Overview The Compliance Specialist is responsible for the day-to-day security, compliance, HIPAA governance, risk management, and audit-readiness activities of PPOk and its affiliated organizations. Working under the authority and direction of the Vice President of Enterprise Operations, who retains final approval authority, the Compliance Specialist authors and maintains the organization's HIPAA-required policies and plans, researches applicable requirements, and recommends program changes based on that analysis. The position independently performs assigned compliance activities, coordinates directly with department leaders and external parties, identifies potential compliance or security concerns, and drives assigned activities through completion. The Compliance Specialist serves as the primary administrator of the organization's Drata compliance management platform, exercising judgment in designing controls, establishing evidence requirements, and determining whether submitted evidence is sufficient to satisfy a control. The position also develops and administers the organization's compliance training program and supports preparation for SOC 2 examinations and other audits and assessments. The position works collaboratively across the organization while escalating material compliance, security, regulatory, contractual, or risk matters to the Vice President of Enterprise Operations for review, prioritization, approval, or further action.
MAJOR RESPONSIBILITIES
Position is responsible for the following duties and responsibilities:
Compliance Program Administration :
Perform and coordinate the day-to-day activities of the organization's security and compliance program under the authority and direction of the Vice President of Enterprise Operations. Maintain an enterprise compliance calendar and audit-ready documentation and evidence repositories covering required assessments, attestations, policy reviews, training requirements, and audits. Evaluate assigned compliance requirements to identify deficiencies, gaps, and missing documentation, and prepare status reports, analyses, and recommendations for leadership. Track compliance deficiencies and corrective-action plans through resolution, escalating material or overdue issues to the Vice President of Enterprise Operations.
Drata Administration and Control Design :
Serve as the primary administrator and organizational subject matter resource for the Drata compliance management platform, including controls, evidence requirements, integrations, users, policies, and personnel requirements. Design and configure controls within Drata, determine the evidence requirements necessary to demonstrate each control, and develop the supporting collection and documentation methods. Evaluate submitted evidence and determine whether it is sufficient to satisfy the applicable control, requesting additional or alternative evidence where it is not. Monitor automated and manual controls, investigate failed, incomplete, or overdue controls, and coordinate with responsible departments to remediate deficiencies. Use platform reporting to communicate compliance posture, control deficiencies, and remediation requirements to management, and recommend improvements to the organization's use of the platform. SOC 2 and
Audit Readiness :
Support ongoing preparation and readiness activities for SOC 2 examinations, including assembling the documentation and evidence necessary to demonstrate the design and operating effectiveness of applicable controls. Serve as an operational point of contact for auditors and authorized external assessors during evidence collection, testing, and interviews, and coordinate internal resources and department participation. Track audit findings, observations, exceptions, and recommendations through remediation, and support other third-party security reviews and assessments as required.
HIPAA Governance, Policies, and Plans :
Author, research, and maintain the organization's HIPAA-required policies, plans, and supporting documentation, including privacy and security policies, and present recommended changes to the Vice President of Enterprise Operations for approval. Research applicable regulatory requirements, framework updates, and industry practice, and recommend policy and program changes based on that analysis. Maintain the organization's inventory of security, compliance, privacy, and risk management policies, plans, procedures, and standards, including version control, review dates, and approvals. Maintain and update business continuity and disaster recovery documentation in coordination with Information Technology, which retains ownership of the underlying recovery capability and testing. Document core compliance processes and develop procedures and process documentation supporting consistent execution of program requirements.
Training and Awareness :
Develop and administer the organization's security, compliance, and privacy training and awareness program, including determining appropriate content, audiences, and frequency for approval. Maintain training schedules and track completion of required training, policy acknowledgements, and attestations, coordinating with department leadership regarding overdue items. Advise departments on compliance and security requirements and assist them in understanding and implementing approved obligations.
Risk and Vendor Management :
Conduct and document security, compliance, and vendor risk assessments, and maintain risk registers, assessments, and mitigation plans. Administer the Vendor Management Program, including vendor due diligence and review of SOC reports, security assessments, certifications, insurance documentation, and Business Associate Agreements. Identify vendor and organizational risk concerns and track findings, exceptions, and corrective actions through resolution, escalating legal or contractual interpretation matters to leadership or counsel.
Artificial Intelligence and Technology :
Maintain practical knowledge of artificial intelligence tools applicable to compliance, security, risk management, and audit preparation, and appropriately utilize approved AI tools to improve the efficiency and quality of compliance research, documentation, analysis, and reporting. Apply organizational security, privacy, data governance, and acceptable-use requirements when using AI-enabled technologies, and support the organization's AI governance program by maintaining documentation for approved AI use cases and AI-related policies.
Cross-Functional Coordination :
Work directly with department heads, leadership, Information Technology, Operations, Human Resources, Finance, business units, vendors, consultants, and auditors to obtain required compliance evidence, documentation, and corrective actions. Communicate compliance requirements clearly and professionally in writing and verbally, and provide appropriate follow-up regarding outstanding requests. Maintain confidentiality and appropriately safeguard sensitive, confidential, proprietary, security-related, and regulated information. Perform other security, compliance, risk management, audit, and governance responsibilities as assigned by the Vice President of Enterprise Operations.
POSITION'S REQUIREMENTS/EXPERIENCE/QUALIFICATIONS
Required:
Bachelor's degree in business, healthcare administration, information systems, risk management, compliance, or a related field, or equivalent relevant experience. Minimum of two (2) years of experience in compliance, risk management, audit, information security governance, healthcare regulatory compliance, or a closely related function. Working knowledge of HIPAA privacy and security requirements, including required policies and plans and the appropriate handling of protected health information. Familiarity with recognized security and compliance frameworks such as SOC 2 and NIST, including controls, evidence, and control testing concepts. Demonstrated ability to author, research, and maintain policies, procedures, and process documentation, and to exercise judgment in evaluating whether documentation satisfies a stated requirement. Strong written and verbal communication, organizational, analytical, and stakeholder-coordination skills, with the ability to manage multiple concurrent assignments and projects efficiently. Proficiency in Microsoft Office products, especially Excel and AI tools.
Preferred:
Experience administering a governance, risk, and compliance (GRC) or compliance automation platform such as Drata, Vanta, Secureframe, or similar. Experience supporting SOC 2 examinations, including evidence collection, control testing, exceptions, and remediation. Experience in a healthcare, Pharmacy Benefits Management (PBM), Medicare, self-insured health plan, or other highly regulated environment. Experience with third-party or vendor risk management, including review of SOC reports, security questionnaires, Business Associate Agreements, and insurance documentation.
ADDITIONAL REQUIREMENTS
Employment is contingent upon successful completion of a background screening. The position requires access to confidential, proprietary, and protected health information, subject to all applicable PPOk access, training, and confidentiality requirements. Ability to sit and work at a computer for extended periods of time. Ability to occasionally stand, walk, bend, reach, and move throughout the workplace as needed to perform job duties. Ability to perform the essential functions of the position with or without reasonable accommodation.
PHYSICAL REQUIREMENTS/WORK ENVIRONMENT
Ability to work remote and travel up to 30% of the time including overnight
NOTE :
The above statements are intended to describe the general nature and level of work performed by an employee in this position. These statements are not to be construed as an exhaustive list of all responsibilities, duties, and skills required of employees in this position. Responsibilities may be modified or assigned based upon organizational needs and at the direction of the Vice President of Enterprise Operations.
Pay:
$50,000.00 - $60,000.00 per year
Benefits:
401(k) Dental insurance Health insurance Paid time off Vision insurance