> Markdown version of [/jobs/ext/2713256-director-of-compliance-ai-governance](https://www.wearedevelopers.com/jobs/ext/2713256-director-of-compliance-ai-governance). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Director of Compliance & AI Governance - **Company:** AKASA, LLC - **Location:** South San Francisco, CA, United States (Remote available) - **Experience:** Experienced - **Salary:** $150,000.0 - $185,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Software as a Service, Python (Programming Language), Software Tools, Scripting, Okta, Zapier, Low-code, Gsuite, GPT, SentinelOne Expertise, Software Version Control - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/director-compliance-ai-governance-akasa-8979100 ## About the Role * 8+ years experience in security compliance, GRC, or risk management, including 2+ years leading a team or function. Healthcare SaaS, health tech, or AI startup experience strongly preferred. * Deep, hands-on expertise across HITRUST CSF (r2 preferred), SOC 2 Type II, HIPAA Security and Privacy Rules, and emerging AI governance frameworks like NIST AI RMF. You've run certification and audit cycles from start to finish and know how to translate AI governance standards into real controls for a company building on PHI. * An automation-first instinct: hands-on experience with GRC and continuous control monitoring platforms (Vanta, Drata, Hyperproof, or similar), evidence collection automation, and a track record of using AI tools (ChatGPT, Claude) to push the boundaries of what a lean compliance function can do. * End-to-end policy ownership: drafting, cross-framework mapping, and running review/exception/attestation cycles. * Comfort in front of customers: enterprise security questionnaires, sales-cycle support, BAA/security terms negotiation alongside Legal, and managing customer audits. We'd love to see one or more of: * Direct experience achieving or maintaining ISO 27001, ISO 42001, or HITRUST AI certifications. * Familiarity with the technical side of a modern security stack (Okta, MDM platforms like Kandji/Iru, SentinelOne, Nightfall, AWS) and the ability to partner credibly with Security and IT on control implementation. * Experience with privacy regulations beyond HIPAA, such as CCPA/CPRA, state health data laws, or GDPR. * Implementing Compliance Automation Tools and Trust Centers like Drata or Vanta. * Scripting or low-code automation skills (Python, Zapier, Tray.io) for building compliance workflows. * Relevant certifications such as CISSP, CISA, CIPP/US, HCISPP, or HITRUST CCSFP. ## Description We're looking for a strategic, automation-minded Director of Compliance & AI Governance to own and evolve AKASA's compliance program as we scale. This role is ideal for someone who has led compliance in a healthcare SaaS or AI environment and wants to build a modern, engineering-forward program rather than a paperwork factory. You'll own our HITRUST, SOC 2, and HIPAA programs end to end, operationalize emerging AI governance frameworks like the NIST AI RMF, and drive the policy lifecycle across the company. The ideal candidate treats compliance as a product: automated evidence collection, continuous control monitoring, and policies people actually read and follow. You'll join a small, high-leverage team with immediate ownership and room to build. You thrive in a fast-paced startup environment and are agile with an ownership mindset., * Own AKASA's compliance certification portfolio end to end (including HITRUST CSF, SOC 2 Type II, and HIPAA) from control design and implementation through evidence collection, audit coordination, and remediation. Evaluate and pursue new certifications and attestations (such as ISO 27001, ISO 42001, and HITRUST AI) as customer and market needs evolve. * Define compliance roadmaps and ensure org-wide adoption, driving cross-functional alignment and accountability on regulatory requirements. * Build our AI governance program grounded in the NIST AI RMF, partnering with Engineering, Product, and Legal to establish model risk assessments, AI use policies, and documentation that meets enterprise health system expectations. * Drive compliance automation as a first principle: implement and optimize GRC and continuous control monitoring tooling, automate evidence collection across our stack (Okta, Google Workspace, Kandji/Iru, SentinelOne, Nightfall, AWS), and use AI tools to streamline policy drafting, control mapping, and audit preparation. * Own the full policy lifecycle, including authoring, review cadences, exception handling, attestation campaigns, and version control; ensuring policies are clear, practical, and mapped to the frameworks we certify against. * Be the compliance face of AKASA for customers and prospects: lead security and compliance questionnaire responses, support enterprise sales cycles, manage customer audits, and maintain trust artifacts including BAAs, our trust center, and shared assessments. Find ways to automate these processes using AI first tooling. * Oversee vendor and third-party risk management, the annual risk assessment, security awareness and HIPAA training programs, and incident response documentation and tabletop exercises in partnership with Security and IT. * Partner with Legal and Security leadership on all security-related contractual obligations. ## Related Videos - [HR ROBO SAPIENS: Decoding AI Agents and Workflow Automation for Modern Recruitment](https://www.wearedevelopers.com/videos/1470-hr-robo-sapiens-decoding-ai-agents-and-workflow-automation-for-modern-recruitment) - [Rethinking Recruiting: What you didn’t know about Responsible AI](https://www.wearedevelopers.com/videos/1090-rethinking-recruiting-what-you-didn-t-know-about-responsible-ai) - [ Evaluating AI models for code comprehension](https://www.wearedevelopers.com/videos/1462-evaluating-ai-models-for-code-comprehension) - [Agentic employees in world's most downloaded FinTech app](https://www.wearedevelopers.com/videos/100123-agentic-employees-in-world-s-most-downloaded-fintech-app) - [Create a Programmatic SEO Project Using Next.js and Static Site Generation](https://www.wearedevelopers.com/videos/449-create-a-programmatic-seo-project-using-next-js-and-static-site-generation) - [Streaming AI Responses in Real-Time with SSE in Next.js & NestJS](https://www.wearedevelopers.com/videos/1630-streaming-ai-responses-in-real-time-with-sse-in-next-js-nestjs) ## Related Articles - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere) - [Panel Discussion: Responsible AI in Practice - Real-World Examples and Challenges](https://www.wearedevelopers.com/magazine/488-panel-discussion-responsible-ai-in-practice-real-world-examples-and-challenges)