Manager of Security and Compliance

New
I
IntusCareHealthcare SaaS
This is a fully remote role based in the United States.Full-TimeManager
Salary130,000 - 150,000 USD per year
Apply NowOpens the employer's application page

Job Details

Experience
7+ years of experience in information security, healthcare compliance, privacy, or risk management
Required Skills
HIPAA

Requirements

  • Bring 7+ years of experience in information security, healthcare compliance, privacy, or risk management.
  • Have strong knowledge of HIPAA, SOC 2, HITRUST, healthcare privacy requirements, and security control frameworks.
  • Have led audits, risk assessments, compliance programs, and remediation activities, including directing external advisors and assessors.
  • Have owned at least one HITRUST i1 or r2 certification end to end, including scoping, evidence collection, assessor management, and corrective action plans.
  • Understand cloud/SaaS security, identity and access management, vulnerability management, encryption, logging, data protection, and incident response.
  • Have partnered with Engineering and Product teams to incorporate security into technology and development processes.
  • Have experience with vendor risk management and third-party security assessments.
  • Have experience working with healthcare technology, EMRs, clinical systems, or healthcare data environments.
  • Preferred: experience with PACE, value-based care, Medicare/Medicaid, or regulated healthcare environments.
  • Preferred: experience securing Azure and Kubernetes/AKS environments, including DevSecOps and security automation.
  • Preferred: experience leading a small security/compliance team or cross-functional security initiatives; certifications such as CCSFP, CISSP, CISM, or HCISPP.

Responsibilities

  • Own and continuously improve security and compliance programs across HIPAA, SOC 2, HITRUST, and applicable privacy requirements.
  • Lead HITRUST certification from scoping and readiness assessment through evidence collection, assessor coordination, and corrective action plans.
  • Lead audits, risk assessments, security reviews, penetration tests, evidence collection, and remediation efforts.
  • Manage external security and compliance partners, set their scope and priorities, and ensure findings lead to owned remediation.
  • Maintain the security and compliance roadmap, assigning owners and resolution plans to risks, vulnerabilities, audit findings, and control gaps.
  • Partner with Engineering, Product, Platform, SRE, and IT to integrate security into architecture, infrastructure, product development, and the SDLC.
  • Oversee access management, logging and monitoring, encryption, vulnerability management, data retention, and vendor risk.
  • Lead security incident investigations, communications, post-incident reviews, and corrective actions.
  • Maintain security policies, procedures, Business Associate Agreements, data handling requirements, and breach response plans.
  • Support customer security reviews and lead training, metrics, and development of the security and compliance team.
View Full Description & ApplyYou'll be redirected to the employer's site
130,000 - 150,000 USD per year
Apply Now