Director, Compliance & AI Governance

Posted Yesterday
Be an Early Applicant
South San Francisco, CA, USA
Hybrid
150K-185K Annually
Senior level
Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Software • Generative AI
Building the future of healthcare with AI.
The Role
Lead and scale AKASA's compliance and AI governance: own HITRUST, SOC 2, and HIPAA programs; operationalize NIST AI RMF; drive automation-first GRC and continuous control monitoring; manage policy lifecycle, vendor risk, customer audits, and sales security support; partner with Engineering, Legal, and Security.
Summary Generated by Built In

About AKASA

At AKASA, our mission is to build the future of healthcare with AI. As the leading provider of generative AI solutions for the healthcare revenue cycle, we help health systems comprehensively capture and communicate the full patient clinical journey. By empowering health systems to streamline their operations, they can focus on what matters most - delivering quality patient care. We have raised over $205M in funding from investors such as Andreessen Horowitz, BOND, and Costanoa Ventures.

This is the most exciting time to join AKASA. Revenue bookings for our new AI-native product suite have grown over 20x since launching in 2024. In this time, we have broken our record for the largest deal in company history three times consecutively. This growth is driven by the massive improvement we are generating for our customers across clinical quality and documentation accuracy, both top priority areas for health system leaders.

Our deployments have been recognized nationally as "one of the most comprehensive real-world uses of GenAI in healthcare finance to date" (link). Our customer base represents more than $120B+ in net patient revenue and includes the most innovative health systems in the country, like Cleveland Clinic, Duke, Stanford, and Johns Hopkins.

Some of our recent recognitions include being named one of America's Top Startup Employers 2026 by Forbes, #1 most promising healthcare RCM startup of 2025 by Black Book Market Research, and one of the fastest-growing GenAI startups to watch by AIM Research. Our CEO was ranked among the “Top 50 Healthcare Technology CEOs” by the Healthcare Technology Report, and we have been certified as a “Great Place to Work” for the past 6 years in a row.

We’re building on this momentum to redefine what’s possible in healthcare. We’re looking for exceptional people to help us accelerate that reality.

About the Role

We’re looking for a strategic, automation-minded Director of Compliance & AI Governance to own and evolve AKASA’s compliance program as we scale. This role is ideal for someone who has led compliance in a healthcare SaaS or AI environment and wants to build a modern, engineering-forward program rather than a paperwork factory. You’ll own our HITRUST, SOC 2, and HIPAA programs end to end, operationalize emerging AI governance frameworks like the NIST AI RMF, and drive the policy lifecycle across the company. The ideal candidate treats compliance as a product: automated evidence collection, continuous control monitoring, and policies people actually read and follow. You’ll join a small, high-leverage team with immediate ownership and room to build. You thrive in a fast-paced startup environment and are agile with an ownership mindset.

This is an on-site position that requires 3+ days a week in our South San Francisco HQ.

What You’ll Do

  • Own AKASA’s compliance certification portfolio end to end (including HITRUST CSF, SOC 2 Type II, and HIPAA) from control design and implementation through evidence collection, audit coordination, and remediation. Evaluate and pursue new certifications and attestations (such as ISO 27001, ISO 42001, and HITRUST AI) as customer and market needs evolve.

  • Define compliance roadmaps and ensure org-wide adoption, driving cross-functional alignment and accountability on regulatory requirements.

  • Build our AI governance program grounded in the NIST AI RMF, partnering with Engineering, Product, and Legal to establish model risk assessments, AI use policies, and documentation that meets enterprise health system expectations.

  • Drive compliance automation as a first principle: implement and optimize GRC and continuous control monitoring tooling, automate evidence collection across our stack (Okta, Google Workspace, Kandji/Iru, SentinelOne, Nightfall, AWS), and use AI tools to streamline policy drafting, control mapping, and audit preparation.

  • Own the full policy lifecycle, including authoring, review cadences, exception handling, attestation campaigns, and version control; ensuring policies are clear, practical, and mapped to the frameworks we certify against.

