Security & Compliance Manager (GRC), US-based
Collectly - Remote
Still listed by Collectly · checked today · posted 17 Sep 2026 (2 weeks ago)
Skills: GRC, Hitrust i1, Soc 2 type 2, Hipaa, PHI, PCI, Security compliance, Evidence automation, Customer security questionnaires
About Collectly Collectly is a patient billing and payments platform for US healthcare providers. We handle protected health information and card payments at scale, integrate directly with major EHRs, and sell to health systems and large provider organizations buyers with real security programs and real diligence processes. We're HITRUST i1 Validated and SOC 2 Type 2. The role You'll own security and compliance end to end. Today it's split between the CTO and whichever engineer happens to be nearest. You'll take all of it. You'll be the only person in this function, so the job is to build a program that scales without adding drag. Automate the evidence, delete the controls nobody can trace to a requirement, and answer the hard customer questions yourself instead of routing them to engineering.