Overview

Security & Compliance Manager Jobs in New York City Metropolitan Area at Cassidy

Title: Security & Compliance Manager

Company: Cassidy

Location: New York City Metropolitan Area

Location: New York, NY (in-office) Reports to: CTO

About Cassidy

Cassidy is an AI automation platform that helps non-technical knowledge workers automate their work with the context of their business. We’re Series A, ~25 people, and growing fast with insurance and employee benefits companies. Our customers trust us with sensitive data, and we take that seriously.

The Role

We’re looking for our first dedicated Security & Compliance hire. You’ll own risk across the entire company: IT operations, vendor management, compliance programs, security posture, and customer-facing trust. Today this all sits with our CTO. We need someone who can take full ownership.

This isn’t a paper-pushing compliance role and it isn’t a software engineering role. You need to be technical enough to look at our infrastructure, understand how data flows through our systems, and identify real problems. You’ll work closely with engineers to scope and prioritize fixes, but you won’t be expected to write production code. You also need to be confident and credible on calls with customer security teams, because your answers directly impact whether deals close.

You’ll be the single person who holds the full picture of security and compliance risk at Cassidy. That means you need to be organized, detail-oriented, and proactive.

What You’ll Own

Compliance programs

  • Manage SOC 2 Type II, HIPAA, and GDPR compliance programs
  • Own our Vanta dashboard, maintain evidence collection, keep everything green
  • Own the policy packet and keep it accurate to what we actually do
  • Run quarterly access reviews
  • Coordinate the annual pentest

Customer-facing security

  • Handle inbound security questionnaires end-to-end
  • Get on calls with customer security teams and walk them through our architecture, controls, and compliance posture
  • Maintain our Trust Center and BAA disclosure page
  • Be the point of contact when a prospect’s security team has questions during a deal

IT operations

  • Own device management, SSO/MFA configuration, onboarding and offboarding access provisioning across all systems
  • Manage our tool inventory and ensure appropriate controls are in place for every vendor that touches customer data

Vendor and BAA management

  • Own the subprocessor list and BAA tracker
  • Coordinate new BAAs with vednors
  • Work with outside counsel on contract amendments and compliance-related legal questions

Technical audit and project management

  • Review infrastructure, application architecture, and data flows alongside engineers to identify compliance gaps and security risks
  • Write clear tickets for engineering to address and track remediation to completion
  • Be comfortable reading a cloud architecture diagram, understanding database access patterns, and having informed conversations with engineers about logging, access controls, encryption, and data retention

Risk management

  • Own and maintain the company risk register
  • Assess new risks as the product and customer base evolve
  • Make prioritized recommendations on where to invest engineering time
  • Help leadership weigh business value against compliance overhead

Incident response

  • Own the incident response plan and keep it current with real names, contacts, and procedures
  • Be the coordinator if an incident occurs
  • Know the HIPAA breach notification rules and timelines

What We’re Looking For

  • 3-5 years of experience in security, compliance, or technical operations at a B2B SaaS
  • companyBeen through SOC 2 and ideally
  • HIPAATechnical fluency: comfortable navigating cloud consoles (AWS, Azure), understanding how a multi-tenant SaaS application handles data, and evaluating whether a security control is actually working or just documented
  • Experience filling out enterprise security questionnaires from the vendor side
  • Strong communication skills: you’ll be on calls with customer security teams, working with outside counsel, and coordinating with engineers, and you need to be credible with all three audiences
  • Extremely organized, with systems for tracking BAAs, vendor reviews, access reviews, policy updates, remediation tickets, and customer security requests
  • Bias toward action: you’ll identify a gap, propose a fix, and drive it to completion, not write a 30-page report about it

Nice to Have

  • Experience with Vanta
  • Experience working with healthcare or insurance customers
  • Previous experience as the first or early security/compliance hire at a startup
  • Familiarity with cloud infrastructure providers (Railway, Azure, AWS, Cloudflare)
  • Basic scripting ability (Python, Bash) for automating compliance tasks
Upload your CV/resume or any other relevant file. Max. file size: 800 MB.