Brado Ai

1 job near Columbus, OH

Director, Compliance Brado AI · Individual contributor, reporting to Chief Financial Officer About the role The Director of Compliance owns and advances Brado AI's compliance program as we scale.

New

Director, Compliance

Brado AI Inc

Saint Louis, MO • On-site

Full-time

Posted yesterday

New


Job description

Description:

Director, Compliance


Brado AI · Individual contributor, reporting to Chief Financial Officer


About the role

The Director of Compliance owns and advances Brado AI's compliance program as we scale. This person bridges regulatory rigor with practical business execution, serving as our subject-matter authority on HIPAA, HiTRUST, and SOC 2. They build a culture of compliance across every team, partner with leaders and employees on day-to-day compliance activities, and keep the organization in a constant state of audit readiness.


What you'll do


Program ownership & strategy

  • Manage the end-to-end compliance program across for the company’s client offerings: HIPAA Privacy and Security Rules, SOC 2 (Type II), and HiTRUST CSF.
  • Develop, maintain, and continuously improve policies, procedures, and controls to address evolving regulatory and contractual requirements.
  • Own execution of the compliance roadmap set jointly with the VP, Legal & Compliance; support preparation of executive and board updates as needed. Includes evaluating a potential move to a single HiTRUST certification across both platforms, a decision still pending.
  • Oversee development and ongoing maintenance of policies, guidelines, and systems for data privacy and security, working with domain experts to define and implement key controls.
  • Own and maintain the legislative matrix: monitor federal and state regulatory changes and updates, and document where and how each change impacts the business and any actions required.


Audit & certification management

  • Lead ISCC meetings.
  • Lead and manage all external audits, assessments, and renewals — including the annual SOC 2 Type II engagement and the HiTRUST engagement — from scoping through report issuance.
  • Coordinate with third-party auditors and assessors.
  • Continuously monitor compliance with privacy and security frameworks so the organization is always audit-ready and in compliance.
  • Manage and maintain Vanta as the system of record for continuous control monitoring and evidence collection.
  • Conduct quarterly department-level compliance audits on a rotating basis, in addition to company-wide audits, to spread documentation and remediation work evenly across the year.


Risk & incident management

  • Operate and mature the company's risk management framework, including regular risk assessments and risk register maintenance.
  • Own the HIPAA Breach Notification process; lead investigations and coordinate required notifications to Covered Entities and vendors.
  • Partner with Engineering and IT on vulnerability, patch management, and remediation prioritization.
  • Serve as the point of contact for incident reporting and management, coordinating investigation and resolution with IT and Legal.
  • Own disaster recovery and business continuity (DRBC) planning and execution, in partnership with IT.


Cross-functional collaboration

  • Work closely with sales and contract teams to support customer security and privacy questionnaires, enterprise procurement processes, and business associate agreement (BAA) review.
  • Partner with HR to deliver workforce compliance training, including annual HIPAA, privacy, and security awareness programs.
  • Advise Product and Engineering on privacy-by-design principles and secure development practices.
  • Facilitate the compliance committee, including developing agendas, reports, and information as requested by the committee, senior leadership, and/or the Board of Directors.
  • Offer coaching and mentorship for managers and employees throughout Brado AI on domain expertise.
Requirements:

What we're looking for

  • 7+ years of experience in health care regulatory compliance and compliance leadership, with a deep understanding of HIPAA, key transactional systems (e.g. EMR), and ancillary communication systems (e.g. CRM).
  • Familiarity with the compliance and security expectations of health system and health payor clients in a B2B SaaS sales cycle, including vendor risk assessments and enterprise procurement review.
  • Experience operating in a SaaS or cloud-native environment (AWS or Azure).
  • Bachelor's degree or equivalent experience.
  • Willingness to complete all Brado AI and client-required training on healthcare industry regulations, including HCP processes and reporting, ethics, confidentiality, data privacy and security, and harassment prevention.