Biograph
Senior GRC Engineer
New York, NY · Senior
Sponsorship not specified$150k-$200kDetected 62 days ago
PythonGoBashGCPCloud PlatformsTerraformCI/CDDevOpsRESTData ScienceCybersecurityComplianceHIPAALeadershipCommunication
About the role
- Biograph is looking for a founding GRC Engineer to help us mature and scale a modern, automation-first compliance program to secure our data-driven approach to preventative care.
- Our small and nimble engineering team thrives on ownership and autonomy. We're building foundational systems with an eye toward scalability and an emphasis on best practices. We're looking for an "engineer-first" GRC practitioner who values product and communication as much as technical excellence. Joining this early provides a great opportunity to help
Responsibilities
- Your immediate mission will be to lead and advance our HIPAA compliance initiatives, ensuring rigorous security standards across our environment.
- GRC Engineering & Automation: Own the implementation, configuration, and maintenance of continuous compliance automation platforms (e.g., Vanta, Drata, or Secureframe), integrating them deeply into our tech stack.
- Infrastructure Integration: Design and build automated evidence collection workflows using scripts (Python, Go, or similar) to pull data from our GCP environment, identity providers, and SaaS tools.
- Partner with DevOps to embed compliance checks directly into CI/CD pipelines.
- Own the implementation, configuration, and maintenance of continuous compliance automation platforms (e.g., Vanta, Drata, or Secureframe), integrating them deeply into our tech stack.
Requirements
- Strong working knowledge of SOC 2 and HITRUST.
- Proven experience implementing and maximizing modern continuous compliance tooling.
- Experience or familiarity with FedRAMP (Moderate/High), Infrastructure as Code (Terraform), or previous experience in the BioTech/HealthTech industry.
- Build and Execute: Lead the strategy and execution of our HIPAA compliance operations, identifying technical gaps, authoring policies, and implementing required controls.
- Experience building, scaling, and modernizing compliance programs in fast-paced startup environments.
- Deep, practical understanding of HIPAA requirements and how to map them to technical cloud controls. Strong working knowledge of SOC 2 and HITRUST.
- Excited about applying technology to improve healthcare.
- COMP | PERKS | BENEFITS
- $150,000 - $200,000 per year
- Equity in an early stage company
- Medical, dental, and vision insurance
Skills
- 6+ years of professional experience in Security Engineering, GRC Engineering, DevOps, or Cloud Security roles.
- Hands-on expertise with Google Cloud Platform (GCP) architecture, IAM, logging, and security best practices.
- Strong programming/scripting skills (e.g., Python, Bash) and experience working with REST APIs to automate evidence gathering.
Compensation
- $150,000 - $200,000 per year
Benefits
- Conduct internal risk assessments and threat modeling tailored to cloud-native, health care environments.
- Work with a forward-thinking team that merges the latest in health technology, data science, and personalized care.
- Be the voice for our members' health journeys, influencing the development of cutting-edge tools and technologies to enhance their lives.
Company info
- With Biograph, you're not just stepping into a role-you're joining a company where growth and development are prioritized.
- As we continue to scale and innovate, you will have opportunities to expand your expertise, take on new challenges, and make meaningful contributions to the broader healthcare landscape.
- We are building new impactful products and need to secure our infrastructure for the future.
Apply directly at Biograph →Create a free account for alerts like thisView Biograph immigration profile
This listing is sourced directly from Biograph's careers page and normalized into a canonical job model.