  • Be the compliance face of AKASA for customers and prospects: lead security and compliance questionnaire responses, support enterprise sales cycles, manage customer audits, and maintain trust artifacts including BAAs, our trust center, and shared assessments. Find ways to automate these processes using AI first tooling.

  • Oversee vendor and third-party risk management, the annual risk assessment, security awareness and HIPAA training programs, and incident response documentation and tabletop exercises in partnership with Security and IT.

  • Partner with Legal and Security leadership on all security-related contractual obligations.

Skills & Qualifications

  • 8+ years experience in security compliance, GRC, or risk management, including 2+ years leading a team or function. Healthcare SaaS, health tech, or AI startup experience strongly preferred.

  • Deep, hands-on expertise across HITRUST CSF (r2 preferred), SOC 2 Type II, HIPAA Security and Privacy Rules, and emerging AI governance frameworks like NIST AI RMF. You’ve run certification and audit cycles from start to finish and know how to translate AI governance standards into real controls for a company building on PHI.

  • An automation-first instinct: hands-on experience with GRC and continuous control monitoring platforms (Vanta, Drata, Hyperproof, or similar), evidence collection automation, and a track record of using AI tools (ChatGPT, Claude) to push the boundaries of what a lean compliance function can do.

  • End-to-end policy ownership: drafting, cross-framework mapping, and running review/exception/attestation cycles.

  • Comfort in front of customers: enterprise security questionnaires, sales-cycle support, BAA/security terms negotiation alongside Legal, and managing customer audits.

We’d love to see one or more of:

  • Direct experience achieving or maintaining ISO 27001, ISO 42001, or HITRUST AI certifications.

  • Familiarity with the technical side of a modern security stack (Okta, MDM platforms like Kandji/Iru, SentinelOne, Nightfall, AWS) and the ability to partner credibly with Security and IT on control implementation.

  • Experience with privacy regulations beyond HIPAA, such as CCPA/CPRA, state health data laws, or GDPR.

  • Implementing Compliance Automation Tools and Trust Centers like Drata or Vanta.

  • Scripting or low-code automation skills (Python, Zapier, Tray.io) for building compliance workflows.

  • Relevant certifications such as CISSP, CISA, CIPP/US, HCISPP, or HITRUST CCSFP.

What We Offer

  • Flexible paid time off (PTO)

  • Expansive coverage for health, dental, and vision

  • Employer contribution to Health Savings Accounts (HSA)

  • Generous parental leave policy

  • Full employee coverage for life insurance

  • Home office stipend

  • Cell phone/internet reimbursement

  • Commuting benefits

  • Company-paid holidays

  • 401(K) plan

Compensation

  • Based on market data and other factors, the salary range for this position is $150,000 - $185,000 + Equity. However, a salary higher or lower than this range may be appropriate for a candidate whose qualifications differ meaningfully from those listed in the job description.

 

The above represents the expected salary range for this job requisition. Ultimately, in determining your pay, we'll consider your location, experience, and other job-related factors.

 

We’re committed to doing the best work of our lives, together. Come see if we're the right team for you.

AKASA is a proud equal opportunity employer and we believe that a diverse and inclusive workforce is an imperative. We welcome people of different backgrounds, genders, races, ethnicities, abilities, sexual orientations, and perspectives, just to name a few. We do not discriminate based upon any protected class and we encourage candidates of all identities and backgrounds to apply. AKASA considers qualified applicants regardless of criminal histories in accordance with the San Francisco Fair Chance Ordinance.

AKASA is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance or accommodations due to a disability, please let us know at [email protected].

