Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Security GRC and Operations Lead  image - Rise Careers
Job details

Security GRC and Operations Lead

About Us:

Hippocratic AI is developing the first safety-focused Large Language Model (LLM) for healthcare. Our mission is to dramatically improve healthcare accessibility and outcomes by bringing deep healthcare expertise to every person. No other technology has the potential for this level of global impact on health.

Why Join Our Team:

  • Innovative mission: We are creating a safe, healthcare-focused LLM that can transform health outcomes on a global scale.

  • Visionary leadership: Hippocratic AI was co-founded by CEO Munjal Shah alongside physicians, hospital administrators, healthcare professionals, and AI researchers from top institutions including El Camino Health, Johns Hopkins, Washington University in St. Louis, Stanford, Google, Meta, Microsoft and NVIDIA.

  • Strategic investors: Raised $137 million from top investors including General Catalyst, Andreessen Horowitz, Premji Invest, SV Angel, NVentures (Nvidia Venture Capital), and Greycroft.

  • Team and expertise: We are working with top experts in healthcare and artificial intelligence to ensure the safety and efficacy of our technology.

For more information, visit www.HippocraticAI.com.

We value in-person teamwork and believe the best ideas happen together. Our team is expected to be in the office five days a week in Palo Alto, CA unless explicitly noted otherwise in the job description

About the role:

As the Security GRC and Operations Lead at Hippocratic AI, you'll lead the charge to ensure security compliance across all our product offerings. Your role involves managing a comprehensive information security GRC program, navigating new and existing compliance standards, and building the security operations program to ensure proper oversight for monitoring and data compliance. You will be a member of the security team reporting to the CISO.

Responsibilities:

  • Work with the CISO and other stakeholders to Identify, assess, and prioritize IT risks, advising stakeholders on appropriate courses of action to mitigate or eliminate risk. Serve as a trusted resource for healthcare-related risk and compliance inquiries.

  • Implement and maintain relevant legal and regulatory requirements, including SOC2, ISO, HITRUST, HIPAA Privacy & Security, HITRUST and other CMS regulations and guidelines updated by the Federal Government. 

  • Be the leader and central point of contact for ongoing audits. Work across all departments including sales, engineering, devops and clinical teams.

  • Develop and optimize audit evidence collection and responses for Request for Proposals (RFPs)

  • Develop targeted training programs to educate staff on patient privacy, data security, and regulatory requirements and foster a culture of compliance and accountability across clinical and administrative teams.

  • Facilitate a metrics and reporting framework to measure program efficiency and effectiveness, ensuring appropriate resource allocation and increasing security maturity.

  • Prepare clear, actionable reports for leadership regarding compliance gaps and solutions. Assist in executive reporting, tabletop exercises and Build robust dashboarding and tooling to support the ongoing operational monitoring and detection capabilities.

 

Qualifications & Skills

  • Education & Experience

    • Bachelor’s degree with additional Certifications (e.g., CISM, CHPC, CRISC) preferred.

    • 5+ years in GRC, compliance, or audit, ideally within a healthcare, pharma or payor environment.

  • Technical & Professional Skills

    • Familiarity with healthcare regulations and frameworks (HIPAA, HITRUST).

    • Proven experience in risk assessments, auditing, and compliance reviews.

    • Strong analytical, problem-solving, and communication skills.

  • Soft Skills

    • Startup experience

    • Detail-oriented with high ethical standards.

    • Ability to collaborate effectively across clinical, administrative, and technical teams.

    • Organized and adaptable to shifting priorities in a fast-paced healthcare setting.

Other Attributes:

  • High personal integrity, ability to handle confidential matters, and demonstrate judgment and maturity.

  • Initiative, dependability, and ability to work with minimal supervision.

Hippocratic AI Glassdoor Company Review
4.8 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
Hippocratic AI DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Hippocratic AI
Hippocratic AI CEO photo
Munjal Shah
Approve of CEO

Average salary estimate

$135000 / YEARLY (est.)
min
max
$120000K
$150000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Security GRC and Operations Lead , Hippocratic AI

At Hippocratic AI, we’re on a mission to revolutionize healthcare with our groundbreaking safety-focused Large Language Model (LLM). As the Security GRC and Operations Lead in Palo Alto, you’ll play a key role in this innovative endeavor by ensuring security compliance across all our offerings. You’ll be at the forefront of managing our comprehensive information security GRC program while navigating various compliance standards. You'll collaborate closely with our CISO and stakeholders to identify, assess, and prioritize IT risks, providing valuable insights to mitigate those risks effectively. Part of your exciting new role will involve implementing essential regulatory requirements within healthcare, encompassing SOC2, ISO, and HIPAA, ensuring our technology aligns with industry standards. You’ll lead the charge during ongoing audits, working closely with sales, engineering, and clinical teams to gather evidence and prepare responses for RFPs. Your ability to educate our staff on patient privacy and data security establishes a culture of compliance and accountability. With your strong analytical skills, you’ll develop metrics to measure program effectiveness and produce actionable reports for our leadership team. If you’re looking to make an impactful difference in healthcare alongside a talented team of experts, Hippocratic AI is the place to be!

Frequently Asked Questions (FAQs) for Security GRC and Operations Lead Role at Hippocratic AI
What are the main responsibilities of the Security GRC and Operations Lead at Hippocratic AI?

