Senior Compliance Analyst
Translates legal and regulatory requirements into product guidance, privacy operations, risk assessments, vendor oversight, and compliance controls. Requires at least four years of compliance experience, strong cross-functional project skills, and working knowledge of HIPAA, HITRUST, and U.S. privacy requirements.
About the job
Responsibilities
Product Compliance
- Serve as the Compliance partner for assigned product squads and initiatives.
- Review Product Requirement Documents (PRDs), features, and material product changes early in development.
- Translate Legal requirements and recommendations into actionable guidance for Product, Engineering, Design, and Operations.
- Assess compliance considerations for AI-enabled features, accessibility, data use, and emerging technologies.
- Document material assessments, decisions, remediation items, and escalations.
Privacy and Regulatory Operations
- Support implementation of HIPAA and applicable federal, state, and international privacy law requirements.
- Lead compliance projects from intake through completion across cross-functional teams.
- Monitor regulatory developments, coordinate interpretation with Legal, and operationalize resulting requirements.
- Support data mapping, retention, minimization, consent management, and de-identification initiatives.
- Assist with data subject rights requests, privacy controls, and customer-facing privacy documentation.
Risk, Assurance, and Vendor Oversight
- Conduct risk and compliance assessments and support remediation plans.
- Support HITRUST, PCI, ISO, and other audit or certification activities through evidence collection, control testing, documentation, and remediation tracking.
- Conduct compliance reviews of vendors and third parties, including data access, data use, integrations, and AI considerations.
- Maintain policies, procedures, checklists, and operational guidance.
Business and Customer Support
- Support compliance-related customer inquiries and escalations with Customer Support, Marketing, and Legal.
- Participate in compliance incident response, including documentation, tracking, and corrective actions.
- Develop internal privacy, AI, and compliance training and guidance.
- Help create customer-facing trust content.
- Track workflow performance, risks, SLAs, and program metrics; recommend process improvements and automation.
Requirements
- 4 years of prior compliance experience, preferably in healthcare technology or SaaS.
- Working knowledge of HIPAA, HITRUST, U.S. privacy law requirements, and product compliance practices.
- Experience partnering with Product, Engineering, Legal, Security, Marketing, or Customer Support teams.
- Ability to turn complex requirements into clear operational guidance.
- Strong judgment, writing, organization, and project-management skills.
- Bachelor’s degree or equivalent practical experience.
Nice-to-Haves
- Experience with AI governance, accessibility, vendor risk, incident response, 42 CFR Part 2, or ePrescribing.
- Experience supporting HITRUST, PCI, ISO, or similar assurance programs.
- IAPP, healthcare compliance, or comparable certification.
- Experience using AI tools, including large language models (LLMs), to operationalize compliance programs.
- Familiarity with privacy, procurement, training, and workflow-management tools.
Compensation and Benefits
- Base salary range: $113,600–$142,000 USD annually.
- Medical, dental, vision, life, and disability insurance.
- 401(k) plan with company match.
- Flexible Time Off, wellbeing days, paid holidays, and summer Fridays.
- Mental health resources.
- Paid parental leave and Backup Care.
- Tuition reimbursement.
- Employee Resource Groups (ERGs).
Skills
HIPAA, Hitrust, U.S. Privacy Law, Product Compliance, Ai Governance, Accessibility, Data Mapping, Consent Management, De-Identification, Vendor Risk, Incident Response, Pci Dss, Iso Standards, Iapp, LLMs
Similar jobs
Legal jobsSupports public-company legal operations, SEC reporting, securities compliance, corporate governance, board administration, and subsidiary management. The role requires substantial corporate-paralegal experience, hands-on SEC and EDGAR expertise, and hybrid work from San Francisco or Atlanta.
Leads governance, reporting, risk assessment, examination support, and remediation for BSA/AML and OFAC compliance programs. Requires at least five years of financial-crimes compliance experience, strong regulatory knowledge, and the ability to influence cross-functional stakeholders.
Leads the BSA/AML compliance program for lending and deposit products, advising cross-functional teams, developing risk-based controls, and managing regulatory, audit, and examination remediation. Requires 7+ years of financial institution compliance experience and strong knowledge of customer due diligence, sanctions, and transaction monitoring.
Supports regulatory and consumer litigation teams by processing civil third-party legal requests, assisting with litigation and arbitration matters, and managing deadlines across jurisdictions. Requires 5+ years of litigation paralegal experience and familiarity with legal technology.
Leads AML/BSA, KYC/KYB, fraud, transaction monitoring, and sanctions compliance programs while managing banking-partner relationships and regulatory readiness. Requires 5+ years of regulated-financial-services compliance experience and the ability to operationalize requirements across Legal, Product, Engineering, and Operations.