SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
AKASA is a leading generative AI platform for healthcare revenue cycle management, helping health systems streamline operations and improve clinical documentation. The company has raised over $205M from top-tier investors and serves major health systems including Cleveland Clinic, Duke, Stanford, and Johns Hopkins.
As Director of Compliance & AI Governance, you will own and evolve AKASA's compliance program as the company scales rapidly. This is a strategic, hands-on role ideal for someone with healthcare SaaS or AI compliance experience who wants to build a modern, engineering-forward program.
Key responsibilities include:
- Own the full compliance certification portfolio (HITRUST CSF, SOC 2 Type II, HIPAA) from control design through audit coordination and remediation. Evaluate and pursue new certifications like ISO 27001, ISO 42001, and HITRUST AI as needed.
- Define compliance roadmaps and drive cross-functional alignment on regulatory requirements across the organization.
- Build AKASA's AI governance program grounded in the NIST AI RMF, partnering with Engineering, Product, and Legal to establish model risk assessments, AI use policies, and documentation meeting enterprise expectations.
- Drive compliance automation as a first principle: implement GRC and continuous control monitoring tools, automate evidence collection across the tech stack (Okta, Google Workspace, Kandji, SentinelOne, Nightfall, AWS), and leverage AI tools for policy drafting and audit preparation.
- Own the full policy lifecycle including authoring, review cadences, exception handling, attestation campaigns, and version control.
- Serve as the compliance face for customers and prospects: lead security questionnaire responses, support enterprise sales cycles, manage customer audits, and maintain trust artifacts.
- Oversee vendor risk management, annual risk assessments, security awareness and HIPAA training, and incident response exercises in partnership with Security and IT.
- Partner with Legal and Security on contractual security obligations.
You'll join a high-leverage team with immediate ownership and room to build. The role requires 3+ days per week on-site at the South San Francisco headquarters.