Senior Associate, Compliance
Zocdoc
Let the right jobs find you
Get personalised suggestions from verified company career pages, matched to your role, location, level, and skills.
Overview
Position Type
Full Time
Experience
4+ years
Job Description
Your Impact on our Mission
Zocdoc’s most important asset is our people. Join Zocdoc as a Senior Associate, Compliance to help provide better care to patients and build a better health care experience! As an Audit Associate, you’ll play a critical role in maintaining the trust of our patients, healthcare providers, and business partners by helping Zocdoc prepare for and successfully complete compliance audits and assessments, including HITRUST, SOC 2, and HIPAA-related reviews. You’ll work closely with our Information Security, Compliance, Legal, Technology, Product, People, and business teams to translate audit requirements into clear actions, gather and validate evidence, and deliver complete, well-organized responses to auditors. This is a great opportunity to join a growing team, improve the way Zocdoc manages audit readiness, and help scale our compliance program as the company and its obligations grow.
You’ll enjoy this role if you are…
- Competent in compliance, security, privacy, healthcare, and building trustworthy processes
- Excited to partner with control owners across Zocdoc to understand how work gets done and turn that work into clear, audit-ready evidence
- Experienced in managing details across multiple workstreams, deadlines, stakeholders, and audit requests
- Not afraid of driving audit-readiness initiatives on your own or taking ownership of larger projects with support from the broader team
- Organized, proactive, and comfortable following up with partner teams to keep evidence collection and remediation work moving
- Always looking to improve repeatable processes, reducing audit burden, and help Zocdoc deliver a consistent experience to auditors and internal stakeholders
Your day to day is…
- Supporting HITRUST, SOC 2, HIPAA-related, and other compliance audits and assessments from planning through completion
- Reviewing audit criteria, control requirements, prior-year findings, and auditor requests to determine the evidence and stakeholder inputs needed
- Coordinating evidence collection with control owners across Information Security, Engineering, Infrastructure, Product, Legal, People, Finance, and other business teams
- Gathering, organizing, naming, tracking, and quality-checking evidence to ensure it is complete, current, relevant, and mapped to the correct requirement or control
- Preparing evidence packages, control narratives, management responses, and supporting documentation for delivery to auditors
- Managing audit request lists, project plans, due dates, status reporting, action-item logs, and escalation paths
- Partnering with control owners to clarify requirements, identify evidence gaps, and improve the quality and repeatability of control execution
- Reviewing audit evidence and processes for opportunities to strengthen documentation, clarify ownership, improve control consistency, and reduce recurring findings
- Supporting auditor meetings, walkthroughs, interviews, follow-up questions, and requests for additional information
- Tracking observations, exceptions, and remediation commitments through resolution, including coordinating updates and validating closure evidence
- Helping build scalable audit operations through standardized evidence repositories, reusable control narratives, centralized calendars, templates, automation, and reporting
- Identifying opportunities to streamline audit work as Zocdoc grows, including reducing duplicate evidence requests and creating repeatable processes for new systems, vendors, products, and teams
- Maintaining accurate compliance program documentation and contributing to internal reporting on audit readiness, open gaps, and program health
You’ll be successful in this role if you have…
- 4-7 years of experience in IT audit, compliance, information security, privacy, risk management, internal controls, or a related field
- Familiarity with compliance frameworks, control testing, audit evidence, and common security and privacy requirements
- Exposure to HITRUST, SOC 2, HIPAA, NIST, ISO 27001, or similar frameworks and assessment processes
- Experience gathering and reviewing evidence such as policies, procedures, tickets, access reviews, training records, system configurations, logs, reports, and meeting artifacts
- Strong project management skills, including the ability to manage multiple requests, dependencies, deadlines, and stakeholders at the same time
- Excellent written and verbal communication skills, with the ability to explain requirements clearly to technical and non-technical audiences
- Strong attention to detail and a disciplined approach to documentation, follow-up, and quality assurance
- Comfort working with spreadsheets, ticketing systems, shared documentation platforms, GRC tools, and other systems used to manage audit work
- Ability to identify process gaps, ask thoughtful questions, and recommend practical improvements without losing sight of audit requirements
- Ability to work independently while collaborating closely with Information Security, Compliance, Legal, Technology, Product, and business teams
- Bachelor’s degree in accounting, information systems, cybersecurity, business, or a related field is preferred
- CISA, CIA, CRISC, Security+, or other relevant certification is a bonus