HimalayasHimalayas logo
MachinifyMA

Security Engineer - GRC (Governance, Risk & Compliance)

Machinify is a revolutionary healthcare software company with a mission to ensure that patients get the right treatment, at the right time, at the right price. The cloud-based Machinify AI platform delivers products that are transforming healthcare administration from a human-powered, error-prone series of spreadsheets workflows to a world of transparent, realtime care and payment decisions.

Machinify

Employee count: 51-200

Salary: 90k-120k USD

United States only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

Machinify is a leading healthcare intelligence company with expertise across the payment continuum, delivering unmatched value, transparency, and efficiency to health plan clients across the country. Deployed by over 85 health plans, including many of the top 20, and representing more than 270 million lives, Machinify brings together a fully configurable and content-rich, AI-powered platform along with best-in-class expertise. We’re constantly reimagining what’s possible in our industry, creating disruptively simple, powerfully clear ways to maximize financial outcomes and drive down healthcare costs.

About the Opportunity:

At Machinify, we’re building a robust security program to protect our clients’ sensitive healthcare data and maintain the highest standards of information security. As part of the Security GRC team, you will play a critical technical role in configuring, automating, and integrating Machinify’s GRC platform (Vanta) to support compliance management, audit readiness, and risk program operations across the organization.

As a Security Engineer focused on GRC, you will bridge technical implementation and compliance requirements—helping streamline evidence collection, automate control monitoring, and connect Vanta to Machinify’s infrastructure and tooling. This role is well-suited for candidates with a mix of technical aptitude and compliance interest who want to build deep expertise in GRC platform engineering within a complex, multi-entity healthcare environment undergoing active transformation.

What you’ll do:

Primary Responsibilities – GRC Platform Engineering & Automation (70% of role):

  • Configure, administer, and continuously improve Machinify’s Vanta GRC platform across all organizational entities
  • Build and maintain Vanta integrations with cloud environments (AWS, Azure), identity providers, endpoint management tools, HR systems, and other compliance-relevant data sources
  • Automate evidence collection workflows to reduce manual effort for HITRUST r2, SOC 2 Type II, and other certification cycles
  • Develop and maintain custom tests, policies, and controls within Vanta to reflect Machinify’s specific compliance requirements and risk posture
  • Monitor control health dashboards and manage remediation workflows for failing or at-risk controls
  • Manage the Vanta vendor risk module, including questionnaire automation and third-party assessment workflows
  • Support access review automation through Vanta, ensuring timely completion and accurate documentation
  • Maintain and improve GRC platform documentation including integration configurations, data flows, and control mapping
  • Evaluate and implement new Vanta capabilities as the platform evolves, including AI-assisted compliance features

Supporting GRC Program Responsibilities (30% of role):

  • Support HITRUST r2 and SOC 2 Type II audit activities through evidence preparation, auditor portal management, and issue tracking
  • Assist with customer security questionnaire responses by leveraging Vanta’s trust center and evidence library
  • Contribute to third-party risk assessments by coordinating vendor security reviews and maintaining assessment records
  • Help develop and maintain security policies and procedures aligned with HITRUST and SOC 2 requirements
  • Support the risk register by maintaining risk records, tracking remediation actions, and producing risk reporting
  • Participate in security awareness program activities including content development and training delivery tracking
  • Assist with regulatory documentation requirements including HIPAA privacy and security program documentation
  • Collaborate with the Security Engineering team to ensure technical controls are properly reflected in the GRC platform

What experience you bring (Role Requirements):

Essential Qualifications:

