Compliance Lead

Aegis VenturesColumbus, OH
Hybrid

About The Position

As our Compliance Lead, you'll own and operationalize our compliance program — turning our regulatory obligations into a scalable, audit-ready system that earns the trust of health systems, investors, and the patients behind the data. Avandra handles protected health information across a growing network of health system partners. This is a build role. You'll work alongside our IT & Security Manager, contributing to security posture while owning the compliance workstream end-to-end. If you're energized by standing up programs — not just maintaining them — this is your role.

Requirements

  • 5+ years of hands-on compliance experience at a B2B SaaS or healthcare technology company.
  • Demonstrated ownership of HIPAA compliance programs; working knowledge of HITRUST (i1 or r2).
  • SOC 2 Type II experience — you've coordinated evidence, managed auditors, and closed gaps.
  • Ability to work cross-functionally with Engineering on technical controls without needing a translator.
  • Strong written communication — policy writing, questionnaire responses, and executive summaries are all in your wheelhouse.
  • Self-starter mentality; you build structure in ambiguity.

Nice To Haves

  • Experience supporting compliance assessments or integration work in M&A contexts.
  • Familiarity with multi-entity or subsidiary compliance program management.
  • CISSP, CISM, HCISPP, or equivalent certification.
  • Experience with compliance automation tooling (Vanta, Drata, Tugboat Logic, etc.).
  • Familiarity with PHI data flows, health data integrations, and healthcare data contracts.
  • Prior experience at a growth-stage startup where the compliance program was being created, not inherited.

Responsibilities

  • Own Avandra's compliance roadmap across HIPAA, HITRUST, and SOC 2; drive certification timelines and recertification cycles.
  • Maintain the risk register and conduct company-wide risk assessments on a defined cadence.
  • Author, publish, and maintain security and compliance policies and procedures.
  • Evaluate emerging frameworks (ISO 27001, NIST CSF) for relevance as we scale.
  • Coordinate evidence collection, gap assessments, and control testing across Engineering, Operations, and People teams.
  • Manage audit relationships with external assessors and compliance-automation platforms.
  • Maintain audit-ready documentation at all times — not just at audit season.
  • Own the vendor security intake and assessment process.
  • Respond to customer security questionnaires, RFPs, and due diligence requests; represent Avandra's compliance posture credibly to health system partners.
  • Conduct compliance assessments for acquisition targets — evaluate PHI handling practices, existing certifications, policy maturity, and open audit findings.
  • Own the post-acquisition compliance integration playbook: gap analysis, remediation roadmap, and timeline to bring acquired entities under the Avandra compliance umbrella.
  • Assess and rationalize subsidiary compliance programs; identify redundancies, coverage gaps, and certification consolidation opportunities.
  • Serve as the compliance integration contributor in cross-functional M&A workstreams alongside Legal, Finance, and Engineering.
  • Maintain a consolidated compliance posture across all entities — ensuring no subsidiary operates outside Avandra's policy and control framework.
  • Develop and deliver company-wide compliance training, including onboarding programs tailored to acquired teams.
  • Translate complex regulatory requirements into clear, actionable guidance for non-compliance teams.

Benefits

  • Competitive salary, equity, comprehensive benefits, and hybrid work flexibility.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service