Skip to content

Careers

Security & Compliance Analyst (HIPAA)

Keep the HIPAA program real - risk assessments, access controls and audit logs, BAAs with anyone who touches PHI, and security review on features before they ship.

SecurityRemote (US)Full-time

Cadence ABA builds AI-native clinical software for ABA practices - capturing session data by voice, structuring it into trial-by-trial records, and drafting billable, CPT-mapped session notes for clinician review and signature. Because Cadence handles protected health information (PHI) as a HIPAA-compliant, BAA-backed platform, we're looking for a Security & Compliance Analyst to help maintain and strengthen our security posture, compliance controls, and audit readiness as we grow.

What you'll do

  • Maintain and continuously improve our HIPAA compliance program, including risk assessments, policies, and administrative, technical, and physical safeguards
  • Monitor access controls, audit logs, and encryption practices across systems that store or transmit PHI
  • Support and help manage Business Associate Agreements (BAAs) with vendors and subprocessors that touch PHI
  • Conduct internal audits and gap assessments, and track remediation of findings to closure
  • Partner with engineering to review system design, data flows, and new features for security and compliance implications
  • Prepare documentation and evidence for external audits, customer security questionnaires, and compliance certifications

What we're looking for

  • 3+ years of experience in security, compliance, or IT risk roles, ideally with direct HIPAA experience
  • Solid understanding of HIPAA Privacy and Security Rules, including risk analysis and breach notification requirements
  • Experience with access control models, audit logging, and encryption practices for data in transit and at rest
  • Familiarity with vendor risk management and BAA review
  • Strong written communication skills for policies, audit responses, and stakeholder reporting
  • Comfortable working cross-functionally with engineering, product, and clinical teams

Nice to have

  • Experience in a healthcare technology or SaaS company handling PHI
  • Familiarity with SOC 2 or other compliance frameworks alongside HIPAA
  • Background supporting audit-defensible data lineage or role-based access systems

How to apply

Applications run through our hiring platform - the button above opens this posting there. If you’d rather start a conversation first, introduce yourself and say which role caught your eye.

Worth reading before you do: what we’ve built, the limits we build inside, and why we’re building it.