Leads AKASA’s healthcare compliance and AI governance programs, owning HITRUST, SOC 2, HIPAA, audit readiness, policy management, and customer trust activities. The role requires 8+ years in security compliance, GRC, or risk management and hands-on experience with automation and emerging AI governance frameworks.
150k – 185k/yr
Hybrid8+ YOELegal
About the role
Responsibilities
Own AKASA’s compliance certification portfolio end to end, including HITRUST CSF, SOC 2 Type II, and HIPAA, from control design and implementation through evidence collection, audit coordination, and remediation.
Evaluate and pursue certifications and attestations such as ISO 27001, ISO 42001, and HITRUST AI.
Define compliance roadmaps and drive organization-wide adoption of regulatory requirements.
Build an AI governance program grounded in the NIST AI Risk Management Framework (AI RMF), including model risk assessments, AI use policies, and documentation.
Implement and optimize GRC and continuous control-monitoring tools, automate evidence collection, and use AI tools to streamline policy drafting, control mapping, and audit preparation.
Own the policy lifecycle, including authoring, review cadences, exception handling, attestation campaigns, version control, and framework mapping.
Lead security and compliance questionnaire responses, support enterprise sales cycles, manage customer audits, and maintain BAAs, the trust center, and shared assessments.
Oversee vendor and third-party risk management, annual risk assessments, security awareness and HIPAA training, incident-response documentation, and tabletop exercises.
Partner with Legal and Security leadership on security-related contractual obligations.
Requirements
8+ years of experience in security compliance, GRC, or risk management, including 2+ years leading a team or function.
Healthcare SaaS, health tech, or AI startup experience strongly preferred.
Hands-on expertise with HITRUST CSF, SOC 2 Type II, HIPAA Security and Privacy Rules, and AI governance frameworks such as NIST AI RMF.
Experience managing certification and audit cycles from start to finish and translating AI governance standards into controls for systems handling PHI.
Experience with GRC and continuous control-monitoring platforms such as Vanta, Drata, or Hyperproof; evidence-collection automation; and AI tools such as ChatGPT or Claude.
Experience drafting policies, mapping them across frameworks, and managing review, exception, and attestation cycles.
Comfortable handling enterprise security questionnaires, sales-cycle support, BAA and security-term negotiations with Legal, and customer audits.
Nice-to-Haves
Experience achieving or maintaining ISO 27001, ISO 42001, or HITRUST AI certifications.
Familiarity with Okta, Kandji/Iru, SentinelOne, Nightfall, and AWS.
Experience with CCPA/CPRA, state health data laws, or GDPR.
Experience implementing compliance automation tools and trust centers such as Drata or Vanta.
Scripting or low-code automation skills using Python, Zapier, or Tray.io.
Certifications such as CISSP, CISA, CIPP/US, HCISPP, or HITRUST CCSFP.
Benefits
Flexible paid time off.
Health, dental, and vision coverage.
Employer contribution to Health Savings Accounts.
Generous parental leave.
Company-paid life insurance.
Home office stipend.
Cell phone and internet reimbursement.
Commuting benefits.
Company-paid holidays.
401(k) plan.
Equity.
Compensation
$150,000–$185,000 annual salary plus equity.
Skills
hitrust csfSOC 2HIPAAnist ai rmfISO 27001iso 42001GRCvantadrataAWSOktaPythoncisacisspGDPR
Manager/Director of Legal Operations & Commercial Finance
LirioUnited States
Hybrid legal operations and commercial finance role bridging Legal, Sales, and Finance. Own CLM systems, contract workflows, deal structuring, financial modeling, and outside counsel management for a health tech SaaS company.
150k – 180k/yrRemote5+ YOELegal
Director of Government Affairs
Applied IntuitionWashington, DC
Lead federal legislative strategy and government relations for autonomy and AI in defense. Build Congressional relationships, draft policy positions, and shape legislation on emerging technologies.
150k – 250k/yrOn-site5+ YOELegal
Head of Policy and Regulatory Affairs – US
EllipticNew York, NY +1
Lead US policy and regulatory engagement strategy for a crypto compliance firm. Shape federal/state digital asset frameworks and advise clients and internal teams on regulatory strategy.
155k – 290k/yrHybrid10+ YOELegal
Director, AML
Clear StreetNew York, NY
Leads and enhances the firm’s anti-money laundering program for broker-dealer and FCM businesses, handling complex KYC, EDD, monitoring, and SAR matters. Requires a bachelor’s degree and 7–10 years of relevant AML or financial crimes experience.
160k – 215k/yrOn-site8+ YOELegal
Head of Legal
AgentSyncDenver, CO
Head of Legal responsible for building legal strategy, advising on commercial and transactional agreements, and providing risk-mitigation counsel to go-to-market and product teams at a high-growth SaaS company. Requires JD, bar membership, 6+ years legal experience including 2+ years in-house at a SaaS firm.