Risk & Compliance Lead

Hi Rasmus · via Himalayas ·

Budget / Salary$125,000–135,000
TypeFull-time job
LocationUnited States
Posted2 hours ago
👋 Welcome to Hi Rasmus!
At Hi Rasmus, people are at the heart of everything we do. Whether you're just joining us or have been part of our journey, we’re excited to have you on board!
We’re on a mission to make evidence-based autism care accessible to families everywhere. 🌍 Families shouldn’t have to uproot their lives to access support—that’s why we break down barriers while keeping the human touch at the center of our work. Our goal? To positively impact the lives of 1 million children with autism.
Rooted in a culture that values trust, collaboration, and balance, we foster a workplace where everyone feels valued and empowered.
🎯 Our Core Values

Innovation 🧠 – We embrace creativity and seek better solutions.

Integrity ⚖️ – Honesty and trust guide everything we do.

Collaboration 🤝 – Together, we achieve more.

Growth 🌱 – We’re committed to personal and professional development.

Empathy ❤️ – We prioritize understanding and human connection.

🚀 What It’s Like to Work Here
At Hi Rasmus, we trust our team to do great work, their way. Flexibility, autonomy, and balance are key—we know that when life and work fit together, everyone thrives. 🏡✨
Flat structure, open doors – Every voice matters. Collaboration and shared decision-making drive us forward.

Balance is a priority – Recharge, make time for what matters, and do your best work in a way that works for you.

Real impact, real growth – Be part of a team making a difference for families worldwide, while growing your skills along the way.

Join us in shaping a future where exceptional autism care is within reach for all. 💡💙
📢 About the Role
📍 Location: Remote (United States)
💼 Department: Operations

🤝 Reports to: Chief Financial Officer (CFO)
⏳ Job Type: Full-Time
💰 Compensation: Range of $125,000–$135,000 annually
🕜 Working Hours: Flexible within US time zones. Because this role partners closely with our Denmark-based leadership, some morning overlap with European hours matters most—Eastern Time works seamlessly, and Pacific or other time zones work well for those able to start their day a bit earlier.

🧩 Why This Role Matters

At Hi Rasmus, families, providers, and partners trust us with sensitive information every day. As we grow, protecting that trust becomes both an important responsibility and a critical part of how we scale.We're looking for a Risk & Compliance Lead to build the programs, processes, and partnerships that help us manage risk, meet regulatory requirements, and grow confidently.This is an opportunity to shape how risk and compliance evolve alongside our business—helping teams make thoughtful decisions, supporting our customers, and ensuring we're prepared for what's next.

🚀 How You'll Make an Impact

Build Our Risk & Compliance ProgramCreate and continuously improve the policies, processes, and operating practices that support HIPAA, GDPR, CCPA, and other applicable requirements.

Own and continuously improve Hi Rasmus' risk and compliance program, including our privacy and security compliance practices.

Lead risk assessments, policy reviews, audit readiness, evidence management, and continuous improvement initiatives.

Shape the long-term risk and compliance roadmap as the business grows.

Build scalable programs that keep the organization prepared for evolving requirements and priorities.

Support Hi Rasmus’ Growth

Help customers and partners feel confident choosing Hi Rasmus.

Develop and lead the process for customer security reviews, HECVATs, questionnaires, and due diligence requests.

Develop and maintain our customer-facing Security Center and trust resources.

Partner with Sales and Customer Success throughout customer evaluations and procurement processes.

Help remove unnecessary risk and compliance friction while maintaining the standards our customers expect.

Own Terms, Agreements & Compliance RequirementsCreate a consistent and scalable approach to the compliance and privacy requirements that support our growing customer base.

Manage the review, application, and ongoing maintenance of Data Processing Agreements (DPAs), Business Associate Agreements (BAAs), security exhibits, and related terms.

Ensure contractual terms and compliance requirements are applied consistently across our customer relationships.

Partner with internal stakeholders and external legal counsel when interpretation or specialized legal guidance is needed.

Maintain clear documentation and processes so contractual compliance obligations are understood and followed across the business.

Strengthen Compliance Operations & CultureBuild practical systems and shared practices that keep Hi Rasmus prepared, informed, and continuously improving.

Maintain policies, standards, documentation, controls, and compliance evidence.

Coordinate audits, assessments, certifications, and remediation activities.

Develop and lead security awareness and compliance training.

Create practical guidance that helps teams make informed decisions and understand their role in managing risk.

