Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Parachute Health

Lead Security & Compliance Analyst

Parachute Health

Lead Security & Compliance Analyst at Parachute Health overseeing audits and hands-on technical security work. Ensuring compliance across security frameworks and managing vulnerability programs.

Posted 7/29/2026full-timeRemote • 🇺🇸 United StatesSenior💰 $80,000 - $130,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in managing compliance audits, including SOC 1, SOC 2, and HITRUST, while implementing security frameworks and policies. Proficient in vulnerability management and AWS security practices, with a strong ability to communicate technical findings and remediation strategies.

Highest-signal resume keywords
SOC 1/SOC 2 Audit ExperienceHITRUST Compliance ManagementVulnerability Scanning and RemediationAWS Security ConceptsPolicy and Procedure Development

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Compliance AuditingVulnerability ManagementSecurity Framework ImplementationEvidence CollectionTechnical Security AnalysisScripting (Python, Bash)Control MonitoringRisk AssessmentForensic Evidence CollectionSecurity Awareness Training
Soft Skills
Clear CommunicationCollaborationProblem-Solving
Tools & Technologies
DrataSafeBaseAWS (EKS, WAF, Shield, CloudFront, IAM)SecurityScorecard
Industry Keywords
HIPAAGRCComplianceSecurity FrameworksThird-Party Risk Assessment

Tech Stack

Tools & technologies
AWSCloudPython

About the role

Key responsibilities & impact
  • Own SOC 1, SOC 2, HITRUST CSF, and HITRUST AI audits end-to-end: scoping, evidence collection, auditor coordination, and findings remediation
  • Develop, update, revise, and implement compliance policies, procedures, and practices for security frameworks (HIPAA, HITRUST, SOC) as well as general compliance and operations
  • Manage our compliance automation and trust platforms (Drata, SafeBase), including control monitoring and responses to customer security questionnaires.
  • Coordinate with external vendors and clients to gather information needed for compliance reviews, validations, and audits
  • Run third-party/vendor risk assessments and respond to customer security assessments and external inquiries
  • Deliver HIPAA and security awareness training and measure control effectiveness through internal audits
  • Run the vulnerability management program: scanning, triage, prioritization, and driving remediation with engineering teams
  • Investigate and remediate security findings across our AWS environment (EKS, WAF, Shield, CloudFront, IAM) and SaaS stack
  • Review external attack surface findings (e.g., SecurityScorecard) and implement fixes from CSP headers to subresource integrity to TLS configuration
  • Support security incident response: log analysis, forensic evidence collection, and containment
  • Support fraud and forensic investigations authentication log analysis, targeted data extraction, and evidence preservation in support of legal and compliance matters
  • Improve our security tooling and automate evidence collection, using scripting (Python, Bash) where manual work can be eliminated

Requirements

What you’ll need
  • 4+ years combined experience across security compliance/GRC and hands-on technical security
  • Direct experience supporting SOC 1/SOC 2 and/or HITRUST audits — you've been through at least one full audit cycle
  • Working knowledge of HIPAA Security and Privacy requirements
  • Hands-on experience with vulnerability scanning and remediation, and comfort reading technical findings (CVEs, misconfigurations, cloud security issues)
  • Familiarity with AWS security concepts (IAM, security groups, logging, WAF)
  • Ability to write clear policies and procedures and equally clear remediation tickets.

Benefits

Comp & perks
  • Medical, Dental, and Vision Coverage: Comprehensive plans with options for low-to-no-cost premiums.
  • Employer HSA Contribution: Company-funded contributions to your Health Savings Account.
  • 401(k) Retirement Plan
  • Equity Incentive Plan
  • Annual Company-Wide Bonus: Opportunity for up to 15% bonus based on company performance.
  • Remote-First Culture: We are remote-first with a dedicated NYC office and reimbursement options for co-working spaces.
  • Flexible Vacation Policy
  • Summer Fridays: 5 additional Fridays off during the summer (separate from PTO).
  • Home Office and Wellness Stipend
  • Monthly Internet Stipend
  • Annual Learning and Development Stipend