--- title: 'Security & Compliance Lead at Maigrate' canonical: 'https://feeny.ai/job/security-compliance-lead-maigrate-lawrence-5npfj9b9qw5p' type: 'job' last_seen: '2026-09-09' --- # Security & Compliance Lead at Maigrate - **Company:** Maigrate - **Location:** Lawrence, NY - **Employment:** full-time - **Work type:** hybrid - **Posted:** 2026-08-18 - **Last confirmed live:** 2026-09-09 - **Apply:** https://jobs.ashbyhq.com/maigrate/bc8d2839-c149-4c84-9fa7-a34d522d7dc8 ## Job description Location: Hybrid (Lawrence, NY) Reports to: CEO Compensation: $160,000 to $200,000, plus health coverage and PTO ## About Maigrate Maigrate builds AI-powered products for mid-market companies. Our software stays in production and keeps working. We started in healthcare and it remains our largest market. We are moving into finance and other industries. We are early-stage and growing fast. The people who join now will shape how we operate and what we become. Our software handles protected health information for ABA therapy providers and other healthcare organizations, and we operate as a business associate under HIPAA. ## About the Role We are hiring our first dedicated security and compliance owner. You will serve as our designated HIPAA Security Officer and own the security program across the company. You will build Maigrate's security and compliance program from the ground up. You will lead SOC 2 readiness through Type II, build the policy and control framework, establish our HIPAA security program, and put the systems in place to keep all of it running as we scale. The work has a second layer most security roles do not have. Our products run on large language models, which creates new questions around what data reaches a model, how providers handle that data, what gets logged, how long it is retained, and how AI systems are monitored in production. You will own the controls around that layer too. You will personally build the compliance foundation. On the technical side, you will set the requirements, verify the work, and drive remediation with engineering, who will implement the changes. ## What You'll Do Build the compliance program - Serve as Maigrate's designated HIPAA Security Officer - Own the HIPAA security program, including security risk analysis, risk management, policies, controls, and documentation - Lead SOC 2 readiness through Type II and manage the audit process end to end - Write and maintain the security policy set and make sure the company follows it - Run our GRC platform, such as Vanta or Drata, and automate evidence collection wherever possible - Track findings, remediation work, and ongoing compliance requirements Set and enforce technical security standards - Define access control, identity, and least-privilege requirements, and verify engineering enforces them across cloud and SaaS systems - Set security standards for our cloud environment and hold the company to them - Own vulnerability management as a program: define the process, prioritize findings, and drive engineering to close them - Set requirements for endpoint security, monitoring, and logging, and confirm coverage is real - Coordinate penetration testing and drive findings through remediation - Investigate findings directly in the environment when you need to understand what is actually happening - Set security requirements for business continuity, backups, and disaster recovery Own incident response - Build and maintain the incident response plan and test it before we need it - Lead the response when a security incident happens - Own incident investigation, documentation, and post-incident remediation - Coordinate breach assessment and required notifications under HIPAA, applicable BAAs, and applicable state breach notification requirements - There is no formal on-call rotation, but as the security owner, you will be expected to lead the response to significant security incidents when they occur, including outside normal business hours when necessary Set the AI security and governance controls - Define what data may reach an AI model and what must be de-identified or removed first - Ensure PHI is only shared with model providers under appropriate HIPAA-compliant arrangements - Review model providers for data retention, training, logging, security, and subcontractor risks - Set logging, retention, access, and review standards for prompts and outputs - Define the controls and fallback requirements for when AI systems fail or behave unexpectedly, and work with product and engineering on implementation Support the business - Answer customer security questionnaires and lead customer security and compliance reviews - Own the security and compliance requirements around BAAs and our subcontractor chain, working with counsel where needed - Run vendor security and risk reviews before we adopt systems that touch customer or company data - Maintain the security documentation customers need during diligence - Deliver security training people actually remember - Develop the annual security and compliance budget, recommend tooling and outside spend, and present priorities to the CEO for approval ## What We're Looking For Must have - 6+ years in security, compliance, or a comparable role - You have built a security and compliance program from the ground up in a cloud SaaS environment, including taking SOC 2 from readiness through audit - Working HIPAA knowledge from the business associate side, including PHI handling, BAAs, security risk analysis, and breach response - Strong cloud security skills. You are comfortable getting into the environment yourself, investigating findings, and working directly with engineering to remediate them - Experience with identity and access management, vulnerability management, logging, endpoint security, and incident response - Ability to turn a control requirement into clear instructions an engineer will actually follow - Comfort speaking directly with customer security and compliance teams - Ability to operate in an early-stage environment where the program is still being built ## Preferred - CISSP, CISA, or HCISPP - Experience securing LLM-based or AI-native products - HITRUST or NIST framework experience - Experience working with healthcare SaaS companies - Experience