Lead Security & Compliance Analyst U.S. Remote
Philadelphia, Philadelphia County, Pennsylvania, 19117, USA
Listed on 2026-09-11
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations
Parachute Health is transforming post-acute care as the leading digital ordering platform for medical equipment and supplies. We connect major health systems, health plans, and suppliers to help patients get the life-saving products they need ce launching, we've connected 300,000+ clinicians and 3,000+ supplier locations across all 50 states and helped 15M+ patients. What started as a DME ePrescribing tool has become the order management platform of choice for home medical equipment.
Join our team and make a difference in patient care.
About the Role
This is a hybrid role: roughly half security compliance and audit, half hands-on technical security. You'll own our compliance audit cycle end-to-end (SOC 1, SOC 2, HITRUST CSF, HITRUST AI), and you'll also work directly on the technical side: vulnerability management, security findings remediation, cloud security reviews, and third-party risk.
Responsibilities
Compliance & Audit
- Own SOC 1, SOC 2, HITRUST CSF, and HITRUST AI audits end-to-end: scoping, evidence collection, auditor coordination, and findings remediation
- Develop, update, revise, and implement compliance policies, procedures, and practices for security frameworks (HIPAA, HITRUST, SOC) as well as general compliance and operations
- Manage our compliance automation and trust platforms (Drata, Safe Base), including control monitoring and responses to customer security questionnaires.
- Coordinate with external vendors and clients to gather information needed for compliance reviews, validations, and audits
- Run third-party/vendor risk assessments and respond to customer security assessments and external inquiries
- Deliver HIPAA and security awareness training and measure control effectiveness through internal audits
Technical Security
- Run the vulnerability management program: scanning, triage, prioritization, and driving remediation with engineering teams
- Investigate and remediate security findings across our AWS environment (EKS, WAF, Shield, Cloud Front, IAM) and SaaS stack
- Review external attack surface findings (e.g., Security Scorecard) and implement fixes from CSP headers to subresource integrity to TLS configuration
- Support security incident response: log analysis, forensic evidence collection, and containment
- Support fraud and forensic investigations authentication log analysis, targeted data extraction, and evidence preservation in support of legal and compliance matters
- Improve our security tooling and automate evidence collection, using scripting (Python, Bash) where manual work can be eliminated
What We're Looking For
- 4+ years combined experience across security compliance/GRC and hands-on technical security
- Direct experience supporting SOC 1/SOC 2 and/or HITRUST audits — you've been through at least one full audit cycle
- Working knowledge of HIPAA Security and Privacy requirements
- Hands-on experience with vulnerability scanning and remediation, and comfort reading technical findings (CVEs, misconfigurations, cloud security issues)
- Familiarity with AWS security concepts (IAM, security groups, logging, WAF)
- Ability to write clear policies and procedures and equally clear remediation tickets
Nice to Have
- Experience with compliance automation platforms (Drata, Vanta, or similar)
- Experience in healthcare or another regulated industry
- Certifications such as CISSP, CISA, CRISC, HITRUST CCSFP, or CISM
- Experience with SIEM tools and log analysis
- Experience with forensic log analysis, fraud investigations, or supporting legal/eDiscovery requests
- Medical, Dental, and Vision Coverage:
Comprehensive plans with options for low-to-no-cost premiums. - Employer HSA Contribution:
Company-funded contributions to your Health Savings Account. - 401(k) Retirement Plan
- Equity Incentive Plan
- Annual Company-Wide Bonus:
Opportunity…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).