โ† back to jobs
> job detail
P
๐Ÿ‘ฝOther

Lead Security & Compliance Analyst

Parachute Health ยท U.S. Remote
// classified as
Other (Adjacent or hard to classify.)
posted
2d ago
location
U.S. Remote
languages
bash, python
tools
aws
> stack
bashpythonaws
> description
<div class="content-intro"><p>Parachute Health is transforming post-acute care as the leading digital ordering platform for medical equipment and supplies. We connect major health systems, health plans, and suppliers to help patients get the life-saving products they need at home. Since launching, we've connected 300,000+ clinicians and 3,000+ supplier locations across all 50 states and helped 15M+ patients. What started as a DME ePrescribing tool has become the order management platform of choice for home medical equipment.</p> <p>Join our team and make a difference in patient care.</p></div><p style="line-height: 1;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><strong>About the Role</strong></span></p> <p style="line-height: 1;"><span style="font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt;">This is a hybrid role: roughly half security compliance and audit, half hands-on technical security. You'll own our compliance audit cycle end-to-end (SOC 1, SOC 2, HITRUST CSF, HITRUST AI), and you'll also work directly on the technical side: vulnerability management, security findings remediation, cloud security </span><span style="font-size: 12pt;">reviews, and third-party risk.</span></span></p> <p style="line-height: 1;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><strong>Responsibilities</strong></span></p> <p style="line-height: 1;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><strong>Compliance &amp; Audi</strong>t</span></p> <ul> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Own SOC 1, SOC 2, HITRUST CSF, and HITRUST AI audits end-to-end: scoping, evidence collection, auditor coordination, and findings remediation</span></li> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Develop, update, revise, and implement compliance policies, procedures, and practices for security frameworks (HIPAA, HITRUST, SOC) as well as general compliance and operations</span></li> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Manage our compliance automation and trust platforms (Drata, SafeBase), including control monitoring and responses to customer security questionnaires.</span></li> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Coordinate with external vendors and clients to gather information needed for compliance reviews, validations, and audits</span></li> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Run third-party/vendor risk assessments and respond to customer security assessments and external inquiries</span></li> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Deliver HIPAA and security awareness training and measure control effectiveness through internal audits</span></li> </ul> <p style="line-height: 1;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><strong>Technical Security</strong></span></p> <ul> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Run the vulnerability management program: scanning, triage, prioritization, and driving remediation with engineering teams</span></li> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Investigate and remediate security findings across our AWS environment (EKS, WAF, Shield, CloudFront, IAM) and SaaS stack</span></li> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Review external attack surface findings (e.g., SecurityScorecard) and implement fixes from CSP headers to subresource integrity to TLS configuration</span></li> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Support security incident response: log analysis, forensic evidence collection, and containment</span></li> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Support fraud and forensic investigations authentication log analysis, targeted data extraction, and evidence preservation in support of legal and compliance matters</span></li> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Improve our security tooling and automate evidence collection, using scripting (Python, Bash) where manual work can be eliminated</span></li> </ul> <p style="line-height: 1;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><strong>What We're Looking For</strong></span></p> <ul> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">4+ years combined experience across security compliance/GRC and hands-on technical security</span></li> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">&nbsp;Direct experience supporting SOC 1/SOC 2 and/or HITRUST audits โ€” you've been through at least one full audit cycle</span></li> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Working knowledge of HIPAA Security and Privacy requirements</span></li> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Hands-on experience with vulnerability scanning and remediation, and comfort reading technical findings (CVEs, misconfigurations, cloud security issues)</span></li> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Familiarity with AWS security concepts (IAM, security groups, logging, WAF)</span></li> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Ability to write clear policies and procedures and equally clear remediation tickets</span></li> </ul> <p style="line-height: 1;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><strong>Nice to Have</strong></span></p> <ul> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Experience with compliance automation platforms (Drata, Vanta, or similar)</span></li> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Experience in healthcare or another regulated industry</span></li> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Certifications such as CISSP, CISA, CRISC, HITRUST CCSFP, or CISM</span></li> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Experience with SIEM tools and log analysis</span></li> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Experience with forensic log analysis, fraud investigations, or supporting legal/eDiscovery requests</span></li> </ul> <p style="line-height: 1;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><strong>Benefits</strong></span></p> <ul> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Medical, Dental, and Vision Coverage: Comprehensive plans with options for low-to-no-cost premiums.</span></li> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Employer HSA Contribution: Company-funded contributions to your Health Savings Account.</span></li> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">401(k) Retirement Plan</span></li> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Equity Incentive Plan</span></li> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Annual Company-Wide Bonus: Opportunity for up to 15% bonus based on company performance.</span></li> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Remote-First Culture: We are remote-first with a dedicated NYC office and reimbursement options for co-working spaces.</span></li> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Flexible Vacation Policy</span></li> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Summer Fridays: 5 additional Fridays off during the summer (separate from PTO).</span></li> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Home Office and Wellness Stipend</span></li> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Monthly Internet Stipend</span></li> <li style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">Annual Learning and Development Stipend</span></li> </ul> <p style="line-height: 1;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;"><strong>Base Salary Band (based on experience and level)</strong></span></p> <p style="line-height: 1;"><span style="font-size: 12pt; font-family: helvetica, arial, sans-serif;">$80,000 - $130,000</span></p><div class="content-conclusion"><p style="text-align: left;"><span style="font-size: 12pt;"><em>California job applicants may access the Notice of Collection of Personal Information and Privacy Policy with information and rights required by the California Privacy Rights Act (CPRA) the link&nbsp;<a class="c-link" href="https://www.parachutehealth.com/cpra" target="_blank" data-stringify-link="https://www.parachutehealth.com/cpra" data-sk="tooltip_parent">here</a>.</em></span></p> <p class="p1" style="text-align: left;"><span style="font-size: 12pt;"><em>We are proud to be an equal opportunity employer that does not discriminate on the basis of actual or perceived race, color, creed, religion, national origin, ancestry, citizenship status, age, sex or gender (including pregnancy, childbirth related medical conditions and lactation), gender identity or gender expression (including transgender status), sexual orientation, marital status, military service and veteran status, disability, genetic information, or any other characteristic protected by applicable federal, state, or local laws and ordinances.</em></span></p> <p class="p1" style="text-align: left;"><span style="font-size: 12pt;"><strong><em>This role is not eligible for employer visa sponsorship. Applicants must be legally authorized to work in the United States at the time of application and for the duration of employment. The Company does not sponsor employment authorization for this position.</em></strong></span></p> <p>&nbsp;</p></div>