Owning the compliance audit cycle end-to-end, the full-time remote Lead Security Compliance Analyst will manage SOC 1, SOC 2, and HITRUST audits while also engaging in hands-on technical security tasks such as vulnerability management and security findings remediation. Key responsibilities Manage the end-to-end process for SOC 1, SOC 2, HITRUST CSF, and HITRUST AI audits, including scoping and evidence collection Run the vulnerability management program, including scanning, triage, and remediation efforts in collaboration with engineering teams Develop and implement compliance policies and procedures for various security frameworks, ensuring adherence to HIPAA and other regulations Required qualifications 4+ years of experience in security compliance/GRC and hands-on technical security Direct experience with SOC 1/SOC 2 and/or HITRUST audits, having completed at least one full audit cycle Working knowledge of HIPAA Security and Privacy requirements Hands-on experience with vulnerability scanning and remediation, including familiarity with AWS security concepts Ability to write clear policies and procedures as well as remediation tickets