CronJobs

security jobs

Security GRC Lead

Candidhealth · San Francisco

hybridlead$180,000–$258,000Posted Aug 25, 2026PythonTypeScriptSQLGCPTerraformDockerKubernetesCI/CD

Apply on the employer site

About this role

**Security GRC Lead — Candid Health** ## About Candid Health Candid Health is building the modern financial backbone for American healthcare. Their autonomous Revenue Cycle Management (RCM) platform uses AI agents and a configurable rules engine to unify clinical, billing, and insurance data—helping healthcare providers submit complex medical claims accurately and efficiently. ## Role Overview Candid Health is seeking a **Security GRC Lead** to build their **first in-house GRC program** from the ground up. This role focuses on treating compliance as an engineering and data problem—building automated evidence pipelines, implementing compliance-as-code, and establishing continuous controls monitoring across **GCP infrastructure, identity systems, and CI/CD pipelines**. ## Key Responsibilities 1) **Compliance Automation & Engineering** - Develop automated scripts and API integrations to collect compliance evidence directly from system sources (instead of manual screenshots). - Write and deploy infrastructure-as-code and policy enforcement rules to automatically enforce security baselines. - Maintain live compliance dashboards and alerts to flag configuration drift or policy violations in real time. - Partner with Legal on **Medicare and Medicaid compliance**. - Partner closely with Legal and Finance on future due diligence and compliance projects. 2) **Framework Mapping & Control Architecture** - Convert regulatory, security, and industry standards (e.g., **SOC 2, HiTrust, PCI, HIPAA**) into clear, testable technical controls. - Map single technical controls across multiple overlapping frameworks to reduce redundant work. - Work with DevOps and Software Engineering to build compliance controls into **CI/CD pipelines** without slowing delivery. 3) **Risk Management & Audits** - Lead technical audit readiness and external audit engagements using programmatic evidence pipelines. - Automate vendor risk management workflows and API-driven vendor evaluations. - Build continuous risk tracking tools using live vulnerability telemetry and identity logs (instead of static quarterly surveys). ## Required Qualifications - **3+ years** in a technical security role (Security Engineering, Cloud Security, or Technical GRC). - Proficiency in **Python, TypeScript, SQL**, with hands-on experience interacting with APIs, parsing logs, and querying databases. - Hands-on experience with at least one primary cloud platform (**GCP preferred**) and Infrastructure-as-Code tools such as **Terraform**. - Deep familiarity with core frameworks such as **SOC 1/2, PCI, NIST, and/or HITRUST**. - Understanding of **CI/CD pipelines**, Git workflows, and container environments (**Docker/Kubernetes**). ## Preferred Qualifications - Certifications such as **CISSP, CISA, CRISC, AWS Certified Security—Specialty, or CCSP**. - Experience with **Policy-as-Code** engines. - **HITRUST** experience. - Background in software development, DevOps, or platform engineering. - Experience with modern continuous compliance platforms (e.g., **Vanta, Drata, Anecdotes**). ## Values - Put customers first - Take care of each other and ourselves - Anchor on outcomes and work relentlessly and creatively - Prioritize building a diverse and inclusive workspace - Humility is our greatest strength - Be candid, kind, and committed - Strive to be the most prepared person in the room - Be truth seekers ## Pay Transparency - Estimated starting annual salary range: **$180,000 – $258,000 USD** - Total

Listing freshness

CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord