Security GRC Lead
Candidhealth · San Francisco
About this role
**Security GRC Lead — Candid Health** ## About Candid Health Candid Health is building the modern financial backbone for American healthcare. Their autonomous Revenue Cycle Management (RCM) platform uses AI agents and a configurable rules engine to unify clinical, billing, and insurance data—helping healthcare providers submit complex medical claims accurately and efficiently. ## Role Overview Candid Health is seeking a **Security GRC Lead** to build their **first in-house GRC program** from the ground up. This role focuses on treating compliance as an engineering and data problem—building automated evidence pipelines, implementing compliance-as-code, and establishing continuous controls monitoring across **GCP infrastructure, identity systems, and CI/CD pipelines**. ## Key Responsibilities 1) **Compliance Automation & Engineering** - Develop automated scripts and API integrations to collect compliance evidence directly from system sources (instead of manual screenshots). - Write and deploy infrastructure-as-code and policy enforcement rules to automatically enforce security baselines. - Maintain live compliance dashboards and alerts to flag configuration drift or policy violations in real time. - Partner with Legal on **Medicare and Medicaid compliance**. - Partner closely with Legal and Finance on future due diligence and compliance projects. 2) **Framework Mapping & Control Architecture** - Convert regulatory, security, and industry standards (e.g., **SOC 2, HiTrust, PCI, HIPAA**) into clear, testable technical controls. - Map single technical controls across multiple overlapping frameworks to reduce redundant work. - Work with DevOps and Software Engineering to build compliance controls into **CI/CD pipelines** without slowing delivery. 3) **Risk Management & Audits** - Lead technical audit readiness and external audit engagements using programmatic evidence pipelines. - Automate vendor risk management workflows and API-driven vendor evaluations. - Build continuous risk tracking tools using live vulnerability telemetry and identity logs (instead of static quarterly surveys). ## Required Qualifications - **3+ years** in a technical security role (Security Engineering, Cloud Security, or Technical GRC). - Proficiency in **Python, TypeScript, SQL**, with hands-on experience interacting with APIs, parsing logs, and querying databases. - Hands-on experience with at least one primary cloud platform (**GCP preferred**) and Infrastructure-as-Code tools such as **Terraform**. - Deep familiarity with core frameworks such as **SOC 1/2, PCI, NIST, and/or HITRUST**. - Understanding of **CI/CD pipelines**, Git workflows, and container environments (**Docker/Kubernetes**). ## Preferred Qualifications - Certifications such as **CISSP, CISA, CRISC, AWS Certified Security—Specialty, or CCSP**. - Experience with **Policy-as-Code** engines. - **HITRUST** experience. - Background in software development, DevOps, or platform engineering. - Experience with modern continuous compliance platforms (e.g., **Vanta, Drata, Anecdotes**). ## Values - Put customers first - Take care of each other and ourselves - Anchor on outcomes and work relentlessly and creatively - Prioritize building a diverse and inclusive workspace - Humility is our greatest strength - Be candid, kind, and committed - Strive to be the most prepared person in the room - Be truth seekers ## Pay Transparency - Estimated starting annual salary range: **$180,000 – $258,000 USD** - Total
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.