Manager of Security and Compliance
New
J
JobgetherHealthcare SaaS
This is a fully remote role for candidates based in the United StatesFull-TimeManager
Salary130,000 - 150,000 USD per year
Apply NowOpens the employer's application page
Job Details
- Experience
- 7+ years of experience in information security, healthcare compliance, privacy, risk management, or a closely related discipline
- Required Skills
- HIPAARisk Management
Requirements
- Have 7+ years of experience in information security, healthcare compliance, privacy, risk management, or a closely related discipline.
- Have strong working knowledge of HIPAA, SOC 2, HITRUST, healthcare privacy requirements, and security control frameworks.
- Have served as the accountable owner for at least one HITRUST i1 or r2 certification, from scoping through evidence collection, assessor management, and corrective action planning.
- Have demonstrated experience leading audits, risk assessments, compliance programs, remediation initiatives, and external security or compliance partners.
- Bring practical knowledge of cloud and SaaS security, identity and access management, vulnerability management, encryption, logging, data protection, and incident response.
- Have experience partnering with Engineering and Product teams to integrate security into technology architecture and development processes.
- Have experience with vendor risk management and third-party security assessments.
- Have experience working with healthcare technology, electronic medical records, clinical systems, or sensitive healthcare data environments.
- Have strong communication skills to translate technical, regulatory, and security requirements for technical and non-technical stakeholders.
- Relevant certifications such as CCSFP, CISSP, CISM, or HCISPP are preferred.
- Experience with Azure, Kubernetes/AKS, DevSecOps, or security automation is advantageous.
Responsibilities
- Own and mature security, privacy, and compliance programs covering HIPAA, SOC 2, HITRUST, and applicable healthcare privacy requirements.
- Lead HITRUST certification from scoping and readiness assessments through evidence collection, assessor coordination, remediation, and corrective action plans.
- Manage audits, risk assessments, penetration tests, security reviews, evidence collection, and remediation activities.
- Build continuous, system-generated compliance processes and maintain the security and compliance roadmap.
- Partner with Engineering, Product, Platform, SRE, and IT to integrate security into architecture, infrastructure, product development, and the software development lifecycle.
- Oversee identity and access management, logging and monitoring, encryption, vulnerability management, data retention, data protection, and vendor risk.
- Lead security incident response, including investigation, stakeholder communication, post-incident reviews, and corrective actions.
- Maintain security policies, procedures, Business Associate Agreements, data-handling requirements, and breach-response plans.
- Support customer security reviews, due diligence, onboarding, and security and privacy requirements during contract negotiations.
- Lead security awareness and compliance training and manage, develop, and mentor the security and compliance team.
View Full Description & ApplyYou'll be redirected to the employer's site