Skip to content
ZocdocZocdoc

Senior Associate, Compliance

Supports healthcare compliance audits and assessments by coordinating control owners, gathering and validating evidence, preparing auditor deliverables, and tracking remediation. Requires 4–7 years of audit, compliance, security, privacy, or risk experience and familiarity with frameworks such as HITRUST, SOC 2, and HIPAA.

About the job

Responsibilities

  • Support HITRUST, SOC 2, HIPAA-related, and other compliance audits and assessments from planning through completion.
  • Review audit criteria, control requirements, prior-year findings, and auditor requests to identify required evidence and stakeholder inputs.
  • Coordinate evidence collection with control owners across Information Security, Engineering, Infrastructure, Product, Legal, People, Finance, and other business teams.
  • Gather, organize, track, and quality-check evidence for completeness, currency, relevance, and accurate control mapping.
  • Prepare evidence packages, control narratives, management responses, and supporting documentation for auditors.
  • Manage audit request lists, project plans, deadlines, status reporting, action-item logs, and escalation paths.
  • Identify evidence gaps and improve control documentation, ownership, consistency, and repeatability.
  • Support auditor meetings, walkthroughs, interviews, follow-up questions, and additional information requests.
  • Track observations, exceptions, and remediation commitments through resolution and validate closure evidence.
  • Help build scalable audit operations using standardized repositories, reusable narratives, calendars, templates, automation, and reporting.
  • Maintain compliance program documentation and contribute to reporting on audit readiness, open gaps, and program health.

Requirements

  • 4–7 years of experience in IT audit, compliance, information security, privacy, risk management, internal controls, or a related field.
  • Familiarity with compliance frameworks, control testing, audit evidence, and security and privacy requirements.
  • Exposure to HITRUST, SOC 2, HIPAA, NIST, ISO 27001, or similar frameworks and assessment processes.
  • Experience gathering and reviewing policies, procedures, tickets, access reviews, training records, system configurations, logs, reports, and meeting artifacts.
  • Strong project management, written communication, verbal communication, documentation, follow-up, and quality-assurance skills.
  • Comfort using spreadsheets, ticketing systems, shared documentation platforms, GRC tools, and other audit-management systems.
  • Ability to identify process gaps, recommend practical improvements, work independently, and collaborate with technical and non-technical stakeholders.
  • Bachelor’s degree in accounting, information systems, cybersecurity, business, or a related field preferred.

Nice-to-haves

  • CISA, CIA, CRISC, Security+, or another relevant certification.

Benefits

  • Competitive compensation package with medical insurance.
  • Catered lunches and additional workplace perks.
  • Daycare reimbursement.
  • Cellphone and Wi-Fi reimbursement.
  • Competitive parental leave.
  • Sabbatical leave after five years.
  • Annual sponsored health check-ups.

Skills

Hitrust, SOC 2, HIPAA, Nist, ISO 27001, Control Testing, Audit Evidence, Grc Tools, Project Management, Risk Management, Information Security, Privacy, Cisa, Crisc, Security+

Similar jobs

Legal jobs
Alpaca

Alpaca

Remote

Senior Manager of Compliance
No salary listedRemote7+ YOELegal

Supports the Chief Compliance Officer by overseeing regulatory compliance across business lines, maintaining policies and controls, reviewing communications, and coordinating examinations and filings. Requires 7+ years of broker-dealer compliance experience, strong FINRA/SEC knowledge, and Series 7 and 24 licenses.

Stripe

Stripe

Bengaluru, India

Contracting Operations Specialist
No salary listedOn-site4+ YOELegal

Manages supplier contracting requests from intake and contract preparation through negotiation, legal review, and lifecycle completion. Requires 4–5 years of contract lifecycle experience, a law or related degree, strong contract analysis, stakeholder management, and operational improvement skills.

OpenLoop

OpenLoop

Remote

Healthcare Investigations Manager
No salary listedRemoteLegal

Owns the healthcare compliance hotline investigation function, including intake, triage, HIPAA and security investigations, remediation, exclusion screening, self-disclosures, reporting, and platform administration. The role manages a small team while partnering with Legal, Compliance, IT Security, and Operations.

Alpaca

Alpaca

India

AML Compliance Analyst
No salary listedRemote3+ YOELegal

Investigates suspicious activity and supports AML, sanctions, anti-fraud, and securities-surveillance programs for a U.S.-focused financial services business. The role requires 3–5 years of financial-crime investigation experience, strong U.S. regulatory knowledge, and overlap with U.S. Eastern Time.

Coinbase

Coinbase

Hyderabad, India

Screening Analyst II
₹998k+/yrOn-site2+ YOELegal

Conduct end-to-end customer and entity screening, analyze KYC and transaction information, document findings, and escalate financial crime risks. The role requires at least two years of compliance, KYC/CDD, financial crime prevention, or investigations experience and flexibility for shift work.