Leap (leaphealth.com) Logo

Leap (leaphealth.com)

Senior Manager, Security & Compliance

Posted An Hour Ago
Be an Early Applicant
In-Office or Remote
Hiring Remotely in New York City, NY
150K-190K Annually
Senior level
In-Office or Remote
Hiring Remotely in New York City, NY
150K-190K Annually
Senior level
Lead Leap’s security and compliance program, including HITRUST certification, SOC 2 Type II audits, HIPAA controls, policy development, vendor risk reviews, security questionnaires, and client security engagements. Build a prioritized security roadmap, advise Engineering on GCP and data-stack controls, manage an external security partner, and report security posture and compliance risks to leadership.
The summary above was generated by AI
About Leap

Leap is one of the fastest-growing benefits solutions and a category-defining pioneer in employer specialty pharmacy. We are reshaping how life-changing therapies are delivered and financed, ensuring patients get the treatment they need while employers finally get a fair deal.

Specialty drugs and infusions represent nearly 10% of all healthcare spend and are the fastest-growing cost category for employers. Leap tackles this challenge with a novel approach: eliminating hidden markups, expanding access to high-quality infusion providers, and bringing clarity and fairness to how therapies are priced and paid for.

We’re proud to partner with numerous Fortune 500 companies and leading TPAs. Each patient we serve creates immediate ROI: lower costs, improved access, and better care. Join us as we redefine what’s possible in specialty care.

About the Role

Leap is hiring a Senior Manager, Security & Compliance to lead the next phase of our security program. We have an established foundation, including SOC 2 Type II and HIPAA-aligned controls. Now we’re looking for a leader to shape where the program goes next and own the work of getting there, starting with HITRUST certification.

This is a hands-on builder role. You’ll set the direction for our security and compliance program and do much of the work yourself: running audits and certifications, writing policies, reviewing controls, and completing security questionnaires. You’ll also be trusted with the judgment calls that matter most, including the security obligations Leap commits to, the vendors and tools we adopt, and how new controls roll out across the company.

You’ll represent Leap with client and partner security teams when it counts, but the core of the job is building and maintaining a program strong enough to make those conversations easy. You’ll work closely with Engineering, Operations, and our go-to-market teams, and you’ll manage our external security partner.

This is an individual contributor role for an ambitious, highly autonomous security leader who thrives on building end-to-end and driving strategic impact.

What You'll Accomplish

Lead our compliance program
  • Run HITRUST certification from kickoff through completion next year, including gap assessment, control mapping, remediation, and assessor management.

  • Own SOC 2 Type II end to end, including evidence collection, the auditor relationship, and closing gaps.

  • Maintain our HIPAA security and privacy controls, core policies, and BAA obligations.

Build and strengthen our security program
  • Complete a full review of Leap’s security posture and deliver a prioritized roadmap of improvements and tooling recommendations.

  • Roll out new controls, policies, and processes across the company, partnering with Engineering on implementation across our GCP and data stack.

  • Assess new vendors and tools, including AI tools, and run ongoing third-party risk reviews.

Own what Leap commits to on security
  • Complete security questionnaires, RFP security sections, and controls reviews yourself, with responses that are accurate and consistent.

  • Make the call on the security obligations Leap takes on in client and partner agreements.

  • Build a response library and repeatable review process that keeps pace as we grow, and represent Leap with client and partner security teams when needed.

Run our security partnerships and reporting
  • Select and manage our external security partner, making sure they extend the program we own internally.

  • Keep leadership informed on security posture, risk, and compliance status, and flag where investment is needed.

What You Bring
  • 7+ years in healthcare information security, governance/risk/compliance (GRC), or IT audit, including directly owning at least one full SOC 2 Type II audit cycle.

  • Deep familiarity with security and compliance frameworks such as SOC 2, HIPAA, and HITRUST, and an audit- and GRC-first approach to building a program.

  • Experience building a security or compliance program from scratch, or owning one end to end as an early security hire at a startup or growth-stage company.

  • Hands-on experience completing security questionnaires and representing your company with enterprise or health plan security teams.

  • Working knowledge of the HIPAA Security and Privacy Rules and of handling patient health data (PHI) in B2B healthcare.

  • Enough technical depth in cloud infrastructure (GCP preferred) and modern data stacks to review controls and advise engineers through implementation. This isn’t a policy-only role.

  • Comfort staying deep in the details while making judgment calls that commit the company.

Bonus Points For
  • Hands-on experience taking a company through HITRUST certification.

  • Health tech, digital health, or benefits experience, especially with health plans and large self-funded employers.

  • ISO 27001 experience.

  • Experience with compliance automation tools such as Vanta, Drata, or Secureframe.

  • CISSP, CISA, CISM, or CRISC certification.

At Leap, we’re building an outlier company with real impact — and that takes focus, energy, and commitment. If that excites you, we’d love to hear from you.
Leap is an equal opportunity employer and welcomes applicants from all backgrounds. We’re committed to building a team that reflects a diversity of perspectives, experiences, and identities.

Similar Jobs

An Hour Ago
Remote or Hybrid
US
200K-200K Annually
Expert/Leader
200K-200K Annually
Expert/Leader
Artificial Intelligence • Cloud • Payments • Software • Business Intelligence • Generative AI • Automation
Sell connectivity, data solutions, and AI-powered risk digitization software to insurance carriers and MGA clients across Canada. Responsibilities include developing strategic account plans, acquiring new logos, expanding existing accounts, managing executive relationships, negotiating renewals, forecasting sales, gathering market feedback, and meeting or exceeding quotas. The role uses a consultative solution-selling methodology and involves virtual, telephone, onsite, and industry-event engagements.
Top Skills: Ai-Powered Risk Digitization PlatformsCrm SystemsExcelMicrosoft OutlookMicrosoft PowerpointMicrosoft WordSalesforceSlack
2 Hours Ago
Remote or Hybrid
United States
84K-129K Annually
Junior
84K-129K Annually
Junior
Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Improves Global Talent processes, governance, onboarding, localization and translation workflows, information management, and technology-enabled solutions. Analyzes workflows, documents standards, coordinates stakeholders and vendors, monitors adoption and effectiveness, and leads moderate-scope improvements. The role also identifies opportunities for responsible AI and automation while maintaining appropriate human oversight, privacy, security, quality, and compliance.
Top Skills: Artificial IntelligenceAutomationCollaboration ToolsDocumentation ToolsInformation-Management ToolsReporting ToolsWorkflow Tools
2 Hours Ago
Remote or Hybrid
United States
Senior level
Senior level
Fintech • Software
Prepares quarterly and year-end income tax provisions, federal, state, and local tax returns, estimated payments, and apportionment data. Supports tax research, notices, tax planning, forecasting, transfer pricing, controls documentation, and process improvements. Coordinates with finance and corporate teams, monitors tax law changes, and maintains tax software and ledger expertise. The role requires strong knowledge of ASC 740, tax accounting research, return preparation, Excel, and corporate tax processes.
Top Skills: Asc 740ExcelFin 48OnesourceSAPSox Section 404

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account