Security & Compliance Lead
Summary
Own Maigrate’s security and compliance program as HIPAA Security Officer, build SOC 2 Type II readiness, and define AI-specific controls for LLM-powered healthcare SaaS.
Location: Hybrid (Lawrence, NY)
Reports to: CEO
Compensation: $160,000 to $200,000, plus health coverage and PTO
About Maigrate
Maigrate builds AI-powered products for mid-market companies. Our software stays in production and keeps working. We started in healthcare and it remains our largest market. We are moving into finance and other industries. We are early-stage and growing fast. The people who join now will shape how we operate and what we become.
Our software handles protected health information for ABA therapy providers and other healthcare organizations, and we operate as a business associate under HIPAA.
About the Role
We are hiring our first dedicated security and compliance owner. You will serve as our designated HIPAA Security Officer and own the security program across the company.
You will build Maigrate's security and compliance program from the ground up. You will lead SOC 2 readiness through Type II, build the policy and control framework, establish our HIPAA security program, and put the systems in place to keep all of it running as we scale.
The work has a second layer most security roles do not have. Our products run on large language models, which creates new questions around what data reaches a model, how providers handle that data, what gets logged, how long it is retained, and how AI systems are monitored in production. You will own the controls around that layer too.
You will personally build the compliance foundation. On the technical side, you will set the requirements, verify the work, and drive remediation with engineering, who will implement the changes.
What You'll Do
Build the compliance program
Serve as Maigrate's designated HIPAA Security Officer
Own the HIPAA security program, including security risk analysis, risk management, policies, controls, and documentation
Lead SOC 2 readiness through Type II and manage the audit process end to end
Write and maintain the security policy set and make sure the company follows it
Run our GRC platform, such as Vanta or Drata, and automate evidence collection wherever possible
Track findings, remediation work, and ongoing compliance requirements
Set and enforce technical security standards
Define access control, identity, and least-privilege requirements, and verify engineering enforces them across cloud and SaaS systems
Set security standards for our cloud environment and hold the company to them
Own vulnerability management as a program: define the process, prioritize findings, and drive engineering to close them
Set requirements for endpoint security, monitoring, and logging, and confirm coverage is real
Coordinate penetration testing and drive findings through remediation
Investigate findings directly in the environment when you need to understand what is actually happening
Set security requirements for business continuity, backups, and disaster recovery
Own incident response
Build and maintain the incident response plan and test it before we need it
Lead the response when a security incident happens
Own incident investigation, documentation, and post-incident remediation
Coordinate breach assessment and required notifications under HIPAA, applicable BAAs, and applicable state breach notification requirements
There is no formal on-call rotation, but as the security owner, you will be expected to lead the response to significant security incidents when they occur, including outside normal business hours when necessary
Set the AI security and governance controls
Define what data may reach an AI model and what must be de-identified or removed first
Ensure PHI is only shared with model providers under appropriate HIPAA-compliant arrangements
Review model providers for data retention, training, logging, security, and subcontractor risks
Set logging, retention, access, and review standards for prompts and outputs
Define the controls and fallback requirements for when AI systems fail or behave unexpectedly, and work with product and engineering on implementation
Support the business
Answer customer security questionnaires and lead customer security and compliance reviews
Own the security and compliance requirements around BAAs and our subcontractor chain, working with counsel where needed
Run vendor security and risk reviews before we adopt systems that touch customer or company data
Maintain the security documentation customers need during diligence
Deliver security training people actually remember
Develop the annual security and compliance budget, recommend tooling and outside spend, and present priorities to the CEO for approval
What We're Looking For
Must have
6+ years in security, compliance, or a comparable role
You have built a security and compliance program from the ground up in a cloud SaaS environment, including taking SOC 2 from readiness through audit
Working HIPAA knowledge from the business associate side, including PHI handling, BAAs, security risk analysis, and breach response
Strong cloud security skills. You are comfortable getting into the environment yourself, investigating findings, and working directly with engineering to remediate them
Experience with identity and access management, vulnerability management, logging, endpoint security, and incident response
Ability to turn a control requirement into clear instructions an engineer will actually follow
Comfort speaking directly with customer security and compliance teams
Ability to operate in an early-stage environment where the program is still being built
Preferred
CISSP, CISA, or HCISPP
Experience securing LLM-based or AI-native products
HITRUST or NIST framework experience
Experience working with healthcare SaaS companies
Experience supporting security and compliance requirements for customers in regulated financial services environments
Equal Opportunity
Maigrate is an equal opportunity employer. We consider qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, disability, veteran status, or any other characteristic protected by applicable law.