×
Register Here to Apply for Jobs or Post Jobs. X

Security & Compliance Manager; GRC)

Job in Chicago, Cook County, Illinois, 60290, USA
Listing for: Collectlyinc
Full Time position
Listed on 2026-10-02
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 190000 - 220000 USD Yearly USD 190000.00 220000.00 YEAR
Job Description & How to Apply Below
Position: Security & Compliance Manager (GRC), US-based

About Collectly

Collectly is a patient billing and payments platform for US healthcare providers. We handle protected health information and card payments at scale, integrate directly with major EHRs, and sell to health systems and large provider organizations buyers with real security programs and real diligence processes. We're HITRUST i1 Validated and SOC 2 Type 2.

The role

You'll own security and compliance end to end. Today it's split between the CTO and whichever engineer happens to be nearest. You'll take all of it.

You'll be the only person in this function, so the job is to build a program that scales without adding drag. Automate the evidence, delete the controls nobody can trace to a requirement, and answer the hard customer questions yourself instead of routing them to engineering.

Customer-facing security and compliance

The largest part of the job.

  • Answering customers’ security questionnaires
  • AI governance questionnaires and responsible-AI reviews covering our AI patient billing agent
  • Live security calls with prospects' Info Sec teams — technical conversations, not slide reading
  • Health-system procurement portals (Archer, Process Unity, Venminder and similar)
  • Annual customer reattestation cycles
  • Customer security escalations, incident communications, and customer-facing RCAs
  • Hosting customers who exercise right-to-audit clauses
  • Distribution of SOC 2, HITRUST certification, pen test summaries, and subprocessor notices under NDA
  • A public trust center, standard security package, and answer library — so most of the above becomes a lookup rather than a project
Audits and certifications
  • HITRUST i1 and SOC 2 Type 2, end to end: readiness, evidence, auditor management, remediation tracking
  • PCI DSS: SAQ ownership, AOC collection from processors, scope definition for card-present and card-not-present flows
  • Annual HIPAA Security Risk Analysis and risk register
  • Pen test lifecycle: scheduling, scoping, remediation tracking, customer-facing summary
  • Quarterly user access reviews
  • BCP/DR tabletops and annual test coordination
Compliance tooling
  • Own Vanta and our security scanners as an administrator
  • Pull evidence from systems — CI, infrastructure-as-code, identity provider, EDR, cloud config — instead of collecting screenshots
  • Reduce the count of manually evidenced controls every year
Contracts, BAAs, and vendor risk
  • BAAs in both directions, customer and subcontractor, from template through negotiation
  • Security exhibits, DPAs, subprocessor inventory
  • Tiered vendor security review, so a no-PHI vendor gets a one-page checklist and a same-day answer
  • Annual vendor reattestation
Policies, training, and incident response
  • Own and maintain the policy set
  • Security awareness and HIPAA training, phishing simulations, completion tracking
  • Own the incident response program: runbooks, tabletops, coordination during an incident
  • Breach notification clock management — the HIPAA window, state AG requirements, cyber insurance notice, and the per-contract customer notification windows in our MSAs
  • A documented exception process with a named approver, expiry date, and compensating control
Privacy and AI governance
  • HIPAA Privacy Officer designation
  • State privacy law tracking: CCPA/CPRA, Washington My Health My Data, and what follows
  • Stand up a durable AI governance framework for our AI patient billing agent — model inventory, human oversight, monitoring — replacing today's per-customer, from-scratch approach
  • Track emerging state rules on AI in healthcare and AI-generated patient communications
  • Remediation engineering. Findings and fixes belong to Dev Ops. You own the SLA dashboard and the escalation path.
  • Shipping decisions. You document risk and elevate. The CTO decides on the priority.
  • A seat as a gate in design or code review.
  • Extensive experience in…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary