683,639open jobs
39,571companies
98,002added this week
Browse all
Salary
$190k – $220k per year
Location
Remote (United States)
Employment
Full-Time
Overview
Company
Impact
Profile match
Collectly is a fast-growing, profitable healthcare technology company that helps medical and dental practices modernize the patient financial experience without changing their existing EHR or practice management systems. By integrating directly with EHRs, Collectly automates pre- and post-service billing workflows using AI-powered revenue cycle management, helping practices increase patient collections, improve cash flow, and reduce administrative overhead. Today, Collectly engages over 300,000 patients daily across thousands of U.S.

About Collectly

Collectly is a patient billing and payments platform for US healthcare providers. We handle protected health information and card payments at scale, integrate directly with major EHRs, and sell to health systems and large provider organizations buyers with real security programs and real diligence processes. We're HITRUST i1 Validated and SOC 2 Type 2.

The role

You'll own security and compliance end to end. Today it's split between the CTO and whichever engineer happens to be nearest. You'll take all of it.

You'll be the only person in this function, so the job is to build a program that scales without adding drag. Automate the evidence, delete the controls nobody can trace to a requirement, and answer the hard customer questions yourself instead of routing them to engineering.

What you'll own

    Customer-facing security and compliance

    The largest part of the job.

  • Answering customers’ security questionnaires

  • AI governance questionnaires and responsible-AI reviews covering our AI patient billing agent

  • Live security calls with prospects' InfoSec teams - technical conversations, not slide reading

  • Health-system procurement portals (Archer, ProcessUnity, Venminder and similar)

  • Annual customer reattestation cycles

  • Customer security escalations, incident communications, and customer-facing RCAs

  • Hosting customers who exercise right-to-audit clauses

  • Distribution of SOC 2, HITRUST certification, pen test summaries, and subprocessor notices under NDA

  • A public trust center, standard security package, and answer library - so most of the above becomes a lookup rather than a project

  • Audits and certifications

  • HITRUST i1 and SOC 2 Type 2, end to end: readiness, evidence, auditor management, remediation tracking

  • PCI DSS: SAQ ownership, AOC collection from processors, scope definition for card-present and card-not-present flows

  • Annual HIPAA Security Risk Analysis and risk register

  • Pen test lifecycle: scheduling, scoping, remediation tracking, customer-facing summary

  • Quarterly user access reviews

  • BCP/DR tabletops and annual test coordination

  • Compliance tooling

  • Own Vanta and our security scanners as an administrator

  • Pull evidence from systems - CI, infrastructure-as-code, identity provider, EDR, cloud config - instead of collecting screenshots

  • Reduce the count of manually evidenced controls every year

  • Contracts, BAAs, and vendor risk

  • BAAs in both directions, customer and subcontractor, from template through negotiation

  • Security exhibits, DPAs, subprocessor inventory

  • Tiered vendor security review, so a no-PHI vendor gets a one-page checklist and a same-day answer

  • Annual vendor reattestation

  • Policies, training, and incident response

  • Own and maintain the policy set

  • Security awareness and HIPAA training, phishing simulations, completion tracking

  • Own the incident response program: runbooks, tabletops, coordination during an incident

  • Breach notification clock management - the HIPAA window, state AG requirements, cyber insurance notice, and the per-contract customer notification windows in our MSAs

  • A documented exception process with a named approver, expiry date, and compensating control

  • Privacy and AI governance

  • HIPAA Privacy Officer designation

  • State privacy law tracking: CCPA/CPRA, Washington My Health My Data, and what follows

  • Stand up a durable AI governance framework for our AI patient billing agent - model inventory, human oversight, monitoring - replacing today's per-customer, from-scratch approach

  • Track emerging state rules on AI in healthcare and AI-generated patient communications

What you won't own

  • Remediation engineering. Findings and fixes belong to DevOps. You own the SLA dashboard and the escalation path.

  • Shipping decisions. You document risk and escalate. The CTO decides on the priority.

  • A seat as a gate in design or code review.

What we're looking for

  • Extensive experience in security compliance or GRC, including time in healthcare SaaS or another PHI-handling environment

  • Has run SOC 2 and HITRUST as an owner, not a contributor

  • Deep HIPAA fluency: Security Rule, Privacy Rule, Breach Notification Rule, BAAs, minimum necessary

  • Hands-on with Vanta or a comparable compliance automation platform

  • Strong on frameworks generally, and able to pick up an unfamiliar one and apply it without a playbook - NIST AI RMF and ISO 42001 are where we're headed and neither has settled practice yet

  • Writes final-draft customer-facing prose: clear, accurate, no hedging

  • Able to follow a technical conversation with our DevOps and platform engineers unassisted - architecture diagrams, infrastructure-as-code, access control models, cloud configuration

  • Reasons about threat models, not finding titles. Given how a control is actually implemented in our system, you can work out whether a finding is exploitable, whether it's already mitigated elsewhere, and whether it matters for the data in question. You can close something as not applicable with a written rationale that survives an auditor, and you can tell when the opposite is true and it needs to be escalated hard.

