Senior Associate, Compliance
Your Impact on our Mission
Zocdoc’s most important asset is our people. Join Zocdoc as a Senior Associate, Compliance to help provide better care to patients and build a better health care experience! As an Audit Associate, you’ll play a critical role in maintaining the trust of our patients, healthcare providers, and business partners by helping Zocdoc prepare for and successfully complete compliance audits and assessments, including HITRUST, SOC 2, and HIPAA-related reviews. You’ll work closely with our Information Security, Compliance, Legal, Technology, Product, People, and business teams to translate audit requirements into clear actions, gather and validate evidence, and deliver complete, well-organized responses to auditors. This is a great opportunity to join a growing team, improve the way Zocdoc manages audit readiness, and help scale our compliance program as the company and its obligations grow.
You’ll enjoy this role if you are…
Competent in compliance, security, privacy, healthcare, and building trustworthy processes
Excited to partner with control owners across Zocdoc to understand how work gets done and turn that work into clear, audit-ready evidence
Experienced in managing details across multiple workstreams, deadlines, stakeholders, and audit requests
Not afraid of driving audit-readiness initiatives on your own or taking ownership of larger projects with support from the broader team
Organized, proactive, and comfortable following up with partner teams to keep evidence collection and remediation work moving
Always looking to improve repeatable processes, reducing audit burden, and help Zocdoc deliver a consistent experience to auditors and internal stakeholders
Your day to day is…
Supporting HITRUST, SOC 2, HIPAA-related, and other compliance audits and assessments from planning through completion
Reviewing audit criteria, control requirements, prior-year findings, and auditor requests to determine the evidence and stakeholder inputs needed
Coordinating evidence collection with control owners across Information Security, Engineering, Infrastructure, Product, Legal, People, Finance, and other business teams
Gathering, organizing, naming, tracking, and quality-checking evidence to ensure it is complete, current, relevant, and mapped to the correct requirement or control
Preparing evidence packages, control narratives, management responses, and supporting documentation for delivery to auditors
Managing audit request lists, project plans, due dates, status reporting, action-item logs, and escalation paths
Partnering with control owners to clarify requirements, identify evidence gaps, and improve the quality and repeatability of control execution
Reviewing audit evidence and processes for opportunities to strengthen documentation, clarify ownership, improve control consistency, and reduce recurring findings
Supporting auditor meetings, walkthroughs, interviews, follow-up questions, and requests for additional information
Tracking observations, exceptions, and remediation commitments through resolution, including coordinating updates and validating closure evidence
Helping build scalable audit operations through standardized evidence repositories, reusable control narratives, centralized calendars, templates, automation, and reporting
Identifying opportunities to streamline audit work as Zocdoc grows, including reducing duplicate evidence requests and creating repeatable processes for new systems, vendors, products, and teams
Maintaining accurate compliance program documentation and contributing to internal reporting on audit readiness, open gaps, and program health
You’ll be successful in this role if you have…
4-7 years of experience in IT audit, compliance, information security, privacy, risk management, internal controls, or a related field
Familiarity with compliance frameworks, control testing, audit evidence, and common security and privacy requirements
Exposure to HITRUST, SOC 2, HIPAA, NIST, ISO 27001, or similar frameworks and assessment processes
Experience gathering and reviewing evidence such as policies, procedures, tickets, access reviews, training records, system configurations, logs, reports, and meeting artifacts
Strong project management skills, including the ability to manage multiple requests, dependencies, deadlines, and stakeholders at the same time
Excellent written and verbal communication skills, with the ability to explain requirements clearly to technical and non-technical audiences
Strong attention to detail and a disciplined approach to documentation, follow-up, and quality assurance
Comfort working with spreadsheets, ticketing systems, shared documentation platforms, GRC tools, and other systems used to manage audit work
Ability to identify process gaps, ask thoughtful questions, and recommend practical improvements without losing sight of audit requirements
Ability to work independently while collaborating closely with Information Security, Compliance, Legal, Technology, Product, and business teams
Bachelor’s degree in accounting, information systems, cybersecurity, business, or a related field is preferred
CISA, CIA, CRISC, Security+, or other relevant certification is a bonus
Benefits:
An incredible team of smart and supportive people
● A competitive compensation package, including attractive medical insurance
● Amazing perks – think catered lunch every day, Ping Pong, etc.
● Daycare reimbursement
● The chance to create a better healthcare experience for millions of patients!
● Cellphone and wifi reimbursement
● Competitive parental leave
● Sabbatical leave (over 5 years)
● Annual sponsored health check-ups
● Zocdoc is certified as a Great Place to Work 2025-2026