supporting security and compliance requirements for customers in regulated financial services environments ## Equal Opportunity Maigrate is an equal opportunity employer. We consider qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, disability, veteran status, or any other characteristic protected by applicable law. ## About Maigrate ## Company Overview - **One-liner**: Maigrate is an AI transformation partner that embeds dedicated teams inside mid-market American businesses to build and deploy tailored AI tools that drive measurable value. - **Entity Type**: Private (early-stage startup, likely bootstrapped or seed-stage based on launch date) - **Headquarters**: Lawrence, New York, USA (with an office also in Potsdam, NY) - **Founded**: February 24, 2026 (public launch date) - **Founders**: Eli Langer (CEO), Steven Mandel — the team also includes early engineer from Litify (Noah Blumenthal) ## Core Business - **Primary industry**: AI Consulting & Transformation / AI Implementation Services - **Target customers**: Established American mid-market businesses (SMB to mid-market enterprises) looking to integrate AI to improve profitability, efficiency, and growth. - **Mission**: “Business to AI” — to make AI work inside real businesses, moving the needle on profits, efficiency, and growth by deploying AI that fits into existing workflows — not just strategy decks. ## Products & Services - **AI Opportunity Audit**: A complimentary diagnostic service offered to prospective clients, mapping how a business operates, identifying process bottlenecks, data quality gaps, and where AI can create the most measurable value. - **Embedded AI Transformation Teams**: The core offering — Maigrate places dedicated teams directly inside client operations to build, deploy, and iterate on AI tools tailored to that business. The firm commits to delivering at least $1 million in measurable value (revenue, cost savings, quality improvement) per engagement. - **Proprietary Diagnostic & AI Deployment Tools**: Internal tools to map workflows, enable AI integration without disruption, and ensure business impact “compounds at unprecedented rates.” ## Market Standing - **Valuation**: Not disclosed (private, early-stage startup) - **Key Metric**: Just launched in February 2026 - **Notable Investors/Partners**: Not publicly disclosed (no funding rounds or institutional investors visible) - **Growth Signals**: Launched publicly in Feb 2026; already hiring for key roles (Full Stack AI Engineer, Junior AI Engineer) across two locations (Lawrence, NY and Potsdam, NY); growing team with a clear mission and a strong founding team with experience at Litify, Fortune 10 companies, and large law firms. ## Competitive Advantages - **Embedded, outcome-driven model**: Unlike typical AI consultants who deliver strategy decks, Maigrate’s teams live inside the client’s business, own the outcome, and are tied to a guarantee of at least $1M in measurable value. - **Strong founding team**: Combines deep engineering (ex-Litify early engineer), AI/infrastructure expertise, and enterprise transformation experience at the world’s largest law firms and Fortune 10 companies. - **Proprietary diagnostic and deployment tools**: Builds and deploys its own tooling to map business operations and integrate AI without disruption, creating a moat in execution capability. - **Security-first approach**: End-to-end encryption, strict access controls, and compliance-ready systems built into every deployment. ## Strategic Focus - **Scale the team and client base**: Rapidly hiring to assemble the team that will “set the standard for how companies adopt AI.” - **Deepen the embedded model**: Perfecting the methodology of embedding AI engineers inside mid-market businesses to achieve compounding business impact. - **Expand geographic footprint**: Offices in Lawrence, NY and Potsdam, NY (both in New York) indicate a US-focused geographic strategy initially, with hybrid work flexibility. ## Why Work Here - **Mission-driven culture**: The company describes itself as a “mission, not a job” and asks employees to “do the most important work of your career.” High ownership, real impact on client businesses. - **Early-stage opportunity**: Joining as one of the first engineers means helping shape the product, culture, and operating model from the ground up. - **Fast-paced, high-autonomy environment**: “You’ll be trusted with a meaningful mission” — engineers own features end-to-end, from design to deployment, and “live with the outcomes.” - **Hybrid flexibility**: Roles are based in Lawrence, NY or Potsdam, NY with hybrid flexibility (in-person core but not fully remote). - **AI-native focus**: Engineers work directly with AI solutions daily — ideal for someone who wants to build real AI systems, not just talk about them. - **Security-focused engineering**: Emphasis on end-to-end encryption and compliance — a strong signal for engineers who care about building robust, trustworthy systems. - **Perks**: Not explicitly listed, but typical early-stage startup environment with high impact and growth potential. ## Sources 1. [maigrate.com](https://maigrate.com) — Company website (overview, team, mission) 2. [maigrate.com/careers](https://maigrate.com/careers) — Careers page (culture, open positions) 3. [einpresswire.com](https://www.einpresswire.com/article/895022241/maigrate-opens-its-doors-to-american-business-owners) — Press release (launch announcement, Feb 24, 2026) 4. [jobsearcher.com](https://jobsearcher.com/companies/maigrate) — Job listings and location data 5. [tealhq.com](https://www.tealhq.com/job/full-stack-ai-engineer_7ea1aa34b1588ed83eb14648378dd5714fc2c) — Full Stack AI Engineer job posting (responsibilities, requirements, culture) ## Other roles at Maigrate - [AI Product Lead](https://feeny.ai/job/ai-product-lead-maigrate-lawrence-e13dqdnb7zzy) — Lawrence, NY - [Security & Compliance Lead](https://feeny.ai/job/security-compliance-lead-opal-security-san-francisco-b414fmaeemcp) — San Francisco, CA - [Security & Compliance Lead](https://feeny.ai/job/security-compliance-lead-atari-inc-delhi-skcxjn99nkqj) — Delhi, India - [Security & Compliance Lead](https://feeny.ai/job/security-compliance-lead-playpower-labs-india-th67h1yxq67h) — India