Security and Compliance Lead
worklist handles protected health information and acts in systems that hold money. You'll own security and compliance from the start: the controls, the evidence, and the programmes customers ask for, such as HIPAA and SOC 2.
What you'll do
- Design and run the security programme: access, logging, secrets, vendor reviews
- Lead HIPAA compliance and prepare for SOC 2
- Review designs with engineering so PHI never reaches logs, URLs or fixtures
- Answer customers' security questionnaires and support their audits
What you'll bring
- 5+ years in security or compliance at a software company handling sensitive data
- Hands-on experience with HIPAA, and with a SOC 2 or ISO 27001 audit
- Comfort in cloud infrastructure and code reviews, not only policy
- Pragmatism: controls that engineers actually follow
Nice to have
- Healthcare startup experience
- Security engineering background
About worklist
worklist runs healthcare operations as workflows, from intake to payment, and turns everything automation can't finish into structured work for a person. We're a small team building it carefully, starting with denial recovery for medical equipment suppliers.