Director, Compliance
Job in
St. Louis, Saint Louis, St. Louis city, Missouri, 63105, USA
Listed on 2026-08-28
Listing for:
Brado AI
Full Time
position Listed on 2026-08-28
Job specializations:
-
IT/Tech
Information Security & Data Protection, Cybersecurity
Job Description & How to Apply Below
Description
Director, Compliance
Brado AI
Individual contributor, reporting to Chief Financial Officer
AboutThe Role
The Director of Compliance owns and advances Brado AI's compliance program as we scale. This person bridges regulatory rigor with practical business execution, serving as our subject-matter authority on HIPAA, HiTRUST, and SOC 2. They build a culture of compliance across every team, partner with leaders and employees on day-to-day compliance activities, and keep the organization in a constant state of audit readiness.
WhatYou'll DoProgram ownership & strategy
- Manage the end-to-end compliance program across for the company’s client offerings: HIPAA Privacy and Security Rules, SOC 2 (Type II), and HiTRUST CSF.
- Develop, maintain, and continuously improve policies, procedures, and controls to address evolving regulatory and contractual requirements.
- Own execution of the compliance roadmap set jointly with the VP, Legal & Compliance; support preparation of executive and board updates as needed. Includes evaluating a potential move to a single HiTRUST certification across both platforms, a decision still pending.
- Oversee development and ongoing maintenance of policies, guidelines, and systems for data privacy and security, working with domain experts to define and implement key controls.
- Own and maintain the legislative matrix: monitor federal and state regulatory changes and updates, and document where and how each change impacts the business and any actions required.
- Lead ISCC meetings.
- Lead and manage all external audits, assessments, and renewals — including the annual SOC 2 Type II engagement and the HiTRUST engagement — from scoping through report issuance.
- Coordinate with third‑party auditors and assessors.
- Continuously monitor compliance with privacy and security frameworks so the organization is always audit‑ready and in compliance.
- Manage and maintain Vanta as the system of record for continuous control monitoring and evidence collection.
- Conduct quarterly department‑level compliance audits on a rotating basis, in addition to company‑wide audits, to spread documentation and remediation work evenly across the year.
- Operate and mature the company's risk management framework, including regular risk assessments and risk register maintenance.
- Own the HIPAA Breach Notification process; lead investigations and coordinate required notifications to Covered Entities and vendors.
- Partner with Engineering and IT on vulnerability, patch management, and remediation prioritization.
- Serve as the point of contact for incident reporting and management, coordinating investigation and resolution with IT and Legal.
- Own disaster recovery and business continuity (DRBC) planning and execution, in partnership with IT.
- Work closely with sales and contract teams to support customer security and privacy questionnaires, enterprise procurement processes, and business associate agreement (BAA) review.
- Partner with HR to deliver workforce compliance training, including annual HIPAA, privacy, and security awareness programs.
- Advise Product and Engineering on privacy‑by‑design principles and secure development practices.
- Facilitate the compliance committee, including developing agendas, reports, and information as requested by the committee, senior leadership, and/or the Board of Directors.
- Offer coaching and mentorship for managers and employees throughout Brado AI on domain expertise.
- 7+ years of experience in health care regulatory compliance and compliance leadership, with a deep understanding of HIPAA, key transactional systems (e.g. EMR), and ancillary communication systems (e.g. CRM).
- Familiarity with the compliance and security expectations of health system and health payor clients in a B2B SaaS sales cycle, including vendor risk assessments and enterprise procurement review.
- Experience operating in a SaaS or cloud‑native environment (AWS or Azure).
- Bachelor's degree or equivalent experience.
- Willingness to complete all Brado AI and client‑required training on healthcare industry regulations, including HCP processes and reporting, ethics, confidentiality, data privacy and security, and harassment prevention.
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×