Sr. Security Compliance Analyst
Remote (United States)
Bamboo Health
Delivering actionable insights on patients' physical, behavioral and social health. Empowering healthcare professionals to provide better experiences and care.Bamboo Health is the leader in Real-Time Care Intelligence™ solutions aimed at improving lives for everyone experiencing physical and behavioral health challenges. We are driven by our mission to empower clients to deliver seamless, high-quality and cost-effective care during pivotal moments to improve health outcomes. From coast to coast, Bamboo Health partners with all major retail pharmacy chains, 52 states and territories, 100% of the top 10 best hospitals and more than half of the country’s largest health plans to improve more than 1 billion patient encounters annually. Join us in improving lives during pivotal care moments!
Summary:
Bamboo Health Security designs innovative security architectures across cloud services, identity management, virtualization, and third-party providers, ensuring compliance in complex regulatory environments. Our highly collaborative team is committed to growth and innovation.
We are seeking a Senior Security Compliance Analyst to monitor and enforce compliance, assess risks, and enhance security processes using AI and automation. This role bridges compliance and security operations, conducting system reviews, supporting audits, and assisting with security incidents. You’ll collaborate with experienced security experts to strengthen compliance and risk management across the organization.
What You’ll Do:
- Ensure compliance with internal and external policies, standards, and regulations.
- Enhance the compliance program using AI, automation, and process improvements.
- Support external audits and customer inquiries by providing necessary information.
- Leverage AI tools to streamline compliance request responses while applying professional judgment.
- Maintain and develop policy documentation, ensuring clarity and alignment across IT, Legal, HR, and Operations.
- Assist in internal compliance training and best practices initiatives.
- Align security operations with compliance requirements and support audits.
- Clearly communicate compliance status to internal and external stakeholders.
- Assist Security Operations with incident response and continuous improvement efforts.
- Participate in the on-call rotation to escalate and resolve security incidents.
What Success Looks Like…
In 3 months…
- Learn the current compliance landscape, tools, policies, procedures, and stakeholders in key internal departments.
- Develop an understanding of the specific regulatory frameworks that Bamboo Health adheres to.
- Understand and be able to describe the function of Bamboo Health's products and services.
- Participate in weekly on-call rotation, incident analysis, and escalation – aiding Security Operations as needed.
In 6 months…
- Understand Bamboo Health's current compliance status and begin to identify immediate compliance risks or gaps.
- Participating in risk and compliance assessment exercises with internal teams.
- Describe the organization layout in detail and identify key stakeholders.
- Be familiar with the required communication channels and participate in providing required metrics and feedback to internal and external stakeholders.
In 12 months…
- Make recommendations and provide feedback to improve the effectiveness of our internal compliance program.
- Actively helping to improve and streamline the methods, processes, and procedures used in measuring and adhering to compliance requirements.
- Lead the team's efforts in completing comprehensive security assessments executed by independent third-party assessment organizations and utilize the findings to improve compliance.
- Augment the team's efforts with internal educational initiatives and objectives.
What You Need:
- 5+ years of experience utilizing information security best practices, compliance frameworks, and security tooling and processes.
- Familiarity with security frameworks like ISO, NIST, HIPAA, CIS, HITRUST, and FedRAMP.
- Experience with testing and measuring security controls.
- Ability to provide technical and operational support on security compliance initiatives.
- Expertise in security auditing and evidence gathering for compliance purposes.
- Experience in security best practices and controls applied in cloud-centric environments (AWS/Azure/GCP).
- Excellent written and verbal communication skills, with ability to build and communicate business rationale.
- Strong ability to learn quickly and work independently while being part of a team.
- Ability to build effective, sustainable working relationships internally, with customers, and external stakeholders.
- Working knowledge of incident response best practices and programs would be beneficial.
- A high level of judgment, analytical ability and creativity in investigating problems that require original and innovative solutions.
- Experience working a fast-paced, rapidly changing work environments.
- A work environment that is conducive to high quality virtual interactions. This includes but is not limited to being able to work from a quiet space with minimal interruptions or distractions, and a strong internet connection.
What You Get:
- Join one of the most innovative healthcare technology companies in the country.
- Have the autonomy to build something with an enthusiastically supportive team.
- Learn from working at the highest levels and on the most strategic priorities of the company, including from world class investors and advisors.
- Receive competitive compensation, including equity, with health, dental, vision and other benefits.
Belonging at Bamboo
We Care. #BambooHealthValuesCare
Every human being has the right to the best possible healthcare. Our solutions enable healthcare professionals to see and treat every individual as a whole person by providing the right information, at the right time – regardless of physical, behavioral, or social barriers.
We’re a great place to work because we care. We continually seek to learn about our differences and ensure the unique identities and contributions of all employees are welcome, valued and celebrated.
Our commitment to making a positive impact starts by recognizing and leveraging our differences, building inclusive teams, cultivating a sense of belonging, combating biases, and actively removing barriers to equity.
Bamboo Health is proud to be an Equal Employment Opportunity and affirmative action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
To protect our applicants from fraudulent recruitment activity, we recommend that all applicants verify the validity of an interview and hiring process by visiting our website www.bamboohealth.com. All valid job postings will be listed on our careers page. Bamboo Health does not conduct interviews via text and will not request sensitive information such as banking details during the application process.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Audits Automation AWS Azure Banking Cloud Compliance FedRAMP GCP HIPAA HITRUST Incident response NIST Risk management Security assessment
Perks/benefits: Competitive pay Equity / stock options Health care Startup environment
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.