CronJobs

security jobs

Director, Compliance & AI Governance

Akasa · South San Francisco

hybridunknown$150,000–$185,000Posted Aug 10, 2026PythonAWSSOC 2HIPAAHITRUSTNIST AI RMFGRCVanta

Apply on the employer site

About this role

## About AKASA At AKASA, our mission is to build the future of healthcare with AI. We’re the leading provider of generative AI solutions for the healthcare revenue cycle—helping health systems capture and communicate the full patient clinical journey, streamline operations, and focus on delivering quality patient care. AKASA has raised **$205M+** in funding from investors including **Andreessen Horowitz, BOND, and Costanoa Ventures**. Revenue bookings for our new AI-native product suite have grown **20x+** since launching in 2024, and our deployments have been recognized nationally for real-world GenAI impact in healthcare finance. Our customer base represents **$120B+** in net patient revenue and includes leading health systems such as **Cleveland Clinic, Duke, Stanford, and Johns Hopkins**. ## About the Role AKASA is seeking a **strategic, automation-minded Director of Compliance & AI Governance** to own and evolve our compliance program as we scale. This role is ideal for someone who has led compliance in a **healthcare SaaS or AI environment** and wants to build a modern, engineering-forward program—not a paperwork factory. You will own our **HITRUST, SOC 2, and HIPAA** programs end to end, operationalize emerging **AI governance** frameworks (including **NIST AI RMF**), and drive the **policy lifecycle** across the company. **Location:** On-site, **3+ days/week** in **South San Francisco HQ**. ## What You’ll Do - **Own compliance certifications end to end** (including **HITRUST CSF, SOC 2 Type II, and HIPAA**)—from control design and implementation through evidence collection, audit coordination, and remediation. - **Evaluate and pursue new certifications/attestations** as needs evolve (e.g., **ISO 27001, ISO 42001, HITRUST AI**). - **Define compliance roadmaps** and drive org-wide adoption with cross-functional alignment and accountability. - **Build AI governance** grounded in **NIST AI RMF**, partnering with Engineering, Product, and Legal to establish model risk assessments, AI use policies, and enterprise-ready documentation. - **Drive compliance automation** as a first principle: - Implement/optimize **GRC** and **continuous control monitoring** tooling - Automate evidence collection across **Okta, Google Workspace, Kandji/Iru, SentinelOne, Nightfall, AWS** - Use AI tools to streamline policy drafting, control mapping, and audit preparation - **Own the full policy lifecycle** (authoring, review cadences, exceptions, attestation campaigns, version control) ensuring policies are clear, practical, and mapped to certified frameworks. - **Be the compliance face of AKASA** for customers and prospects: - Lead security/compliance questionnaire responses - Support enterprise sales cycles - Manage customer audits - Maintain trust artifacts (e.g., **BAAs, trust center, shared assessments**) and automate where possible - **Oversee vendor/third-party risk management**, annual risk assessment, security awareness & HIPAA training, and incident response documentation/tabletop exercises (with Security and IT). - Partner with **Legal and Security leadership** on security-related contractual obligations. ## Skills & Qualifications - **8+ years** experience in security compliance, GRC, or risk management, including **2+ years** leading a team or function. - Strong hands-on expertise with **HITRUST CSF (r2 preferred), SOC 2 Type II, HIPAA Security & Privacy Rules**, and **NIST AI RMF**. - **Automation-first mindset** with ex

Listing freshness

CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord