Manager of Security and Compliance

Jobgether SRL

United States

À distance

USD 130 000 - 150 000

Plein temps

Il y a 9 heures
Soyez parmi les premiers à postuler
Générateur de candidature

Une candidature conçue pour ce poste — un CV et une lettre de motivation personnalisés qui correspondent à l’offre.

Passez les filtres ATS

Avantages offerts par ce poste

Base salary: $130,000–$150,000
Fully remote in the United States
Lead HITRUST certification initiatives
Cross-functional exposure across teams
Career growth opportunities

Résumé du poste

Jobgether SRL, listing on behalf of a partner company, seeks a Manager of Security and Compliance based in the United States. This high-impact leadership role lives in a growing healthcare SaaS environment and will own day-to-day security, privacy, risk, and healthcare compliance programs.

You will work with Engineering, Product, SRE, IT, Legal, and customer-facing teams to embed security into development, with HITRUST certification as a major priority and scalable evidence collection, risk

Qualifications

  • 7+ years in information security, healthcare compliance, privacy, risk management, or a closely related discipline.
  • Deep knowledge of HIPAA, SOC 2, HITRUST, healthcare privacy requirements, and security control frameworks.
  • Experience leading HITRUST certification end-to-end from scoping to remediation.
  • Proven track record in audits, risk assessments, remediation, and working with external partners.
  • Cloud/SaaS security expertise, IAM, encryption, incident response, and data protection.

Responsabilités

  • Own and mature security, privacy, and compliance programs covering HIPAA, SOC 2, HITRUST.
  • Lead HITRUST certification end to end, including readiness assessments and evidence collection.
  • Manage audits, risk assessments, penetration tests, and remediation activities.
  • Integrate security into architecture, SDLC, and cross-functional product development.
  • Oversee incident response, investigations, and post-incident actions.
  • Partner with engineering, product, SRE, IT, and legal to embed security controls.
  • Establish metrics for risk, incidents, audits, and remediation progress.

Connaissances

Security leadership
HIPAA compliance
SOC 2 / HITRUST
Audit & risk management
Cloud security
DevSecOps
Vendor risk management
Security incident response
Cross-functional collaboration
Healthcare IT

Outils

Azure
Kubernetes/AKS
Security automation tools

Description du poste

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Manager of Security and Compliance based in United States. This is a high-impact security and compliance leadership role within a growing healthcare SaaS environment. You will own the day-to-day execution and continued maturity of security, privacy, risk, and healthcare compliance programs. The role combines strategic program leadership with hands‑on security, audit, incident response, and risk‑management work. You will work closely with Engineering, Product, SRE, IT, Legal, and customer‑facing teams to embed security into technology and business processes. A major priority will be leading HITRUST certification while strengthening HIPAA, SOC 2, privacy, and broader security controls. You will also help modernize compliance through automation, continuous evidence collection, measurable risk management, and scalable processes. This role is ideal for a security leader who can turn complex regulatory requirements into practical controls and trusted business partnerships.

