV

ApplySarthi scores your CV against this role, shows the skills you are missing, and writes a tailored version for the application.

Check my match →

Similar open roles

Need answers during your interview? Try Live Sarthi.

Live Sarthi, an Interview Sarthi app, shows answer suggestions during the call.

Try Live Sarthi free →

A Windows app, from the same team as ApplySarthi.

Listed on lever · posted 2026-10-06. ApplySarthi collects openings and links to application pages; the role is advertised by Jobgether, not by us.