1

Hitrust Jobs in California (NOW HIRING)

Has owned a recurring external audit cycle end-to-end (e.g., SOC 2, ISO, PCI, HITRUST) - designed evidence collection, mapped controls, ran the auditor relationship, and made the next cycle ...

Privacy and Compliance Lead

Mountain View, CA · On-site +1

$130K - $165K/yr

Leading/Managing External Audits including MARSe, ARC-AMPE (NIST 800-53 rev5), SOC2 Type2, ISO27001, HITRUST * Assisting in audit activities - Interfacing with the Auditors, translating audit ...

Senior Software Engineer

San Francisco, CA · On-site

$144K - $190K/yr

Knowledge of healthcare compliance frameworks (HIPAA, HITRUST, SOC 2). Nice to Have * Experience with real-time data pipelines or event-driven architectures * Background in analytics, population ...

Privacy and Compliance Lead

Mountain View, CA · On-site

$185K/yr

Leading/Managing External Audits including MARSe, ARC-AMPE (NIST 800-53 rev5), SOC2 Type2, ISO27001, HITRUST * Assisting in audit activities - Interfacing with the Auditors, translating audit ...

Exposure to security‑led or compliance‑conscious environments (SOC 2, HIPAA, HITRUST). * Some PowerShell or scripting exposure and an interest in automation. What We're Looking For * Highly ...

New

Experience in healthcare, dental, or a similarly regulated enterprise environment with awareness of HIPAA Privacy and Security Rules and HITRUST CSF requirements. * Familiarity with AI-augmented ...

Senior DevOps Engineer

Los Angeles, CA · Remote

$140K - $179K/yr

Partner with Security & Compliance to support HIPAA, HITRUST, SOC 2, OWASP, NIST, auditability, policy enforcement, software supply chain security, and risk mitigation expectations. * Support ...

HITRUST * 21 CFR Part 11 * GxP or validated systems environments * Knowledge of Customer Data Platform (CDP) concepts. * Understanding of email deliverability, authentication, and marketing ...

Senior DevOps Engineer

Los Angeles, CA · Remote

$140K - $179K/yr

Partner with Security & Compliance to support HIPAA, HITRUST, SOC 2, OWASP, NIST, auditability, policy enforcement, software supply chain security, and risk mitigation expectations. * Support ...

Showing results 41-60

Hitrust information

See California salary details

$70K

$119.9K

$177.7K

How much do hitrust jobs pay per year?

As of Sep 13, 2026, the average yearly pay for hitrust in California is $119,851.00, according to ZipRecruiter salary data. Most workers in this role earn between $95,474.00 and $143,457.00 per year, depending on experience, location, and employer.

What is a HITRUST?

A HITRUST job typically involves working with the HITRUST Common Security Framework (CSF) to help organizations achieve and maintain regulatory compliance, data security, and risk management. Professionals in this role may conduct risk assessments, implement security controls, and guide organizations through the HITRUST certification process. Common job titles include HITRUST Consultant, Compliance Analyst, and Security Auditor. These roles require expertise in cybersecurity, regulatory frameworks, and industry best practices.

What does a HITRUST professional do?

As a HITRUST professional, you will be responsible for guiding organizations through the HITRUST CSF certification process, conducting comprehensive risk and gap assessments, and creating remediation plans to address compliance issues. Your work will often involve collaborating with IT, compliance, and executive teams to implement policies, improve security controls, and ensure adherence to industry standards like HIPAA and HITECH. You can also expect to manage regular audits, prepare documentation, and educate staff on emerging security requirements. This role plays a key part in maintaining regulatory compliance and safeguarding sensitive patient data.

What skills and qualifications are needed for a HITRUST position?

To thrive in a HITRUST professional role, you need a robust understanding of information security, healthcare compliance, and risk assessment, typically supported by a relevant degree or certifications such as HITRUST Certified CSF Practitioner (CCSFP). Proficiency with regulatory frameworks like HIPAA, GRC tools, and HITRUST’s MyCSF platform is crucial. Strong attention to detail, analytical thinking, and effective communication are key soft skills for working with cross-functional teams and translating complex requirements. These skills enable professionals to ensure organizational compliance, manage complex security assessments, and foster trust in healthcare data protection programs.

What cities in California are hiring for Hitrust jobs?

Cities in California with the most Hitrust job openings:

Infographic showing various Hitrust job openings in California as of September 2026, with employment types broken down into 95% Full Time, and 5% Contract. Highlights an 74% In-person, 7% Hybrid, and 19% Remote job distribution, with an average salary of $119,851 per year, or $57.6 per hour.

Security & Compliance Manager

South San Francisco, CA • On-site

Full-time

Medical, Dental, Vision, Retirement, PTO

Re-posted 14 days ago


Job description

About Phylo
Phylo is an applied research lab building agentic intelligence to accelerate discovery for every biomedical scientist. We believe AI agents will fundamentally transform how biomedical research is done. Our fast-growing team brings together researchers and engineers across AI and biology, commercializing the Biomni platform.
Our growing team brings together world class researchers and engineers across AI and biology. Backed by a $13.5M seed round led by a16z, Menlo Ventures and Anthropic, and advised by Nobel Prize laureate and pioneering biologists, Phylo is building the next generation of AI systems for the life sciences.
About the Role
We're hiring a hands-on Security & Compliance Lead to build and scale Phylo's security, privacy, and compliance program. You'll own our compliance roadmap, lead audits and customer reviews, and work closely with engineering to turn requirements into practical controls.
What you'll do as a Security & Compliance Manager at Phylo:
  • Own Phylo's security and compliance roadmap.
  • Lead SOC 2, ISO 27001 and GDPR readiness, audits, evidence collection, and remediation.
  • Build HIPAA-ready processes for workloads involving protected health information.
  • Assess and plan for FedRAMP, NIST, privacy, and life-sciences requirements where applicable.
  • Partner with engineers to implement scalable controls across cloud infrastructure, applications, and AI systems.
  • Lead customer questionnaires, RFPs, due diligence, and security conversations.
  • Run risk assessments and drive remediation across systems, vendors, and processes.
  • Maintain lightweight policies, customer-facing security documentation, and compliance reporting.
  • Automate evidence collection, monitoring, and other compliance workflows.

What We're Looking For:
  • 5+ years in security GRC, compliance, or a security engineering-adjacent role.
  • Experience leading SOC 2, ISO 27001, HIPAA, FedRAMP, or similar programs.
  • Strong understanding of cloud and application security.
  • Ability to translate regulatory requirements into technical controls.
  • Experience supporting audits and enterprise customer security reviews.
  • Strong cross-functional communication and program ownership.
  • A pragmatic, hands-on approach suited to an early-stage company.

Nice to Haves:
  • Experience building a security program from an early stage.
  • Background in healthcare, life sciences, enterprise AI, or cloud infrastructure.
  • Experience with HIPAA, FedRAMP, NIST SP 800-53, HITRUST, or GDPR.
  • Familiarity with AI governance frameworks such as NIST AI RMF or ISO 42001.
  • Experience automating GRC and compliance workflows.

Why Join Us?
  • Competitive salary and equity share in building the future of biomedical discovery
  • Full medical, dental, and vision coverage, including free therapy sessions and eyewear stipend
  • 401(k) to help you build long-term financial security (US only)
  • Unlimited PTO to recharge when you need it (US only)
  • Lunch and snacks when you're in the office
  • Regular team offsites and company events
  • A culture of excellence and speed - we move fast, think big, and support each other every step of the way
  • Your work will directly impact our mission to 100X biomedical discoveries through AI