SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Candid Health is building the modern financial backbone for American healthcare by automating Revenue Cycle Management (RCM). The company processes billions in claims annually for over 200 healthcare organizations, using AI agents and configurable rules engines to handle complex medical claims end-to-end.
You will build Candid Health's first in-house GRC (Governance, Risk, and Compliance) program from the ground up, treating compliance as an engineering and data problem rather than a manual administrative function. This is a hands-on technical role focused on automation, not policy writing or screenshot collection.
Key responsibilities include:
**Compliance Automation & Engineering**: Develop automated scripts and API integrations to collect compliance evidence directly from system sources. Write and deploy infrastructure-as-code and policy enforcement rules to enforce security baselines automatically. Maintain live compliance dashboards and alerts that flag configuration drift or policy violations in real time. Partner with Legal on Medicare and Medicaid compliance and future due diligence projects.
**Framework Mapping & Control Architecture**: Convert regulatory and industry standards (SOC 2, HiTrust, PCI, HIPAA) into clear, testable technical controls. Map single technical controls across multiple overlapping frameworks to eliminate redundant work. Work alongside DevOps and Software Engineering teams to build compliance controls directly into CI/CD pipelines without slowing delivery.
**Risk Management & Audits**: Lead technical audit readiness and external audit engagements using programmatic evidence pipelines. Automate vendor risk management workflows and API-driven vendor evaluations. Build continuous risk tracking tools fed by live vulnerability telemetry and identity logs.
Required: 3+ years in technical security (Security Engineering, Cloud Security, or Technical GRC). Proficiency in Python, TypeScript, SQL with hands-on API, log parsing, and database querying experience. Hands-on experience with at least one primary cloud platform (GCP preferred) and Infrastructure-as-Code tools like Terraform. Deep familiarity with core compliance frameworks. Understanding of CI/CD pipelines, Git workflows, and container environments (Docker/Kubernetes).
Preferred: Security certifications (CISSP, CISA, CRISC, AWS Certified Security – Specialty, CCSP). Experience with Policy-as-Code engines. Background in software development, DevOps, or platform engineering. Experience with modern continuous compliance platforms (Vanta, Drata, Anecdotes).