  • Bachelor’s degree in Information Security, Computer Science, Compliance, Risk Management, or related field, or equivalent work experience
  • 3+ years of experience in information security, GRC, or a technical compliance role
  • Hands-on experience with a GRC platform such as Vanta, Drata, Tugboat Logic, ServiceNow GRC, Archer or similar
  • Working knowledge of SOC 2 Trust Service Criteria and HITRUST CSF control requirements
  • Familiarity with cloud environments (AWS or Azure) sufficient to understand integration points and relevant compliance controls
  • Experience with API integrations, webhooks, or similar mechanisms for connecting systems to compliance platforms
  • Understanding of common compliance evidence types and audit workflows for security certifications
  • Familiarity with healthcare compliance requirements, particularly HIPAA Security Rule
  • Strong organizational skills for managing multiple compliance workstreams simultaneously
  • Clear written communication for policy documentation, control narratives, and cross-functional stakeholder engagement

Preferred Qualifications:

  • Direct experience administering Vanta, including custom integrations and automated test configuration
  • Scripting experience (Python, JavaScript, or Bash) for GRC automation or API-based integrations
  • Security certifications such as CISA, CISM, CompTIA Security+, or CISSP
  • Exposure to additional compliance frameworks such as NIST CSF, ISO 27001, FedRAMP, or state-level healthcare regulations
  • Experience supporting compliance programs across multiple legal entities or in a post-merger integration environment
  • Familiarity with identity governance tools, MDM platforms, or cloud security posture management (CSPM) tools and their compliance integration points
  • Experience with customer-facing trust center management or security assurance programs

What We Offer:

  • Work from anywhere in the US! Machinify is digital-first.
  • Top Medical/Dental/Vision offerings
  • FSA/HSA
  • Tuition reimbursement
  • Competitive salary, 401(k) with company match
  • Additional health and wellness benefits and perks
  • Flexible and trusting environment where you’ll feel empowered to do your best work
The salary for this position is based on an array of factors unique to each candidate: Such as years and depth of experience, set skills, certifications, etc. We are hiring for different levels, and our Recruiting team will let you know if you qualify for a different role/range.
Pay range: $90,000-$120,000

Equal Employment Opportunity at Machinify

We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender, gender identity or expression, or veteran status. We are proud to be an equal opportunity workplace. Machinify is an employment at will employer. We participate in E-Verify as required by applicable law. In accordance with applicable state laws, we do not inquire about salary history during the recruitment process. If you require a reasonable accommodation to complete any part of the application or recruitment process, please let our recruiters know. See our Candidate Privacy Notice at: https://www.machinify.com/candidate-privacy-notice/

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Salary

Salary: 90k-120k USD

Education

Bachelor degree

Experience

3 years minimum

Experience accepted in place of education

Location requirements

Hiring timezones

United States +/- 0 hours

About Machinify

Learn more about Machinify and their company culture.

View company profile

We develop software that helps people get the right medical care, at the right time, at the right price.

The $4 trillion healthcare industry is the largest and most complex sector of the U.S. economy. It involves maze-like processes, arcane rules, a multi-party payment system... and the yearly processing of 7 billion health claims.

Healthcare data is fragmented across industry players, stored in legacy systems, and is often unstructured and not machine-readable (think faxes).

We started Machinify to leverage healthcare data at scale to drive down costs and improve outcomes. Our software platform leverages the latest advances in machine learning, large language models, data analytics, and cloud processing to solve previously intractable problems.

Employee benefits

Learn about the employee benefits and perks provided at Machinify.

View benefits

Retirement benefits

401(k) sponsorship to help you invest in your future.

Equity benefits

Every employee gets equity, so you are rewarded for your best work.

Paid parental leave

We offer inclusive paid parental leave for birth and non-birth parents.

Generous paid time-off

Take the time you need when life happens. Our flexible PTO plan encourages people to take time off so they can recharge and live fully.

View Machinify's employee benefits
Claim this profileMachinify logoMA

Machinify

Company size

51-200 employees

Founded in

2015

Chief executive officer

Prasanna Ganesan

Employees live in

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

33 remote jobs at Machinify

Explore the variety of open remote roles at Machinify, offering flexible work options across multiple disciplines and skill levels.

View all jobs at Machinify

Remote companies like Machinify

Find your next opportunity by exploring profiles of companies that are similar to Machinify. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan