Total CollectR , a product of Total AI Systems , is a cutting-edge SaaS platform that helps businesses manage past-due debt collection accounts. We create better consumer experiences, help our customers collect more and empower our employees to succeed through customer success.
We are looking for a Security & Compliance Analyst who will take ownership of our compliance frameworks (SOC 2 Type II, HIPAA and others as needed) and overall security posture. You’ll work with tools like Secureframe and support regular audits, security monitoring and reporting. You will ensure we meet regulatory requirements, proactively identify and mitigate threats and implement best practices to keep our systems, data and employees secure.
Key Responsibilities
- Manage and maintain compliance with SOC 2 Type 2, HIPAA and other relevant security and privacy standards.
- Oversee compliance automation tools such as Secureframe and ensure evidence collection and controls are up-to-date.
- Run regular security reports across all instances and systems to detect and respond to threats.
- Monitor employee device and application usage to ensure up-to-date software and adherence to company security policies.
- Design, implement and monitor security controls across infrastructure, SaaS applications and development processes.
- Stay current on emerging compliance requirements and update internal practices accordingly.
- Lead security awareness training for employees and foster a security-first mindset across the company.
- Support audits, penetration tests and vendor security assessments as needed.
- Create and maintain security documentation, including policies, playbooks and incident response procedures.
Requirements
3–5 years of experience in IT security, compliance, or GRC (preferably in SaaS or IT services)Hands-on experience managing SOC 2 Type 2 auditsExposure to HIPAA, ISO 27001, or other compliance frameworks.Familiarity with compliance automation platforms such as Secureframe etc.Strong understanding of cloud security (AWS preferred) , SaaS applications and modern IT environments.Experience running security audits, reports, and threat assessments .Knowledge of endpoint management and employee security hygiene best practices.Excellent problem-solving, communication and documentation skills.Security certifications (CISSP, CISM, CISA, CCSK, or similar) are a plus.