IT Security & Compliance Lead (Healthcare)

Premium Health Center

New York (NY)

Hybrid

USD 140,000 - 210,000

Full time

9 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Paid time off
Medical, dental, and vision plans
Retirement plans
PSLF

Job summary

Premium Health Center is seeking an IT Security & Compliance Lead to own the organization’s security, risk, and HIPAA compliance across a multi-site ambulatory healthcare environment. The role focuses on governance, controls, and AI risk management while enabling efficient clinical workflows.

The candidate will partner with IT, clinical applications, data, and operations to mature security practices aligned with NIST and industry standards. Remote work up to 20% is available.

Qualifications

  • 5+ years of IT security, compliance, or risk management experience.
  • Healthcare or regulated environment experience preferred (HIPAA)
  • Experience managing security programs, audits, and compliance initiatives
  • Strong understanding of IAM, vendor risk, and security controls

Responsibilities

  • Own and operate the organization’s security program, policies, and controls.
  • Lead HIPAA compliance efforts, audits, and remediation tracking.
  • Manage vendor security reviews, BAAs, and third-party risk.
  • Oversee identity and access management, access reviews, and least-privilege controls.
  • Coordinate security incidents with SOC/EDR partners and define response processes.
  • Establish practical AI governance and guardrails for PHI handling.
  • Provide security awareness training and leadership reporting.

Skills

IT security
Compliance
HIPAA
Vendor risk
Incident response
AI governance
NIST/CIS
Cross-functional

Tools

Microsoft 365 security
SIEM
DLP
Endpoint protection
MFA/CA

Job description

IT Security & Compliance Lead (Healthcare)
Location:

620 Foster Ave, Brooklyn, NY 11230

Hours:

Full Time

Premium Health is looking for outstanding Security & Compliance candidates for our Information Technology department.

Premium Health’s Information Technology (IT) department is based in our Administration office and is responsible for managing and maintaining the entire infrastructure of multiple health practices across Brooklyn. The IT department is a team that is projected to grow as the organization does and is lead by our Chief Digital Information Officer. We are seeking a hands-on IT Security & Compliance Lead to own and operate the organization’s security, risk, and compliance program across a multi-site ambulatory healthcare environment.

This role is responsible for day-to-day execution of security controls, HIPAA compliance, audit readiness, vendor risk management, and AI governance, ensuring systems and data are protected while enabling efficient clinical and operational workflows.

The role serves as the internal owner of security program execution, working closely with IT, clinical applications, data, and operational teams, as well as external partners. The role will also establish and manage practical AI governance, enabling safe and effective use of emerging AI tools across the organization.

This individual will help define and execute a practical security roadmap to continuously mature the organization’s security controls, operational practices, and risk management capabilities, aligned to healthcare regulatory requirements and industry-standard frameworks such as NIST.

Success in this role requires a balance of operational execution, hands‑on security administration, cross‑functional collaboration, and pragmatic risk management while supporting a rapidly evolving healthcare environment.

