Cyber Security Lead

Mednition

Burlingame (CA)

On-site

USD 140,000 - 230,000

Full time

5 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Mednition is seeking a Cyber Security Manager to lead and mature the information security program for our AI SaaS platform, including KATE Triage and KATE Sepsis integrations. You will own GRC, HIPAA, and SOC 2 Type 2 readiness, while guiding security across GCP, Kubernetes, and MongoDB Atlas architectures.

Collaboration with FDA SaMD and NIST RMF teams is required. You will interface with senior management and development teams to embed security into pipelines, respond to threats, and maintain

Qualifications

  • Bachelor's degree in computer science, information security, or a related field.
  • Professional certifications such as CISSP, CISM, or CEH are preferred.
  • Demonstrated experience leading security programs and teams in a SaaS/Cloud environment.

Responsibilities

  • Lead the information security program across an AI SaaS platform and EHR integrations.
  • Oversee GRC activities, HIPAA compliance, and SOC 2 Type 2 readiness.
  • Manage security across GCP, Kubernetes, and MongoDB Atlas environments.
  • Coordinate external audits and regulatory alignment with FDA SaMD and NIST RMF.
  • Collaborate with stakeholders to implement security controls and incident response.

Skills

Security program management
Governance, risk & compliance
Cloud security (GCP)
Kubernetes security
HIPAA & SOC 2 expertise
Stakeholder communication

Education

Bachelor's degree in CS or related field
CISSP or equivalent certification

Tools

GCP
Kubernetes
MongoDB Atlas
SIEM

Job description

The Cyber Security Manager is responsible for building, maintaining, and continuously improving the Mednition Information Security Program across our AI SaaS platform (including KATE Triage and KATE Sepsis). This role involves managing the Governance, Risk, and Compliance (GRC) program, overseeing HIPAA compliance and SOC2 Type 2 certification audits, supervising Google Cloud Platform (GCP) and MongoDB Atlas security architectures, and ensuring security across EHR integrations (HL7, FHIR). The Cyber Security Manager will also support regulatory alignment with FDA SaMD guidelines, NIST AI Risk Management Framework, and predetermined change control plans.

Key Responsibilities:

Build, maintain, and continuously improve the Mednition Information Security Program, including developing and implementing policies, processes, and procedures to protect the organization's information systems and data.

Manage the GRC program, including the development of policies, processes, and procedures to ensure compliance with regulatory requirements and industry standards.

Oversee the IT Security Program across cloud environments, Kubernetes clusters, and MongoDB Atlas databases, including continuous monitoring, SIEM, security architecture, and vulnerability assessments.

Supervise security monitoring operations, including vulnerability and threat assessments, network access control, incident response, and maintenance activities.

Support briefings and meetings with key stakeholders, providing recommendations to development teams regarding security best practices and requirements.

Ensure compliance with HIPAA, SOC2 Type 2 audits, FDA SaMD cybersecurity requirements, and NIST AI Risk Management Framework standards.

Effectively communicate and collaborate with internal and external key stakeholders, such as senior management, IT teams, customer security teams, vendors, and auditors.

Manage secure data integration architectures for HL7/FHIR EHR data pipelines, ensuring proper handling and protection of Patient Health Information (PHI).

Stay updated with the latest cyber security trends, threats, and technologies, and evaluate their applicability to the organization's security program.

Foster a culture of security awareness and compliance throughout the organization, promoting the importance of information security and privacy.

Collaborate with cross-functional teams to implement security controls, mitigate risks, and address security-related issues and incidents.

Required Skills/Abilities:

Proven experience in managing information security programs and teams.

Strong understanding of governance, risk management, and compliance principles and practices.

In-depth knowledge of cloud cybersecurity operations (GCP, MongoDB Atlas, Cloud Run, Kubernetes), container security, CI/CD pipeline security, and SIEM.

Familiarity with healthcare data privacy and security standards (HIPAA, SOC2 Type 2, FDA SaMD regulations, NIST AI RMF, and HL7/FHIR security protocols).

Excellent communication and collaboration skills, with the ability to effectively engage with stakeholders at all levels.

Strong project management and organizational skills, with the ability to prioritize tasks and manage multiple initiatives.

Experience in working with security audit processes and frameworks.

Commitment to staying up-to-date with industry trends and advancements in the field of cyber security.

Education and Experience:

Bachelor's degree in computer science, information security, or a related field. A master's degree is preferred.

Relevant certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or Certified Ethical Hacker (CEH).

Physical Requirements:

Prolonged periods of sitting at a desk and working on a computer.

Must be able to lift 15 pounds at times.

Other Requirements:

Does not now, or in the future, require sponsorship for employment visa status (e.g. H-1B visa status)

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Security Lead
Cyber Security Lead

Valid8 Financial, Inc. • Burlingame (CA)

On-site
USD 180,000 - 240,000
Cybersecurity Program Lead for AI SaaS Platforms
Cybersecurity Program Lead for AI SaaS Platforms

Valid8 Financial, Inc. • Burlingame (CA)

On-site
USD 180,000 - 240,000
Cyber Security Lead: GRC, Cloud Security & AI RMF
Cyber Security Lead: GRC, Cloud Security & AI RMF

Mednition • Burlingame (CA)

On-site
USD 140,000 - 230,000
Chief Information Security Officer (CISO) | PAM Health Corporate
Chief Information Security Officer (CISO) | PAM Health Corporate

PAM Health • Plano (TX)

Hybrid
USD 150,000 - 200,000
Security Engineer
Security Engineer

Birdirx • Plymouth (MI)

On-site
USD 90,000 - 130,000
Senior Security Engineer
Senior Security Engineer

AgelessRx • Town of Montana (WI)

On-site
USD 140,000 - 170,000
Senior Security Engineer
Senior Security Engineer

agelessrx • United States

On-site
USD 150,000 - 190,000
Security Engineer
Security Engineer

Birdi • Plymouth (MI)

On-site
USD 100,000 - 130,000
Cloud Security Operations Engineer (GCP/AWS) - Remote
Cloud Security Operations Engineer (GCP/AWS) - Remote

Medable • United States

Remote
USD 140,000 - 175,000
Remote from start
Stock options
Annual performance-based bonus
+1
Sr. Product Security Engineer - Cloud Digital Solutions
Sr. Product Security Engineer - Cloud Digital Solutions

Medtronic • Fridley (MN)

On-site
USD 130,000 - 180,000