AKASA logo
AKASA

Director, Compliance & AI Governance

South San Francisco, USAHybridPosted 1 month ago

Apply opens AKASA's site. When you're back, we'll ask whether you applied.

Job type
Full-time
Work mode
Hybrid
Level
Director
Department
Legal and Compliance
Experience
8+ years experience
Posted
Aug 10, 2026

About the role

About the Role:

We’re looking for a strategic, automation-minded Director of Compliance & AI Governance to own and evolve AKASA’s compliance program as we scale. This role is ideal for someone who has led compliance in a healthcare SaaS or AI environment and wants to build a modern, engineering-forward program rather than a paperwork factory. You’ll own our HITRUST, SOC 2, and HIPAA programs end to end, operationalize emerging AI governance frameworks like the NIST AI RMF, and drive the policy lifecycle across the company. The ideal candidate treats compliance as a product: automated evidence collection, continuous control monitoring, and policies people actually read and follow. You’ll join a small, high-leverage team with immediate ownership and room to build. You thrive in a fast-paced startup environment and are agile with an ownership mindset.

This is an on-site position that requires 3+ days a week in our South San Francisco HQ.

What You’ll Do:

  • Own AKASA’s compliance certification portfolio end to end, including HITRUST CSF, SOC 2 Type II, and HIPAA, from control design and implementation through evidence collection, audit coordination, and remediation. Evaluate and pursue new certifications and attestations such as ISO 27001, ISO 42001, and HITRUST AI as customer and market needs evolve.
  • Define compliance roadmaps and ensure organization-wide adoption, driving cross-functional alignment and accountability on regulatory requirements.
  • Build the AI governance program grounded in the NIST AI RMF, partnering with Engineering, Product, and Legal to establish model risk assessments, AI use policies, and documentation that meets enterprise health system expectations.
  • Drive compliance automation by implementing and optimizing GRC and continuous control monitoring tooling, automating evidence collection across the technology stack, and using AI tools to streamline policy drafting, control mapping, and audit preparation.
  • Own the full policy lifecycle, including authoring, review cadences, exception handling, attestation campaigns, and version control, ensuring policies are clear, practical, and mapped to the relevant frameworks.
  • Serve as the compliance representative for customers and prospects by leading security and compliance questionnaire responses, supporting enterprise sales cycles, managing customer audits, and maintaining trust artifacts including BAAs, the trust center, and shared assessments.
  • Oversee vendor and third-party risk management, the annual risk assessment, security awareness and HIPAA training programs, and incident response documentation and tabletop exercises in partnership with Security and IT.
  • Partner with Legal and Security leadership on security-related contractual obligations.

Skills & Qualifications:

  • 8+ years of experience in security compliance, GRC, or risk management, including 2+ years leading a team or function. Healthcare SaaS, health tech, or AI startup experience is strongly preferred.
  • Deep, hands-on expertise across HITRUST CSF, SOC 2 Type II, HIPAA Security and Privacy Rules, and emerging AI governance frameworks such as NIST AI RMF.
  • Hands-on experience with GRC and continuous control monitoring platforms such as Vanta, Drata, Hyperproof, or similar, evidence collection automation, and AI tools such as ChatGPT and Claude.
  • End-to-end policy ownership, including drafting, cross-framework mapping, and review, exception, and attestation cycles.
  • Experience with enterprise security questionnaires, sales-cycle support, BAA and security terms negotiation alongside Legal, and customer audits.

Preferred Qualifications:

  • Direct experience achieving or maintaining ISO 27001, ISO 42001, or HITRUST AI certifications.
  • Familiarity with modern security stacks and the ability to partner credibly with Security and IT on control implementation.
  • Experience with privacy regulations beyond HIPAA, such as CCPA/CPRA, state health data laws, or GDPR.
  • Experience implementing compliance automation tools and trust centers such as Drata or Vanta.
  • Scripting or low-code automation skills, including Python, Zapier, or Tray.io, for building compliance workflows.
  • Relevant certifications such as CISSP, CISA, CIPP/US, HCISPP, or HITRUST CCSFP.

What We Offer:

  • Flexible paid time off (PTO)
  • Expansive health, dental, and vision coverage
  • Employer contribution to Health Savings Accounts (HSA)
  • Generous parental leave policy
  • Full employee coverage for life insurance
  • Home office stipend
  • Cell phone and internet reimbursement
  • Commuting benefits
  • Company-paid holidays
  • 401(k) plan

Compensation:

  • Salary range: $150,000–$185,000 plus equity.

The final compensation will consider location, experience, and other job-related factors.

AKASA is committed to providing reasonable accommodations for candidates with disabilities in its recruiting process. Candidates may contact [email protected] for assistance or accommodations.