The Security GRC and Operations Lead at Hippocratic AI is responsible for managing the information security GRC program, ensuring compliance with regulations like SOC2, ISO, and HIPAA. This role also involves conducting risk assessments, leading audits, providing training to staff on data security, and developing metrics for monitoring program efficiency.

Join Rise to see the full answer
What qualifications are needed for the Security GRC and Operations Lead position at Hippocratic AI?

Candidates should possess a Bachelor’s degree and ideally have additional certifications such as CISM, CHPC, or CRISC. They should also have over 5 years of experience in GRC, compliance, or audit, particularly within healthcare or pharma environments, demonstrating strong analytical and problem-solving skills.

Join Rise to see the full answer
How does the Security GRC and Operations Lead contribute to compliance at Hippocratic AI?

The Security GRC and Operations Lead plays a crucial role in ensuring compliance by implementing and maintaining legal requirements, conducting risk assessments, and leading staff education efforts. Their work helps establish a culture of security and regulatory adherence across all departments.

Join Rise to see the full answer
What skills are essential for the Security GRC and Operations Lead role at Hippocratic AI?

Essential skills for the Security GRC and Operations Lead include strong analytical and problem-solving abilities, effective communication, and a detailed understanding of healthcare regulations. Furthermore, individuals must possess soft skills such as initiative, adaptability, and the ability to collaborate across various teams.

Join Rise to see the full answer
Why is working at Hippocratic AI exciting for a Security GRC and Operations Lead?

Working at Hippocratic AI offers the unique opportunity to be part of a transformative mission in healthcare technology. The role provides a chance to influence systemic change, collaborate with top industry experts, and contribute to a culture prioritizing safety and efficacy in innovative healthcare solutions.

Join Rise to see the full answer
Common Interview Questions for Security GRC and Operations Lead
Can you describe your experience with HIPAA regulations as a Security GRC and Operations Lead?

When answering, focus on your direct experience with HIPAA compliance, including any relevant projects where you ensured adherence to these regulations, how you trained staff, and any audits you successfully managed.

Join Rise to see the full answer
How do you prioritize IT risks in your role as a Security GRC and Operations Lead?

Share your methodology for assessing risk factors, such as conducting regular audits or using assessment tools. Illustrating your analytical approach and decision-making process will demonstrate your capability in this role.

Join Rise to see the full answer
What strategies do you use to train staff on data security?

Discuss the types of training programs you’ve developed and implemented, emphasizing interactive training methods, workshops, or ongoing education initiatives that promote a culture of security within the organization.

Join Rise to see the full answer
How do you handle compliance audits within a fast-paced environment?

Provide examples of your experiences managing audits, highlighting your organizational skills and your ability to keep all stakeholders informed. Mention how you ensure that audits are thorough yet efficient.

Join Rise to see the full answer
Describe a time you improved compliance processes in your previous role.

Use the STAR method (Situation, Task, Action, Result) to structure your answer. Talk about a specific challenge and the proactive steps you took that led to measurable improvements in compliance.

Join Rise to see the full answer
What is your approach to developing metrics for measuring program effectiveness?

Discuss the key performance indicators (KPIs) you believe are vital and how you’ve used data to inform adjustments and reporting for ongoing improvement of compliance programs.

Join Rise to see the full answer
How do you ensure effective communication across clinical, administrative, and technical teams?

Share methods you've utilized for fostering collaboration, such as regular cross-department meetings or integrated communication tools, highlighting the importance of clear information flow for compliance.

Join Rise to see the full answer
What challenges have you faced in data security audits, and how did you overcome them?

Reflect on any specific challenges, whether due to resource limitations or resistance from teams. Explain the strategies you used to address these issues and achieve a successful audit outcome.

Join Rise to see the full answer
How do you keep up with changing regulations in healthcare?

Explain your proactive approach, such as attending relevant workshops, participating in industry forums, or subscribing to regulatory updates, which will underline your commitment to ensuring compliance.

Join Rise to see the full answer
Can you explain the importance of a metrics and reporting framework in your role?

Describe how such frameworks inform decision-making, resource allocation, and highlight compliance gaps that require attention, stressing their role in continuous improvement of security measures.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 3 days ago
Photo of the Rise User
Posted 3 days ago
Posted 2 days ago
Photo of the Rise User
ServiceNow Remote 6 Temasek Boulevard Suite 40-01, Singapore, Singapore
Posted 6 days ago
Inclusive & Diverse
Mission Driven
Rise from Within
Diversity of Opinions
Work/Life Harmony
Empathetic
Feedback Forward
Take Risks
Collaboration over Competition
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Conferences Stipend
Paid Time-Off
Maternity Leave
Equity
Photo of the Rise User
College Track Hybrid Denver, Colorado
Posted 2 days ago
Photo of the Rise User
Posted 18 hours ago
Photo of the Rise User
CLEAR - Corporate Hybrid New York, New York, United States
Posted 12 hours ago
Photo of the Rise User
Posted 6 days ago

Hippocratic AI is building a safety-focused large language model (LLM) for the healthcare industry. We believe that generative AI has the potential to massively increase healthcare access the world over but has to be built and tested responsibly. ...

46 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
January 8, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!