InfoSec Compliance Analyst
Hybrid
Full Time
#Technology
#SOC 2
#Risk Management
#SIEM
#AWS
#DevOps
#GitHub
#Jira
#GSuite
At Zus, we are building a shared health data platform that makes it easier to access patient information through APIs and EHR integrations. Founded in 2021 by Jonathan Bush, our mission is to help healthcare innovators build better tools by maximizing the value of patient insights. We partner with health information exchanges and data networks to translate clinical history into actionable information at the point of care, and we are looking for someone to help us maintain the security and integrity of that mission.
What is this role?
We are seeking a Mid-Level InfoSec Compliance Analyst to join our team on a Full Time basis. This is a hybrid role based in the United States, where you will help us mature our security programs and ensure our processes remain robust. You will report to our Manager of InfoSec and work closely with our Engineering, Legal, and People Ops teams to keep our security and privacy initiatives running effectively.
What will you do?
- Manage our SOC 2 compliance by monitoring controls, coordinating evidence collection, and overseeing remediation efforts.
- Lead our vendor risk management workflows and conduct security reviews for new software acquisitions.
- Coordinate our master InfoSec schedule, which includes facilitating incident response tests, disaster recovery drills, and quarterly compliance reviews with our legal partners.
What makes you a great fit?
You are a process-driven professional who takes pride in maintaining organized systems and clear documentation. You are comfortable working in a fast-paced environment and have a knack for turning complex requirements into actionable Jira tickets. We are looking for someone who is fluent in English and possesses the following:
- Strong project management skills with the ability to handle documentation in tools like Confluence.
- Familiarity with SIEM tools and a proactive approach to risk management.
- A self-starter mindset and the ability to work effectively in an early-stage startup environment.
- An interest in learning about AWS, DevOps, and security infrastructure, even if you are not a developer.
- Experience with GitHub, GSuite, or previous work supporting security frameworks like SOC 2 or HIPAA is a significant plus.
What's in it for you?
We provide a supportive environment where you can grow your career while helping us disrupt the healthcare industry. Our benefits package includes:
- Equity compensation to ensure you share in our success.
- Comprehensive medical insurance and wellness programs.
- A 401k retirement plan.
- Unlimited vacation policy.
- The flexibility of a hybrid work schedule.









