Clinically AI Logo

Clinically AI

Security and Compliance Manager

Posted One Month Ago
Be an Early Applicant
Hybrid
San Diego, CA
110K-165K Annually
Mid level
Hybrid
San Diego, CA
110K-165K Annually
Mid level
Manage the company's end-to-end compliance program: run compliance automation, triage and remediate failing controls, maintain policies and evidence, coordinate external audits, administer Google Workspace and MDM, track risk and lead mitigation with stakeholders.
The summary above was generated by AI

About Clinically AI

Clinically AI is a rapidly scaling healthcare AI company transforming how behavioral health and healthcare organizations manage clinical documentation, compliance workflows, chart auditing, and operational efficiency through artificial intelligence.

Our platform helps clinicians, compliance teams, administrators, and healthcare organizations reduce administrative burden, improve documentation quality, strengthen audit readiness, and operate more efficiently. We operate at the intersection of AI, healthcare operations, workflow design, and real-world clinical execution, where adoption, trust, usability, and measurable outcomes matter.

The Opportunity

We are seeking a Security and Compliance Manager to own the day-to-day operation of our compliance program end to end, keeping our frameworks audit-ready, our policies current, and our workforce systems locked down.

This is a critical role for someone who can manage our compliance platform of record, drive remediation on failing controls to closure, and administer the workforce security layer (Google Workspace and MDM) that our compliance posture depends on. You will work closely with engineering, product, and executive leadership to keep the company continuously compliant as we scale at high velocity.

This is not a purely administrative, ticket-routing role. You should be comfortable owning remediation from detection to closure, operating with high rigor, and driving issues to resolution yourself rather than just flagging them, in a fast-moving startup environment.

We believe a successful compliance function is defined not by simply passing audits, but by continuous audit-readiness, strong workforce security hygiene, and trust earned with enterprise customers.

What You'll Own

  • Own our compliance platform of record — manage frameworks (SOC2 Type II, HIPAA, NIST, etc.), controls, tests, policies, and integrations.

  • Monitor compliance tests continuously; triage failures, remediate directly where possible, and drive owners to resolution where not.

  • Maintain and update security policies, procedures, and system documentation, ensuring they reflect actual practice and are reviewed/acknowledged on schedule.

  • Manage evidence collection and audit readiness, keeping automated evidence flowing and closing gaps in manual evidence before auditors ask.

  • Coordinate external audits (SOC2 Type II, HIPAA, NIST, ISO, etc.) end to end — auditor communication, evidence requests, findings, and remediation plans.

  • Administer Google Workspace, including user lifecycle management, access controls, 2FA/SSO enforcement, and audit log reviews.

  • Manage our MDM to ensure all endpoints are enrolled, encrypted, patched, and compliant with policy.

  • Track risk via risk assessments and the risk register, and lead mitigation planning with stakeholders.

What We're Looking For

  • Compliance Ownership: You treat a failing compliance test as a to-do item, not a ticket to route elsewhere — you drive remediation from detection to closure yourself.

  • Operational Rigor: You maintain accurate, up-to-date policies and documentation, and keep evidence collection running continuously rather than scrambling before an audit.

  • Security & IT Administration Fluency: You're comfortable administering Google Workspace and MDM tooling directly — user lifecycle, access reviews, and endpoint compliance are second nature to you.

  • Cross-Functional Collaboration: You partner effectively with engineering, product, and leadership, scoping remediation work and reporting compliance posture clearly to non-technical stakeholders.

  • High Ownership Mindset: You operate with follow-through in a high-velocity, fast-scaling environment, without needing heavy oversight.

Required Qualifications

  • 3+ years of experience in security compliance, GRC, IT security administration, or similar roles.

  • Hands-on experience administering a compliance automation platform (e.g., Vanta, Drata, or Secureframe), including frameworks, tests, policies, and remediation workflows.

  • Direct experience with SOC2 Type II and/or HIPAA compliance programs — evidence collection, audits, and continuous control operations.

  • Experience administering Google Workspace in a business environment (user lifecycle, security settings, access controls).

  • Experience managing an MDM solution (e.g., Kandji, Jamf, Mosyle, or similar) for endpoint compliance.

  • Ability to write, maintain, and operationalize security policies and compliance documentation.

  • Strong organizational and follow-through skills — comfortable owning remediation from detection to closure.

Preferred Qualifications

  • Experience in healthcare, healthtech, or another regulated data environment.

  • Familiarity with additional frameworks (HITRUST, ISO27001, NIST) and experience adding new frameworks to a compliance platform.

  • Experience supporting enterprise customer security reviews, RFPs, and partner compliance requirements.

  • Working knowledge of cloud environments (GCP preferred) sufficient to coordinate remediation with engineering teams.

  • Experience with identity and access tooling (SSO/SAML, Google Cloud Identity, Okta, or similar).

  • Certifications such as CISA, CISM, Security+, CCSK, or equivalent practical experience.

Compensation & Benefits

Base salary: $110,000–$165,000 + equity

Actual compensation will depend on experience, scope, and overall alignment with the role.

We offer competitive compensation, equity participation, healthcare coverage (medical, dental, vision), unlimited PTO, and a 401(k) with company match plus Roth option.

Equal Employment Opportunity

Clinically AI provides equal employment opportunities to all employees and applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, genetics, or any other characteristic protected by applicable law.

Similar Jobs

One Month Ago
Hybrid
South San Francisco, CA, USA
Senior level
Senior level
Artificial Intelligence • Machine Learning • Software • Biotech
Lead and scale Phylo's security, privacy, and compliance program: own the compliance roadmap, prepare for SOC 2/ISO 27001/GDPR/HIPAA readiness, support FedRAMP and NIST planning, partner with engineering to implement controls, run risk assessments and audits, manage customer security reviews and RFPs, and automate evidence collection and compliance workflows.
Top Skills: Ai SystemsCloud InfrastructureFedrampGdprHipaaHitrustIso 27001Iso 42001Nist Ai RmfNist Sp 800-53Soc 2
One Month Ago
In-Office
San Francisco, CA, USA
170K-250K Annually
Senior level
170K-250K Annually
Senior level
Artificial Intelligence • Software
Lead security compliance and GRC programs: manage audits (ISO, PCI, NIST, FedRAMP, HIPAA), define scope, assess readiness, drive remediation, build automated compliance workflows, and embed controls across cloud, containers, Kubernetes, and AI platform infrastructure.
Top Skills: AWSAzureContainer SecurityConversational AiEncryptionFedrampGCPHipaaIdentity And AuthenticationInfrastructure As CodeIso 42001KubernetesLoggingNetwork SecurityNist 800-53Pci Dss
An Hour Ago
Hybrid
2 Locations
230K-286K Annually
Senior level
230K-286K Annually
Senior level
Fintech • Machine Learning • Payments • Software • Financial Services
Leads multiple technology projects and engineering teams while designing and implementing large-scale, distributed, cloud-native systems. Provides technical leadership across teams, shapes architecture and platform roadmaps, mentors engineers, drives reliability and performance, and partners with product leaders. Uses modern programming languages, cloud platforms, microservices, databases, containers, CI/CD, observability, and AI-based development tools to deliver secure solutions supporting regulatory and customer needs.
Top Skills: Ai Coding ToolsAutomated Testing FrameworksAWSAzureBitbucketC#Ci/CdDockerGCPGitGitGoIde CopilotsInfrastructure As CodeJavaJavaScriptKubernetesNode.jsNoSQLObservabilityOpen Source FrameworksPythonRdbmsRustScalaTypescript

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account