Back to all jobs
rater8 logo

Senior Security and Compliance Lead

rater8
United StatesRemote21h ago
Seniority
Lead

About the role

<div class="content-intro"><p>Join rater8, voted a Great Place to Work™ by its employees since 2022!</p></div><p>The Senior Security and Compliance Lead owns the strategy, execution, and continuous improvement of the organization's information security and regulatory compliance programs. This leader is accountable for protecting the company, customer, and employee data; maintaining the organization's security posture across cloud environments; and ensuring that the business meets its legal, contractual, and industry-standard obligations.</p> <p>The role combines hands-on technical leadership with executive-level program management. The Lead builds and leads the security and compliance function, partners across Engineering, Product, and Operations, and reports to the CTO.</p> <p>Responsible for establishing and maintaining the organization's IT governance framework, risk management methodologies, and cybersecurity compliance programs. Develops enterprise policies and control frameworks while ensuring alignment with regulatory requirements and security standards such as ISO 27001, SOC 2, NIST, and HISTRUST. Conducts risk assessments, manages third-party risk evaluations, and facilitates cybersecurity audits. Creates and maintains security policies, develops security awareness training programs, and serves as the liaison between business, IT, and regulatory bodies to translate compliance requirements into actionable governance strategies.</p> <p><span style="font-size: 12pt;"><strong><em>What you’ll do</em></strong></span></p> <h3><span style="font-size: 10pt;"><strong>Security Strategy &amp; Leadership</strong></span></h3> <ul> <li>Define and own the multi-year information security strategy and roadmap aligned to business objectives.</li> <li>Build, mentor, and lead the security and compliance team, including security engineers, analysts, and GRC (governance, risk management, and compliance) staff.</li> <li>Establish and report on security KPIs, KRIs, and program maturity metrics.</li> <li>Manage the security and compliance budget, vendor relationships, and tooling investments.</li> </ul> <h3><span style="font-size: 10pt;"><strong>Governance, Risk &amp; Compliance (GRC)</strong></span></h3> <ul> <li>Own the enterprise risk management program: identify, assess, prioritize, and track remediation of security risks.</li> <li>Lead audit readiness and certification efforts (e.g., SOC 2 Type II, ISO 27001, HIPAA, HITRUST, GDPR, CCPA).</li> <li>Develop, maintain, and enforce security policies, standards, and procedures.</li> <li>Manage relationships with external auditors, assessors, and regulators; coordinate evidence collection and remediation.</li> <li>Oversee third-party and vendor risk management and customer security questionnaire responses.</li> <li>Partner with other functions on data privacy obligations, breach notification readiness, and cross-functional compliance matters.</li> </ul> <h3><span style="font-size: 10pt;"><strong>Security Operations &amp; Engineering</strong></span></h3> <ul> <li>Direct security operations, including monitoring, detection, vulnerability management, and patching.</li> <li>Own the incident response program — preparation, detection, containment, eradication, recovery, and post-incident review.</li> <li>Oversee identity and access management, encryption, network security, and cloud security posture management.</li> <li>Champion "security by design" and shift-left practices within the software development lifecycle.</li> <li>Lead business continuity and disaster recovery planning, testing, and continuous improvement.</li> </ul> <h3><span style="font-size: 10pt;"><strong>Awareness &amp; Culture</strong></span></h3> <ul> <li>Design and administer security awareness, training, and phishing simulation programs across the organization.</li> <li>Foster a “security is everyone’s responsibility” culture — serve as the internal champion and go-to escalation point for security matters.</li> <li>Act as a calm, credible communicator during security events, translating technical risk into clear business language for executives, customers, and the board.</li> <li>Other Duties as Assigned</li> </ul> <h4><span style="font-size: 12pt;"><strong><em>What you’ll bring</em></strong></span></h4> <ul> <li>5+ years in cybersecurity with demonstrated program ownership. You’ve driven initiatives end-to-end, influenced without authority, and been accountable for outcomes, whether or not you carried a management title.