Partner with external auditors, consultants, and compliance vendors.

Use data, evidence, and clear prioritization to focus resources on the areas of greatest business and compliance risk.

Partner with leaders to build a strong compliance mindset across Hi Rasmus.

Partner Across the BusinessRisk and compliance are team efforts.You'll collaborate closely with Engineering, Product, Sales, Customer Success, Finance, and Leadership to identify risks early, solve problems collaboratively, and support thoughtful business decisions that help Hi Rasmus grow responsibly.🌱 What Success Looks Like

After your first year:

Hi Rasmus has a proactive, well-documented, and audit-ready risk and compliance program.

Customer security and compliance reviews follow a clear, scalable process and support our growth.

Customer terms, agreements, and compliance obligations are consistently managed across our customer base.

Teams understand their role in managing risk and protecting customer and company information.

Leadership has clear, fact-based visibility into material risks, priorities, and progress.

Risk and compliance are integrated into how we operate and make decisions without creating unnecessary bureaucracy.

🧑‍💻 About You

You're someone who brings structure and clarity to complex challenges.

You're pragmatic and methodical, grounding your decisions in facts and evidence. You understand that good risk management isn't about eliminating every risk—it's about understanding the business, making thoughtful tradeoffs, and focusing attention where it matters most.

You bring strong business judgment and can connect compliance requirements to commercial and operational priorities. You're comfortable working independently, setting priorities, and moving work forward while knowing when to bring others into the conversation.

You communicate clearly with technical and non-technical teams, build trusted relationships across functions, and care about achieving meaningful outcomes—not simply checking compliance boxes.

🎯 What You Bring

We're more interested in your experience, judgment, and approach than checking every box. If you're excited about this role but don't meet every qualification, we'd still encourage you to apply.✅ Required

5+ years of experience leading or supporting risk, compliance, privacy, security, or related programs within SaaS, healthcare technology, or another regulated industry.

Experience building or improving risk and compliance programs—not just maintaining them.

Experience supporting customer security reviews, vendor assessments, due diligence, enterprise procurement processes, and/or compliance-related customer agreements.

Working knowledge of HIPAA and experience applying privacy and security requirements in a practical business environment.

Experience preparing for or supporting security audits, certifications, or compliance assessments.

Strong written communication skills and the ability to translate complex requirements into clear, practical guidance.

Strong business judgment and the ability to work effectively across technical and non-technical teams.

⭐ Nice to Have

Familiarity with GDPR, CCPA, or other privacy frameworks.

Experience with SOC 2, ISO 27001, HITRUST, NIST, or similar standards.

Experience working in healthcare, behavioral health, education, or another highly regulated industry.

Familiarity with HECVATs, VPATs, accessibility requirements, or enterprise procurement processes.

Experience working in a growing SaaS company where processes and priorities evolve quickly.

💙 Perks & Benefits You'll Love

🏥 Health & Wellness:

100% covered health, dental, and vision premium for employee-only standard plan (Family can join too, with a variable cost)

Employer Sponsored Short-Term Disability Coverage

Employer Sponsored Life Insurance

Optional group benefits: AD&D, long-term disability

Participation in a 401k plan through Empower

🎓 Growth & Development:

Professional development opportunities

Room for growth within the company

🏖️ Time Off to Recharge:

Paid Time Off: 10 vacation days, 5 sick days, 7 paid holidays + 3 floating holidays for ultimate flexibility

🐣 Parental Leave:

All Parents/Caregivers: 6 weeks fully paid

Birthing Parents: Up to 14 weeks paid

🏡 Work Style That Works for You:

Fully remote and flexible work environment—work from wherever feels right!

Opportunity to make a meaningful impact in the Autism healthcare space

📩 How to Apply

Use our applicant tracking system Pinpoint to answer the role-specific application questions. These questions were thoughtfully designed to give you more insight into the role and to give us more insight into you. Please write a thoughtful response—a human really reads these.

If you need accommodations during the application process, just let us know—we’re happy to help. 😊

Originally posted on Himalayas
risk-and-compliance compliance-lead privacy-officer compliance-management healthcare-compliance risk-management-lead risk-and-compliance-manager regulatory-compliance-lead ethics-and-compliance-lead risk-and-compliance-leadership compliance-and-risk-leadership financial-crime-compliance-lead
Apply on Himalayas →

Job sourced from Himalayas. Applications happen directly on the original platform — we never collect your data.