Time Commitment:
  • 40 hours per week (Monday – Friday)
  • Opportunity for remote work for up to 20% of scheduled hours
Responsibilities:
Security Program Ownership& Execution
  • Own and operate the organization’s security program, ensuring policies, procedures, and controls are consistently implemented
  • Maintain and update security policies, standards, and procedures
  • Ensure alignment with regulatory and organizational requirements
  • Support ongoing maturation of the organization’s security posture and controls framework, including alignment with industry-standard practices such as NIST
  • Stay current on emerging cybersecurity threats, vulnerabilities, technologies, AI-related risks, and evolving industry best practices, proactively identifying opportunities to strengthen the organization’s security posture and risk management capabilities
Security Tooling & Control Administration
  • Administer and support security technologies and operational controls across the environment, including email security, endpoint protection, identity and access management, MFA, conditional access, DLP, and firewall/security platforms
  • Configure, tune, monitor, and maintain security rules, alerts, policies, and protections across Microsoft 365, SaaS, endpoint, and network security platforms in collaboration with internal IT teams and external security partners
  • Support email security administration, including phishing protection, impersonation protection, quarantine management, and coordination of SPF/DKIM/DMARC-related controls
  • Coordinate and manage phishing simulations, user remediation, and security awareness follow‑up activities
  • Support SaaS application governance and review of third‑party application access, permissions, and security risks
  • Partner with outsourced SOC/EDR providers to investigate alerts, validate remediation actions, and continuously improve detection and response capabilities
Compliance & Audit Readiness (HIPAA)
  • Lead HIPAA compliance efforts, including risk assessments and remediation tracking
  • Coordinate internal and external audits, ensuring documentation and evidence are maintained continuously
  • Monitor compliance with security policies and regulatory requirements
  • Ensure controls are functioning and documented (not just defined)
Vendor & Third-Party Risk Management
  • Own vendor security review process
  • Ensure BAAs and security requirements are in place and tracked
  • Maintain vendor inventory and risk classification
Identity & Access Management
  • Oversee user access controls, including onboarding, offboarding, and role-based access controls
  • Lead periodic access reviews across key systems
  • Ensure least‑privilege access and proper audit trails
Security Operations & Incident Coordination
  • Serve as the internal point of contact for security incidents, coordinating response with outsourced SOC/EDR providers
  • Define and maintain incident response processes and escalation paths
  • Track and ensure follow‑up on security alerts and incidents
AI Governance & Emerging Technology Risk
  • Establish and maintain practical AI governance guidelines, including acceptable use of tools such as ChatGPT and Microsoft Copilot
  • Define guardrails for responsible use of AI, including PHI protection and data handling
  • Support evaluation of AI-enabled tools and vendors
  • Partner with IT and operational teams to enable safe adoption
Security Awareness & Training
  • Support security awareness initiatives, including phishing simulations and staff education
  • Provide guidance on secure use of systems, data, and AI tools
  • Partner with IT, Clinical Applications, Data, and Operations teams to ensure security practices align with workflows and business needs
  • Provide regular reporting on security posture, risks, and compliance status to leadership
  • Identify opportunities to improve processes, reduce risk, and strengthen controls
Requirements:

Qualified candidates must have 5 years of experience, be self‑driven and know:

  • 5+ years of experience in IT security, compliance, or risk management
  • Experience in healthcare or regulated environments (HIPAA strongly preferred)
  • Experience managing or supporting security programs, audits, and compliance initiatives
  • Strong understanding of identity and access management, vendor risk, and security controls
  • Ability to work cross‑functionally and translate security requirements into practical processes
  • Hands‑on experience administering or supporting security technologies and operational controls, including areas such as identity and access management, endpoint protection, email security, MFA/conditional access, DLP, or SaaS security administration
Preferred:
  • Experience working with SaaS‑heavy environments and third‑party vendors
  • Experience working with Microsoft 365 security technologies, endpoint protection, email security, SIEM, DLP, conditional access, or related security platforms
  • Experience developing or supporting security policies and governance frameworks
  • Familiarity with NIST, CIS Controls, or similar frameworks
  • Exposure to AI tools and interest in emerging technology governance
Compensation:

Commensurate with Experience

  • Paid time Off, Medical, Dental and Vision plans, Retirement plans
  • Public Service Loan Forgiveness (PSLF)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

Birdirx • Plymouth (MI)

Remote
USD 90,000 - 130,000
Senior Security Engineer
Senior Security Engineer

HealthDrive Corporation • Framingham (MA)

Hybrid
USD 85,000 - 115,000
Remote Senior Cybersecurity & Compliance Consultant (HIPAA, NIST & SOC 2)
Remote Senior Cybersecurity & Compliance Consultant (HIPAA, NIST & SOC 2)

Thehelloteam • New York (NY)

Hybrid
USD 100,000 - 130,000
Long-term growth opportunities
Flexible remote work environment
Security Engineer
Security Engineer

Birdi • Plymouth (MI)

Remote
USD 100,000 - 130,000
Senior Security Engineer
Senior Security Engineer

AgelessRx • Town of Montana (WI)

On-site
USD 140,000 - 170,000
AVP Solutions Architecture
AVP Solutions Architecture

ScionHealth Corporate Support Center • Louisville (KY)

On-site
USD 180,000 - 240,000
Dir, Security Operations
Dir, Security Operations

PDS Health • Irvine (CA)

On-site
USD 169,000 - 227,000
Medical, dental, and vision insurance
401K
Paid time off
+2
AVP Solutions Architecture
AVP Solutions Architecture

ScionHealth • Louisville (KY)

On-site
USD 180,000 - 280,000
Healthcare IT Security & Compliance Lead (HIPAA & AI)
Healthcare IT Security & Compliance Lead (HIPAA & AI)

Premium Health Center • New York (NY)

Hybrid
USD 140,000 - 210,000
Paid time off
Medical, dental, and vision plans
Retirement plans
+1
Senior Security Engineer
Senior Security Engineer

agelessrx • United States

On-site
USD 150,000 - 190,000