</li> <li>Familiar with and can demonstrate knowledge and ownership of regulatory compliance, such as SOC 2, HIPAA, HITRUST, GDPR.</li> <li>Strong working knowledge of cloud security (Azure, AWS, or GCP), IAM, network security, encryption, and secure SDLC.</li> <li>Proven track record leading incident response and managing breaches end-to-end including communication with executives and external stakeholders.</li> <li>Experience building and leading teams and managing cross-functional security initiatives</li> <li>Ability to translate technical risk into business terms for executives, the board, and customers.</li> <li>Bachelor's degree in Computer Science, Information Security, or equivalent practical experience.</li> <li>US Residents only. Must reside in the continental U.S., be authorized to work without sponsorship, and not reside in California.</li> </ul> <h4><span style="font-size: 12pt;"><strong><em>Additional Preferred Qualifications</em></strong></span></h4> <ul> <li>Nice to have one or more of the following certifications or equivalent: CISSP, CISM, CCSP, CISA, ISO 27001 Lead Auditor/Implementer, Cloud security certs (AZ-500 / AWS Security Specialty).</li> <li>Experience in a regulated or high-trust industry (healthcare, digital health, fintech, SaaS handling sensitive data).</li> <li>Familiarity with infrastructure-as-code and securing CI/CD pipelines.</li> <li>Experience scaling a compliance program from initial certification through annual renewals where you built the program.</li> <li>Master's degree in a relevant field.</li> </ul> <h4><span style="font-size: 12pt;"><strong><em>Compensation</em></strong></span></h4> <ul> <li>The expected salary range for this position is $145,000 - $185,000 annually. Actual compensation will be based on a candidate’s skills, qualifications, and years of relevant experience. In addition to the base salary, this role offers a bonus 10%, an opportunity, OTE of $159,000K - $203,500K. Bonus compensation will depend on individual performance and company performance.</li> </ul> <h4><span style="font-size: 12pt;"><strong><em>What You’ll Get</em></strong></span></h4> <ul> <li>Smart, intellectually curious, creative, supportive, and overall awesome colleagues!</li> <li>We are 100% fully remote! Work from anywhere in the U.S. with reliable Wi-Fi, within PST–EST time zones. Employees must be physically located in the U.S.; working outside the U.S. requires prior approval from leadership.</li> <li>Medical, dental, and vision benefits</li> <li>Discounted pet insurance</li> <li>Unlimited PTO after 60 days of employment</li> <li>401(k) after six months with company match&nbsp;&nbsp;&nbsp;</li> <li>Competitive salary</li> <li>Fast-track career advancement with a high-growth, Great Place to Work™ certified organization&nbsp;</li> <li>rater8 is a “bring your own device” company, enabling you to work on your preferred operating system; we offer a WFH stipend to offset costs per company guidelines</li> </ul> <p><span style="font-size: 12pt;"><strong>About rater8</strong></span></p> <p>rater8, the healthcare industry’s leader in reputation management, helps medical practices establish pervasive online visibility. The rater8 Visibility Engine (raVE) effortlessly gathers authentic reviews and real-time feedback from verified patients to drive sustainable practice growth, all with the support of award-winning customer service.&nbsp;</p> <p>Based in the United States, rater8 is a rapidly growing healthtech innovator, serving over 25,000 providers at practices and hospitals of all sizes and specialties, and providing unlimited career growth and pay opportunities for its employees.</p> <p><em>rater8 is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to equal opportunity regardless of race, color, ancestry, religion, gender, gender identity, parental or pregnancy status, national origin, sexual orientation, age, citizenship, marital status, disability, or Veteran status.</em></p> <p>&nbsp;</p>

Perks & benefits

  • 401k
  • Vision Insurance
  • Unlimited Vacation
  • Paid Time Off
  • Pension Matching

755,000+ hidden jobs like this

rater8 and thousands of companies post here first — often days before LinkedIn or Indeed. Your first 5 applications are free; go Pro to apply without limits.

Everything Pro unlocks:

  • Unlimited applications — free stops at 5
  • Track every application in one place
  • Apply straight to the source, one click
  • Save & organize roles you love
  • Roles pulled from company boards before the big sites

Weekly

$9.99
$4.99/week

For an active search. Cancel anytime.

Most popular

Monthly

$24.99
$12.99/month

The smart pick. Save 35% vs weekly.

Lifetime

$99
$49.99once

Pay once. Every future feature, forever.