Cyber Security Lead

Valid8 Financial, Inc.

Burlingame (CA)

On-site

USD 180,000 - 240,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Mednition is seeking a Cyber Security Manager to lead the Information Security Program across our AI SaaS platform, including KATE Triage and KATE Sepsis. You will govern GRC, HIPAA/SOC2 audits, and secure cloud and EHR data integrations, aligning with FDA SaMD and NIST RMF guidelines.

The role requires collaboration with senior management, IT teams, and auditors, with a focus on secure data pipelines for HL7/FHIR and ongoing security improvements.

Qualifications

  • Proven experience in managing information security programs and teams.
  • Strong knowledge of governance, risk management, and compliance principles and practices.
  • In-depth knowledge of cloud cybersecurity operations (GCP, MongoDB Atlas, Cloud Run, Kubernetes), container security, CI/CD pipeline security, and SIEM.
  • Familiarity with healthcare data privacy and security standards (HIPAA, SOC2 Type 2, FDA SaMD regulations, NIST AI RMF, HL7/FHIR).
  • Excellent communication and collaboration skills, with the ability to engage stakeholders at all levels.
  • Strong project management and organizational skills, with the ability to prioritize tasks and manage multiple initiatives.
  • Experience with security audit processes and frameworks.
  • Commitment to staying up-to-date with industry trends and advancements in cyber security.

Responsibilities

  • Build, maintain, and continuously improve the Mednition Information Security Program with policies and procedures.
  • Manage the GRC program to ensure regulatory compliance and standards.
  • Oversee IT security across cloud environments, Kubernetes clusters, and MongoDB Atlas databases with monitoring and SIEM.
  • Supervise security monitoring, vulnerability assessments, incident response, and maintenance activities.
  • Provide security recommendations to development teams through briefings with stakeholders.
  • Ensure HIPAA, SOC2 Type 2 audits, FDA SaMD cybersecurity requirements, and NIST AI RMF compliance.
  • Communicate with senior management, IT teams, vendors, and auditors on security matters.
  • Support secure data integration architectures for HL7/FHIR EHR data pipelines and PHI protection.
  • Keep current with cyber security trends and promote security awareness across the organization.
  • Collaborate with cross-functional teams to implement controls and address security incidents.

Skills

InfoSec leadership
GRC principles
Cloud security
Healthcare security
Communication
PM skills
Audit experience
Continuous learning

Education

Bachelor's degree in CS/InfoSec
Master's degree preferred

Tools

CISSP
CISM
CEH

Job description

The Cyber Security Manager is responsible for building, maintaining, and continuously improving the Mednition Information Security Program across our AI SaaS platform (including KATE Triage and KATE Sepsis). This role involves managing the Governance, Risk, and Compliance (GRC) program, overseeing HIPAA compliance and SOC2 Type 2 certification audits, supervising Google Cloud Platform (GCP) and MongoDB Atlas security architectures, and ensuring security across EHR integrations (HL7, FHIR). The Cyber Security Manager will also support regulatory alignment with FDA SaMD guidelines, NIST AI Risk Management Framework, and predetermined change control plans.

Key Responsibilities:

Build, maintain, and continuously improve the Mednition Information Security Program, including developing and implementing policies, processes, and procedures to protect the organization's information systems and data.

Manage the GRC program, including the development of policies, processes, and procedures to ensure compliance with regulatory requirements and industry standards.

Oversee the IT Security Program across cloud environments, Kubernetes clusters, and MongoDB Atlas databases, including continuous monitoring, SIEM, security architecture, and vulnerability assessments.

Supervise security monitoring operations, including vulnerability and threat assessments, network access control, incident response, and maintenance activities.

Support briefings and meetings with key stakeholders, providing recommendations to development teams regarding security best practices and requirements.

Ensure compliance with HIPAA, SOC2 Type 2 audits, FDA SaMD cybersecurity requirements, and NIST AI Risk Management Framework standards.

Effectively communicate and collaborate with internal and external key stakeholders, such as senior management, IT teams, customer security teams, vendors, and auditors.

Manage secure data integration architectures for HL7/FHIR EHR data pipelines, ensuring proper handling and protection of Patient Health Information (PHI).

Stay updated with the latest cyber security trends, threats, and technologies, and evaluate their applicability to the organization's security program.

Foster a culture of security awareness and compliance throughout the organization, promoting the importance of information security and privacy.

Collaborate with cross-functional teams to implement security controls, mitigate risks, and address security-related issues and incidents.

Required Skills/Abilities:

Proven experience in managing information security programs and teams.

Strong understanding of governance, risk management, and compliance principles and practices.

In-depth knowledge of cloud cybersecurity operations (GCP, MongoDB Atlas, Cloud Run, Kubernetes), container security, CI/CD pipeline security, and SIEM.

Familiarity with healthcare data privacy and security standards (HIPAA, SOC2 Type 2, FDA SaMD regulations, NIST AI RMF, and HL7/FHIR security protocols).

Excellent communication and collaboration skills, with the ability to effectively engage with stakeholders at all levels.

Strong project management and organizational skills, with the ability to prioritize tasks and manage multiple initiatives.

Experience in working with security audit processes and frameworks.

Commitment to staying up-to-date with industry trends and advancements in the field of cyber security.

Education and Experience:

Bachelor's degree in computer science, information security, or a related field. A master's degree is preferred.

Relevant certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or Certified Ethical Hacker (CEH).

Physical Requirements:

Prolonged periods of sitting at a desk and working on a computer.

Must be able to lift 15 pounds at times.

Other Requirements:

Does not now, or in the future, require sponsorship for employment visa status (e.g. H-1B visa status)

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Security Lead
Cyber Security Lead

Mednition • Burlingame (CA)

On-site
USD 140,000 - 230,000
Cybersecurity Program Lead for AI SaaS Platforms
Cybersecurity Program Lead for AI SaaS Platforms

Valid8 Financial, Inc. • Burlingame (CA)

On-site
USD 180,000 - 240,000
Cyber Security Lead: GRC, Cloud Security & AI RMF
Cyber Security Lead: GRC, Cloud Security & AI RMF

Mednition • Burlingame (CA)

On-site
USD 140,000 - 230,000
Chief Information Security Officer (CISO) | PAM Health Corporate
Chief Information Security Officer (CISO) | PAM Health Corporate

PAM Health • Plano (TX)

Hybrid
USD 150,000 - 200,000
Senior Security Engineer
Senior Security Engineer

AgelessRx • Town of Montana (WI)

On-site
USD 140,000 - 170,000
Security Engineer
Security Engineer

Birdirx • Plymouth (MI)

On-site
USD 90,000 - 130,000
Senior Security Engineer
Senior Security Engineer

agelessrx • United States

On-site
USD 150,000 - 190,000
Manager of Information Security
Manager of Information Security

The Intersect Group • United States

On-site
USD 120,000 - 180,000
Security Engineer
Security Engineer

Birdi • Plymouth (MI)

On-site
USD 100,000 - 130,000
Cloud Security Operations Engineer (GCP/AWS) - Remote
Cloud Security Operations Engineer (GCP/AWS) - Remote

Medable • United States

Remote
USD 140,000 - 175,000
Remote from start
Stock options
Annual performance-based bonus
+1