--- title: 'Security and Compliance Manager at Clinically AI' canonical: 'https://feeny.ai/job/security-and-compliance-manager-clinically-ai-san-diego-wk088eqtzwv8' type: 'job' last_seen: '2026-09-06' --- # Security and Compliance Manager at Clinically AI - **Company:** Clinically AI - **Location:** San Diego, CA - **Employment:** full-time - **Work type:** hybrid - **Posted:** 2026-08-10 - **Last confirmed live:** 2026-09-06 - **Apply:** https://jobs.ashbyhq.com/clinicallyai/bcaff212-93a7-47d4-90ee-538d08973778 ## Job description ## ABOUT CLINICALLY AI Clinically AI is a rapidly scaling healthcare AI company transforming how behavioral health and healthcare organizations manage clinical documentation, compliance workflows, chart auditing, and operational efficiency through artificial intelligence. Our platform helps clinicians, compliance teams, administrators, and healthcare organizations reduce administrative burden, improve documentation quality, strengthen audit readiness, and operate more efficiently. We operate at the intersection of AI, healthcare operations, workflow design, and real-world clinical execution, where adoption, trust, usability, and measurable outcomes matter. ## THE OPPORTUNITY We are seeking a Security and Compliance Manager to own the day-to-day operation of our compliance program end to end, keeping our frameworks audit-ready, our policies current, and our workforce systems locked down. This is a critical role for someone who can manage our compliance platform of record, drive remediation on failing controls to closure, and administer the workforce security layer (Google Workspace and MDM) that our compliance posture depends on. You will work closely with engineering, product, and executive leadership to keep the company continuously compliant as we scale at high velocity. This is not a purely administrative, ticket-routing role. You should be comfortable owning remediation from detection to closure, operating with high rigor, and driving issues to resolution yourself rather than just flagging them, in a fast-moving startup environment. We believe a successful compliance function is defined not by simply passing audits, but by continuous audit-readiness, strong workforce security hygiene, and trust earned with enterprise customers. ## WHAT YOU'LL OWN - Own our compliance platform of record — manage frameworks (SOC2 Type II, HIPAA, NIST, etc.), controls, tests, policies, and integrations. - Monitor compliance tests continuously; triage failures, remediate directly where possible, and drive owners to resolution where not. - Maintain and update security policies, procedures, and system documentation, ensuring they reflect actual practice and are reviewed/acknowledged on schedule. - Manage evidence collection and audit readiness, keeping automated evidence flowing and closing gaps in manual evidence before auditors ask. - Coordinate external audits (SOC2 Type II, HIPAA, NIST, ISO, etc.) end to end — auditor communication, evidence requests, findings, and remediation plans. - Administer Google Workspace, including user lifecycle management, access controls, 2FA/SSO enforcement, and audit log reviews. - Manage our MDM to ensure all endpoints are enrolled, encrypted, patched, and compliant with policy. - Track risk via risk assessments and the risk register, and lead mitigation planning with stakeholders. ## WHAT WE'RE LOOKING FOR - Compliance Ownership: You treat a failing compliance test as a to-do item, not a ticket to route elsewhere — you drive remediation from detection to closure yourself. - Operational Rigor: You maintain accurate, up-to-date policies and documentation, and keep evidence collection running continuously rather than scrambling before an audit. - Security & IT Administration Fluency: You're comfortable administering Google Workspace and MDM tooling directly — user lifecycle, access reviews, and endpoint compliance are second nature to you. - Cross-Functional Collaboration: You partner effectively with engineering, product, and leadership, scoping remediation work and reporting compliance posture clearly to non-technical stakeholders. - High Ownership Mindset: You operate with follow-through in a high-velocity, fast-scaling environment, without needing heavy oversight. ## REQUIRED QUALIFICATIONS - 3+ years of experience in security compliance, GRC, IT security administration, or similar roles. - Hands-on experience administering a compliance automation platform (e.g., Vanta, Drata, or Secureframe), including frameworks, tests, policies, and remediation workflows. - Direct experience with SOC2 Type II and/or HIPAA compliance programs — evidence collection, audits, and continuous control operations. - Experience administering Google Workspace in a business environment (user lifecycle, security settings, access controls). - Experience managing an MDM solution (e.g., Kandji, Jamf, Mosyle, or similar) for endpoint compliance. - Ability to write, maintain, and operationalize security policies and compliance documentation. - Strong organizational and follow-through skills — comfortable owning remediation from detection to closure. ## PREFERRED QUALIFICATIONS - Experience in healthcare, healthtech, or another regulated data environment. - Familiarity with additional frameworks (HITRUST, ISO27001, NIST) and experience adding new frameworks to a compliance platform. - Experience supporting enterprise customer security reviews, RFPs, and partner compliance requirements. - Working knowledge of cloud environments (GCP preferred) sufficient to coordinate remediation with engineering teams. - Experience with identity and access tooling (SSO/SAML, Google Cloud Identity, Okta, or similar). - Certifications such as CISA, CISM, Security+, CCSK, or equivalent practical experience. ## COMPENSATION & BENEFITS Base salary: $110,000–$165,000 + equity Actual compensation will depend on experience, scope, and overall alignment with the role. We offer competitive compensation, equity participation, healthcare coverage (medical, dental, vision), unlimited PTO, and a 401(k) with