Accountabilities
  • Own and continuously mature security, privacy, and compliance programs covering HIPAA, SOC 2, HITRUST, and applicable healthcare privacy requirements.
  • Lead HITRUST certification end to end, including scoping, readiness assessments, evidence collection, assessor coordination, remediation, and corrective action plans.
  • Manage internal and external audits, risk assessments, penetration tests, security reviews, evidence collection, and remediation activities.
  • Build a path toward continuous, system-generated compliance rather than relying primarily on point-in-time evidence collection.
  • Manage external security and compliance partners, including advisors, assessors, and penetration‑testing providers, ensuring clear scopes, priorities, accountability, and remediation ownership.
  • Maintain the security and compliance roadmap, ensuring vulnerabilities, risks, audit findings, and control gaps have defined owners and resolution plans.
  • Partner with Engineering, Product, Platform, SRE, and IT to integrate security into architecture, infrastructure, product development, and the software development lifecycle.
  • Establish security and PHI-handling standards and guardrails, including considerations for AI-assisted development.
  • Oversee critical controls including identity and access management, logging and monitoring, encryption, vulnerability management, data retention, data protection, and vendor risk.
  • Lead security incident response, including investigation, stakeholder communication, post-incident reviews, and corrective actions within a unified incident‑management framework.
  • Maintain security policies, procedures, Business Associate Agreements, data-handling requirements, and breach-response plans.
  • Serve as the operational lead for HIPAA Security Rule obligations while supporting the designated HIPAA Security Official and collaborating with the Privacy Officer.
  • Support customer security reviews, due diligence, onboarding, and security and privacy requirements during contract negotiations.
  • Establish security and compliance metrics that provide leadership with clear visibility into risks, incidents, vulnerabilities, remediation progress, and audit readiness.
  • Lead security awareness and compliance training while managing, developing, and mentoring the security and compliance team.
Requirements
  • 7+ years of experience in information security, healthcare compliance, privacy, risk management, or a closely related discipline, preferably within healthcare SaaS or health technology.
  • Strong working knowledge of HIPAA, SOC 2, HITRUST, healthcare privacy requirements, and security control frameworks.
  • Demonstrated experience leading audits, risk assessments, compliance programs, remediation initiatives, and external security or compliance partners.
  • Proven experience serving as the accountable owner for at least one HITRUST certification, either i1 or r2, from scoping through evidence collection, assessor management, and corrective action planning.
  • Practical knowledge of cloud and SaaS security, identity and access management, vulnerability management, encryption, logging, data protection, and incident response.
  • Experience partnering with Engineering and Product teams to integrate security into technology architecture and development processes.
  • Experience with vendor risk management and third‑party security assessments.
  • Strong communication skills, with the ability to translate technical, regulatory, and security requirements for both technical and non‑technical stakeholders.
  • Experience working with healthcare technology, electronic medical records, clinical systems, or sensitive healthcare data environments.
  • Experience in PACE, value‑based care, Medicare/Medicaid, or other regulated healthcare environments is a plus.
  • Experience building or scaling security and compliance programs within a growing SaaS organization is preferred.
  • Familiarity with cloud‑native environments, particularly Azure and Kubernetes/AKS, as well as DevSecOps and security automation, is advantageous.
  • Experience leading a small security/compliance team or cross‑functional security initiatives is a plus.
  • Relevant certifications such as CCSFP, CISSP, CISM, or HCISPP are preferred.
  • Strong organizational skills, sound judgment, ownership, and the ability to operate effectively in a growing and evolving environment are essential.
  • This is a fully remote role for candidates based in the United States and is not eligible for sponsorship.
Benefits
  • Base salary range of $130,000–$150,000, with final compensation determined by experience, skills, and organizational needs.
  • Fully remote position within the United States.
  • Opportunity to lead and mature security, privacy, and compliance programs within a growing healthcare technology organization.
  • High-impact role with significant cross‑functional exposure across Engineering, Product, SRE, IT, Legal, and customer‑facing teams.
  • Opportunity to lead HITRUST certification and build scalable, proactive security and compliance capabilities.
  • Meaningful leadership responsibility, including team development and mentorship.
  • Opportunity to influence security architecture, compliance automation, incident management, and organizational risk strategy.
Obtenez votre examen gratuit et confidentiel de votre CV.

ou faites glisser et déposez votre fichier ici.

Similar jobs

Postes similaires à comparer

Manager of Security and Compliance
Manager of Security and Compliance

US Health Partners, LLC • États-Unis

À distance
USD 130 000 - 150 000
Manager of Security and Compliance
Manager of Security and Compliance

IntusCare • États-Unis

À distance
USD 130 000 - 150 000
Manager of Security and Compliance
Manager of Security and Compliance

Collab Capital • États-Unis

À distance
USD 130 000 - 150 000
Manager of Security and Compliance
Manager of Security and Compliance

intus • États-Unis

Sur place
USD 140 000 - 200 000
IT Security & Compliance Lead (Healthcare)
IT Security & Compliance Lead (Healthcare)

Premium Health Center • New York (NY)

Hybride
USD 120 000 - 160 000
Senior Security Engineer
Senior Security Engineer

TravelCenters of America • États-Unis

À distance
USD 130 000 - 190 000
Director of Cyber Security
Director of Cyber Security

Interactive Resources - iR • États-Unis

Sur place
USD 180 000 - 215 000
Senior Security Engineer
Senior Security Engineer

Healthmark Group • États-Unis

À distance
USD 110 000 - 140 000
Remote Senior Cybersecurity & Compliance Consultant (HIPAA, NIST & SOC 2)
Remote Senior Cybersecurity & Compliance Consultant (HIPAA, NIST & SOC 2)

The Hello Team • New York (NY)

Hybride
USD 120 000 - 150 000
Remote work
Long-term opportunity
Senior Security Engineer
Senior Security Engineer

Healthmark-Group • Dallas (TX)

À distance
USD 110 000 - 140 000