Compliance & Audit Manager
Own the compliance program that clients audit us against: SOC 2 Type II, ISO 27001 and HIPAA, kept real rather than performative.
The role
What this job actually is
You own our compliance program across SOC 2 Type II, ISO 27001 and HIPAA. That means keeping controls genuinely operating, not just documented: evidence collected on schedule, gaps remediated, and the organisation ready when an auditor or a client security team arrives. You are also the person who answers client security questionnaires and stands behind the answers.
Ownership
What you will own
Audit readiness
Keep SOC 2, ISO 27001 and HIPAA controls operating and evidenced continuously, not scrambled before an audit.
Evidence discipline
Own the control calendar so evidence is collected on time, every cycle.
Client security reviews
Complete client questionnaires and support diligence with accurate answers.
Risk assessment
Run periodic risk assessments and drive remediation to closure.
Policy currency
Keep policies current and actually reflected in how people work.
Training and awareness
Run the HIPAA and security awareness program across three hubs.
Ramp
Your first 90 days
First 30 days
Review the control set, evidence status and open findings. Identify what is documented but not truly operating.
By day 60
Control calendar running, gaps prioritised, remediation owners assigned.
By day 90
Audit-ready posture with evidence current and client questionnaires turning around quickly.
Requirements
What we look for
- Four or more years in compliance, audit or information security in a regulated environment
- Hands-on with SOC 2 and ISO 27001 audit cycles
- Strong working knowledge of HIPAA privacy and security rules
- Able to drive remediation across teams without direct authority
- Clear, precise written communication for client-facing responses
Bonus
Strong plus, not required
- CISA, CISSP, CIPP or similar credential
- Healthcare BPO or offshore delivery experience
- HITRUST familiarity
Accountability
How this role is measured
| Measure | What it means |
|---|---|
| Audit outcomes | Findings and exceptions per cycle. |
| Evidence timeliness | Collected on schedule. |
| Remediation closure | Open findings closed on time. |
| Questionnaire turnaround | Client security reviews. |
| Training completion | Across all hubs. |
| Incident handling | Response time and closure. |
Why ASP-RCM
Why this seat is different
We are senior-led by design. A senior partner is named on accounts and shows up in the work, which is why clients renew and why this role carries real authority rather than a title. Our AI suite is in production, not in a roadmap deck, and our compliance posture is independently audited: SOC 2 Type II with HITRUST, ISO 27001 and HIPAA.
We pay for certifications and run upskilling cohorts, because coding and revenue cycle are crafts that need investment. You will work across Dallas HQ, six US states and Chennai, India, with colleagues who have run these functions at scale.