  • A software engineering or security engineering background is a strong plus here, though not required - what matters is the judgment, however you acquired it.

    Also a plus: PCI DSS in a payments context. Certifications we recognize: CIPP/US, HCISPP, CISSP, HITRUST CCSFP.

    Process

    Intro with the CTO, then a working session where we answer a real inbound security questionnaire together, then a scenario conversation and cross-functional interviews. No take-home.

    Please be prepared to actively research information during the exercise.

Why you'll love it here

    • Unlimited PTO: We believe in work-life balance and encourage you to recharge when you need it.
    • Comprehensive Health Coverage: Fully paid medical, dental, and vision insurance for you and your dependents, because your well-being matters to us.
    • Equity Opportunities: Share in our success with stock options - your hard work will drive our growth.
    • Retirement Planning Made Easy: Enjoy a 401(k) with a generous company match to secure your future.
    • Student Loan Support: We help lighten the load with contributions toward your student loans.
    • Competitive Compensation: $190,000 - $220,000 per year
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
683,639 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$30k – $70k per year (Estimated) • In office • Full-Time • 2+ years exp
Databases
Amazon Aurora
DevOps
Terraform
GitHub Actions
Azure
CI/CD
ArgoCD
AWS
Kubernetes
Platform Engineering
Amazon EKS
FinOps
IAM
Cybersecurity
PCI DSS
SOC 2
Apply
$11k – $30k per year (Estimated) • In office • Full-Time
PowerShell
DevOps
SLI/SLO/SLA
Management
OneDrive
SharePoint
Apply
$19k – $52k per year (Estimated) • Remote/Hybrid • Full-Time • Bachelor's Degree • Athens
PowerShell
DevOps
VMWare
Azure
Windows Server
Hyper-V
SLI/SLO/SLA
Cybersecurity
Microsoft Entra ID
Management
Jira
ServiceNow
OneDrive
SharePoint
Apply
$20k – $54k per year (Estimated) • Remote/Hybrid • Full-Time • 1+ year exp • Bachelor's Degree • Athens
DevOps
Azure
Windows Server
AWS
SLI/SLO/SLA
Cybersecurity
Wireshark
Management
Microsoft Teams
Apply
SRE Engineer II 6 hours ago
$16k – $42k per year (Estimated) • In office • Full-Time • 3+ years exp • Gurgaon
Python
Bash
Databases
MySQL
PostgreSQL
Redis
RabbitMQ
Apache Kafka
DevOps
Terraform
Ansible
GCP
Datadog
Prometheus
Azure
HAProxy
Windows Server
AWS
Docker
Kubernetes
Ubuntu
Nginx
Grafana
SLI/SLO/SLA
IAM
Cybersecurity
Wireshark
Tcpdump
Management
Jira
ServiceNow
QA
Postman
Apply
$200k per year • In office • Full-Time • 6+ years exp • Associate's Degree • Santa Monica
Python
JavaScript
C#
Python
Flask
SQLAlchemy
FastAPI
Asyncio
Celery
C#
.NET
Databases
PostgreSQL
DevOps
CI/CD
AWS
Docker
Kubernetes
Amazon EKS
GitLab
Analytics
ETL/ELT
Apply
$32k – $73k per year (Estimated) • Remote/Hybrid • Full-Time • 4+ years exp • Belgrade
Python
SQL
AI/ML
Claude
Claude Code
AI Agents
Voice Agents
Analytics
Metabase
Looker
Apply
$84k – $108k per year • Remote/Hybrid • Full-Time • 5+ years exp • Belgrade
Python
Python
Flask
SQLAlchemy
Databases
PostgreSQL
Redis
AI/ML
Claude
Claude Code
AI Agents
LLM
Apply
$64k – $139k per year (Estimated) • Equity • Remote/Hybrid • Full-Time • 1+ year exp • San Francisco
SQL
Marketing
Salesforce
LinkedIn
Apply
$101k – $212k per year (Estimated) • Equity • In office • Full-Time • 5+ years exp • San Francisco
Apply
See all jobs
This is one of many
683,639 more open roles from verified company boards, updated every day.