Senior Director, Security & Compliance

prompt

Deutschland

Remote

EUR 150.000 - 230.000

Vollzeit

Vor 6 Tagen
Sei unter den ersten Bewerbenden
Bewerbungsgenerator

Erhalte eine Antwort von diesem Arbeitgeber — ein Lebenslauf und ein Anschreiben, die genau auf die Eigenschaften eingehen, die gesucht werden.

Schaffe es an den ATS-Filtern vorbei

Zusammenfassung

Prompt is a healthcare SaaS leader delivering automated software to rehab therapy businesses, teams, and patients. We seek a hands-on Senior Director, Security & Compliance to own governance, policy framework, and audits, and to mature enterprise security aligned with HIPAA/HITECH, SOC 2 Type II, and related requirements.

This role partners with Legal, Engineering, IT, Product, and Finance to translate requirements into controls, ownership, and remediation, building a durable security operating

Qualifikationen

  • 8+ years in compliance, information security, or risk management with leadership responsibility.

Aufgaben

  • Serve as Compliance Officer and HIPAA Security Officer; lead security and compliance programs.

Kenntnisse

HIPAA/HITECH knowledge
SOC 2 Type II experience
Cloud security
IAM & vulnerability management
Secure SDLC
SaaS architecture
risk governance
Executive communication

Jobbeschreibung

About Prompt

Prompt is revolutionizing healthcare by delivering highly automated and modern software to rehab therapy businesses, their teams, and the patients they serve. As one of the fastest-growing companies in healthcare SaaS and the new standard in healthcare technology, we are committed to building a team that thrives in our fast-paced, innovative environment.

As Prompt continues to scale, maintaining the trust of our customers, partners, and the patients they serve is critical. We are seeking a Senior Director, Security & Compliance to lead and mature the security and compliance programs that support our continued growth.

About the Role

The Senior Director, Security & Compliance serves as the company's Compliance Officer and designated HIPAA Security Officer and is accountable for the company's enterprise compliance and information security programs.

This role owns the governance, control environment, certification and audit programs, security risk management, policy framework, and cross-functional operating model required to maintain compliance with HIPAA/HITECH, SOC 2, and other applicable regulatory, contractual, and certification requirements.

The Senior Director will partner closely with Legal, Engineering, DevOps, IT, Product, People, Finance, and other business functions to translate requirements into clear controls, accountable owners, remediation plans, and sustainable operating processes. This is a hands-on leadership role for someone who wants to build and mature the program while leveraging strong technical resources across the organization.

Key Responsibilities
  • Serve as the company's Compliance Officer and designated HIPAA Security Officer, leading the company's compliance and information security programs.
  • Own HIPAA/HITECH compliance, including the Security Risk Analysis, risk-management plan, and ongoing oversight of required safeguards.
  • Be accountable for SOC 2 Type II and other compliance certifications, attestations, and assurance programs, including audit readiness, auditor relationships, remediation, and evidence sufficiency.
  • Own the company's compliance and information-security policy framework, including policy development, review, approval, exceptions, and ongoing governance.
  • Establish clear ownership for controls across the organization and ensure deficiencies, risks, and remediation plans are identified, tracked, and appropriately escalated.
  • Partner with Engineering, DevOps, architecture, and IT leaders to evaluate security approaches and ensure technical controls appropriately address compliance and risk requirements.
  • Own the security incident-response framework and partner with Legal, Privacy, technical teams, and executive leadership on incident assessment, response, and remediation.
  • Lead the security and compliance aspects of third-party risk management, enterprise customer diligence, audits, RFPs/RFIs, and security escalations.
  • Partner with Product, AI, Engineering, Legal, and other stakeholders to establish appropriate governance for emerging technologies and the use of sensitive data.
  • Continuously improve the company's compliance and security operating model so that requirements are clear, ownership is durable, and controls operate effectively in practice.
Qualifications
  • 8+ years of experience in compliance, information security, risk management, or related disciplines, including meaningful leadership responsibility.
  • Deep practical knowledge of HIPAA/HITECH and healthcare compliance requirements, ideally within a covered entity or business associate environment.
  • Demonstrated experience leading SOC 2 Type II or comparable certification and assurance programs.
  • Experience building or materially improving compliance governance, control environments, policy frameworks, audit readiness, and cross-functional accountability.
  • Strong working knowledge of cloud security, application security, IAM, vulnerability management, endpoint security, secure SDLC practices, and modern SaaS architecture.
  • Ability to engage credibly with technical leaders, evaluate proposed approaches, identify material risk, and translate technical issues into business, compliance, and customer impact.
  • Strong executive judgment and communication skills, with the ability to work effectively across Legal, Engineering, Product, IT, People, Finance, auditors, customers, and executive leadership.
  • Demonstrated ability to drive accountability across functions without relying solely on direct reporting relationships.
  • Relevant certifications such as CISSP, CISM, CRISC, CISA, CHC, or similar are preferred but not required where equivalent experience is demonstrated.
What We're Looking For

We're looking for a hands-on security and compliance leader who can build a durable program, not simply oversee an established one. The right person will bring deep healthcare compliance expertise, strong risk judgment, and enough technical fluency to work effectiv

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Senior Director, Security & Compliance (Fully Remote)
Senior Director, Security & Compliance (Fully Remote)

Prompt • Deutschland

Hybrid
EUR 140.000 - 230.000
Remote/Hybrid environment
Equity potential
Flexible PTO
+5
Head of Compliance
Head of Compliance

baba • Deutschland

Hybrid
EUR 104.000 - 129.000
Vice President, Information Security
Vice President, Information Security

Springhealth66 • Deutschland

Remote
EUR 215.000 - 250.000
Health, Dental, Vision benefits
Privacy and Compliance Specialist
Privacy and Compliance Specialist

Jobgether • Deutschland

Remote
EUR 86.000 - 103.000
Equity opportunities
Remote-first work environment
Platform Information Security Officer, Diagnostics Platform
Platform Information Security Officer, Diagnostics Platform

Jobtailor • Deutschland

Remote
EUR 180.000 - 240.000
Senior Operations Manager, Implementation & Accounts – Hospital Billing
Senior Operations Manager, Implementation & Accounts – Hospital Billing

Jobtailor • Deutschland

Remote
EUR 90.000 - 130.000
Head of Consulting
Head of Consulting

SoSafe • Köln

Vor Ort
EUR 90.000 - 120.000
Flexible hours
33 vacation days
State-of-the-art tech
+2
Senior Compliance and Risk Analyst
Senior Compliance and Risk Analyst

Optimizely • Berlin

Vor Ort
EUR 75.000 - 105.000
Director, Client Services
Director, Client Services

Jobtailor • Deutschland

Remote
EUR 70.000 - 110.000
Director, Cyber Compliance (Information Security)
Director, Cyber Compliance (Information Security)

Cardinal Health • Deutschland

Remote
EUR 118.000 - 200.000
Medical, dental and vision coverage
Paid time off plan
Health savings account (HSA)
+7