company match plus Roth option. ## EQUAL EMPLOYMENT OPPORTUNITY Clinically AI provides equal employment opportunities to all employees and applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, genetics, or any other characteristic protected by applicable law. ## About Clinically AI ## Company Overview - **One-liner**: Clinically AI provides an AI-powered platform for behavioral health organizations to automate clinical documentation, ensure compliance, and reduce administrative burden. - **Entity Type**: Private (Startup) - **Headquarters**: San Diego, California, United States - **Founded**: 2023 - **Founders**: Ross Young (CEO) and Elijah Lipsky (CTO) ## Core Business - **Primary industry**: Healthcare IT / Behavioral Health Technology - **Target customers**: B2B; behavioral health organizations including private practices, group practices, and multi-state networks; clinicians, case managers, and compliance teams. - **Mission or purpose statement**: To support clinicians by using AI to reduce administrative burden, minimize compliance risk, and help care teams spend more time with people—not in clicks. The company believes in "augmented intelligence, not artificial replacement." ## Products & Services - **Clinical Notes AI**: An AI-powered documentation tool that generates accurate, individualized clinical notes in seconds. It is "Chart-Aware," meaning it understands the longitudinal client record and documents in context. It aligns with service lines, treatment plans, and client goals. - **Comply**: A real-time chart auditing tool that aligns with an organization's best practices and regulations to provide chart quality metrics and catch issues before they become problems. - **Front Door**: A referral support tool for program placement and summarization (currently in beta). - **Supervise**: A supervision tool with insights for supervising staff and associates (coming soon). ## Market Standing - **Valuation/Market Cap**: Not publicly available. - **Key Metric**: Total Funding – Not publicly available. The company is privately held and has not disclosed funding rounds. - **Notable Investors/Partners**: Not publicly disclosed. The company lists "Technology Partners" on its website but does not name specific investors. - **Growth Signals**: The company has grown from 13 to 21 employees (+40% YoY) as of mid-2026. It has a LinkedIn following of 3,465 (+79.3% yearly growth). It is used by "thousands of clinicians nationwide." The company reports a 60-80% reduction in documentation time and a 40% reduction in payer reviews for level of care placement. ## Competitive Advantages - **Purpose-built for behavioral health**: Unlike general AI scribes, Clinically AI is designed specifically for the workflows, regulations (e.g., FERPA, HIPAA), and service lines of behavioral health and integrated care. - **EHR agnostic**: The platform integrates with any web-based EHR, allowing organizations to keep their existing systems. - **Ethics-first, clinician-centered AI**: The company emphasizes "augmented intelligence" and that clinical judgment directs the AI, not the other way around. They offer zero data retention options and are SOC 2 certified. - **Chart-aware AI**: The AI understands the full longitudinal client record, not just a single session, leading to more accurate and contextual documentation. ## Strategic Focus - **Scaling the platform**: The company is actively hiring across engineering, product, sales, and clinical informatics to support growth. - **Expanding product suite**: Moving beyond notes into compliance, referral management, and supervision tools. - **Deepening EHR integrations**: Ensuring seamless integration with the leading EHR platforms used in behavioral health. - **Building for enterprise**: Offering solutions for solo practitioners, group practices, and large multi-state networks. ## Why Work Here - **Culture**: The company describes itself as a team of "creatives, clinicians, product thinkers, engineers, and behavioral health advocates." They value mission-driven work, transparency, and ethical technology. They are "allergic to buzzwords." - **Remote-first**: The company is fully remote, with team members distributed across the US and Spain. They emphasize "Work Anywhere. Impact Everywhere." - **Impact**: Employees work on tools that directly support clinicians doing "some of the hardest, most human work there is." The company is focused on solving real problems in behavioral health. - **Growth**: As an early-stage company, there is room for employees to grow professionally and personally as the company scales. - **Diversity & Inclusion**: Clinically AI is an equal opportunity employer committed to building a team that reflects the diversity of the communities they serve. ## Sources 1. [clinicalnotes.ai](https://www.clinicalnotes.ai/index.html) 2. [clinicalnotes.ai - Careers](https://www.clinicalnotes.ai/about/careers.html) 3. [LinkedIn - Clinically AI](https://www.linkedin.com/company/clinically-ai-1) 4. [clinicalnotes.ai - Executive Team](https://www.clinicalnotes.ai/about/meet-our-executive-team.html) 5. [clinicalnotes.ai - Careers (alt)](https://www.clinicalnotes.ai/1moved-careers.html) ## Other roles at Clinically AI - [IT Manager](https://feeny.ai/job/it-manager-clinically-ai-san-diego-y4msrrpswsc1) — San Diego, CA - [DevOps Engineer](https://feeny.ai/job/devops-engineer-clinically-ai-san-diego-xvnj3njy2mzd) — San Diego, CA - [Head of Product](https://feeny.ai/job/head-of-product-clinically-ai-san-diego-4f7pw5d62wqn) — San Diego, CA - [Clinical AI Implementation Lead](https://feeny.ai/job/clinical-ai-implementation-lead-clinically-ai-san-diego-979trzt4q4ky) — San Diego, CA - [Territory Director](https://feeny.ai/job/territory-director-clinically-ai-united-states-re9wpzvat413) — United States - [Security and Compliance Manager](https://feeny.ai/job/security-and-compliance-manager-sierra-london-5b2tchnqksjf) — London, United Kingdom - [Security and Compliance Manager](https://feeny.ai/job/security-and-compliance-manager-sierra-san-francisco-q9m86r52a0ar) — San Francisco, CA