Cybersecurity GRC Lead: Engineer Automated Compliance at Scale
About Candid Health
The U.S. healthcare system faces a hidden, massive problem: the complex, ever-changing process of getting doctors paid by insurance companies. Mountains of paperwork, constant rule changes, and rejected claims lead to unexpected patient charges and billions lost to administrative bureaucracy—diverting focus from crucial patient care.
Candid Health is disrupting this broken system. Founded by former Palantir leaders who experienced these pain points firsthand, we are building the modern financial backbone for American healthcare. Instead of patching legacy software, we've rebuilt the underlying infrastructure from the ground up.
Our core product is an autonomous Revenue Cycle Management (RCM) platform. Powered by AI agents and a configurable rules engine, it unifies clinical, billing, and insurance data into a single, intelligent system. It acts as an automated back-office, handling complex medical claims from submission to payment with first-pass accuracy, drastically cutting administrative costs, and accelerating cash flow for healthcare providers.
Today, over 200 rapidly growing healthcare organizations, from digital health innovators to large enterprise medical groups, trust Candid Health to process billions in claims annually. Backed by top investors like Sixth Street Growth, Oak HC/FT, 8VC, and Y Combinator, we recently secured $120 million in Series D funding to fuel the AI-driven transformation of healthcare payments and eliminate administrative friction for good.
Role Overview
Are you a security professional who believes GRC isn't just about checklists, but about code, automation, and data? Candid Health is seeking our first Security GRC Lead to forge a groundbreaking, engineering-centric compliance program from the ground up.
This isn't your typical GRC role. You'll architect and implement compliance-as-code, build automated evidence pipelines, and establish continuous controls monitoring across our GCP infrastructure, identity systems, and CI/CD. You will transform static, point-in-time audits into a dynamic, real-time security telemetry system, ensuring our platform is resilient, secure, and always audit-ready. This is a unique opportunity to shape our security posture at a rapidly scaling, mission-driven company.
Key Responsibilities
1) Compliance Automation & Engineering
Pioneer automated evidence collection through scripts and API integrations, moving beyond manual screenshots to collect data directly from system sources.
Design and deploy infrastructure-as-code and policy enforcement rules to embed security baselines proactively and automatically.
Develop live compliance dashboards and real-time alerts that flag configuration drift or policy violations the moment they occur.
Collaborate with our Legal team on critical Medicare and Medicaid compliance initiatives.
Partner closely with legal and finance teams on future due diligence and compliance projects.
2) Framework Architecture & Control Design
Translate complex regulatory, security, and industry standards (SOC 2, HiTrust, PCI, HIPAA) into clear, testable technical controls.
Optimize control mapping across multiple overlapping frameworks to maximize efficiency and eliminate redundant work.
Work alongside DevOps and Software Engineering teams to seamlessly integrate compliance controls directly into CI/CD pipelines, accelerating secure delivery without slowing down development.
3) Advanced Risk Management & Audit Leadership
Lead technical audit readiness and external audit engagements, leveraging programmatic evidence pipelines for streamlined, data-driven processes.
Automate vendor risk management workflows and API-driven vendor evaluations.
Build continuous risk tracking tools, fed by live vulnerability telemetry and identity logs, replacing static quarterly surveys with dynamic insights.
Required Qualifications
3+ years of experience in a technical security role, such as Security Engineering, Cloud Security, or Technical GRC.
Proficiency in Python, TypeScript, and SQL, with hands-on experience interacting with APIs, parsing logs, and querying databases.
Proven experience with at least one primary cloud platform (GCP preferred) and Infrastructure-as-Code tools such as Terraform.
Deep familiarity with core security and compliance frameworks such as SOC 2, HiTrust, PCI, and HIPAA.
Understanding of CI/CD pipelines, Git workflows, and container environments (Docker/Kubernetes).
Preferred Qualifications
Relevant industry certifications such as CISSP, CISA, CRISC, AWS Certified Security – Specialty, or CCSP.
Experience with Policy-as-Code engines (e.g., OPA, Sentinel).
Background in software development, DevOps, or platform engineering.
Experience with modern continuous compliance platforms (e.g., Vanta, Drata, Anecdotes).