Skills Required

  • 8+ years experience in security compliance, GRC, or risk management, including 2+ years leading a team or function.
  • Deep, hands-on expertise across HITRUST CSF (r2 preferred), SOC 2 Type II, HIPAA Security and Privacy Rules, and NIST AI RMF.
  • Experience running certification and audit cycles end to end (control design, evidence collection, audit coordination, remediation).
  • Hands-on experience with GRC and continuous control monitoring platforms (Vanta, Drata, Hyperproof, or similar) and evidence collection automation.
  • Track record of using AI tools (e.g., ChatGPT, Claude) to streamline policy drafting, control mapping, and audit preparation.
  • End-to-end policy ownership including drafting, cross-framework mapping, review/exception/attestation cycles, and version control.
  • Comfort interfacing with customers: enterprise security questionnaires, sales-cycle support, BAAs/security terms negotiation, and customer audits.
  • This is an on-site role requiring 3+ days per week in the South San Francisco HQ.
  • Healthcare SaaS, health tech, or AI startup experience.
  • Experience with privacy regulations beyond HIPAA (CCPA/CPRA, GDPR) and familiarity with ISO 27001, ISO 42001, or HITRUST AI.
  • Familiarity with modern security stack components (Okta, MDM like Kandji/Iru, SentinelOne, Nightfall, AWS).
  • Implementing Compliance Automation Tools and Trust Centers like Drata or Vanta.
  • Scripting or low-code automation skills (Python, Zapier, Tray.io) for building compliance workflows.
  • Relevant certifications such as CISSP, CISA, CIPP/US, HCISPP, or HITRUST CCSFP.

What the Team is Saying

Andy
Aalique
Carolyn
Sara
Sanjay
Angela
Yunus

AKASA Compensation & Benefits Highlights

  • Healthcare Strength Health coverage is presented as robust, with medical, dental, and vision plans that include 100%‑premium options on some tiers, mental‑health support, and a free One Medical membership. These elements signal strong depth and accessibility in core healthcare offerings.
  • Leave & Time Off Breadth Time off is promoted as unlimited and paired with flexible schedules, supporting work‑life balance across roles. This breadth is further reinforced by company messaging around remote‑friendly practices and periodic in‑person gatherings.
  • Parental & Family Support Parental leave is described as generous, alongside family medical leave. Together with healthcare and wellness resources, these programs indicate meaningful support for caregivers.

AKASA Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: South San Francisco, CA
110 Employees
Year Founded: 2019

What We Do

American medicine is the best in the world. But the American healthcare system is challenged by high administrative costs that burden patients, health systems, and insurance companies with unnecessary expenses. We are focused on addressing those challenges. We use GenAI to improve the most pressing financial pain points in the revenue cycle. We’re one of the first companies to deploy GenAI for practical use cases within healthcare. That gives health systems the ability to focus on what really matters: helping patients. This is one of the most exciting times to join AKASA. Bookings for our GenAI product suite have increased 10x in the last year. We also recently closed our biggest deal in company history. Our customer base represents more than $120B+ in net patient revenue and includes the most innovative health systems in the country, like Stanford, Johns Hopkins, and Cleveland Clinic. And we’re just getting started! Some of our most recent recognitions include being named one of the fastest-growing GenAI startups to watch by AIM Research and an “AI Revenue Cycle Leader” by Black Book in 17 out of 18 categories. Our CEO was ranked among the “Top 50 Healthcare Technology CEOs” by the Healthcare Technology Report, and we have been certified as a “Great Place to Work” for the past five years in a row, just to name a few.

Why Work With Us

We are hyper-focused on creating an environment where you can do the best work of your life. We live by our cultural values of "Empower Health Systems", "Innovate for Impact", "Win or Learn, Quickly", and "In This Together."

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

AKASA Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

We are a remote-friendly, hybrid organization with team members across the US. We have hubs of AKASAns in the Bay Area, NYC, and Denver to name a few, and support co-working days within these areas.

Typical time on-site: Not Specified
HQSouth San Francisco, CA
Denver Hub
NYC Hub
Learn more

Similar Jobs

AKASA Logo AKASA

Quality Assurance Specialist

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Software • Generative AI
Hybrid
2 Locations
110 Employees
60K-85K Annually

AKASA Logo AKASA

Senior Software Engineer

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Software • Generative AI
Hybrid
3 Locations
110 Employees
180K-230K Annually

AKASA Logo AKASA

Senior Software Engineer

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Software • Generative AI
Hybrid
San Francisco, CA, USA
110 Employees
180K-220K Annually

AKASA Logo AKASA

Forward Deployed Engineer

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Software • Generative AI
Hybrid
2 Locations
110 Employees
150K-170K Annually

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account