Manager of Security and Compliance

intus

United States

On-site

USD 140,000 - 200,000

Full time

4 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

IntusCare is seeking a Manager, Security & Compliance to lead the day-to-day execution and ongoing maturity of our security, privacy, and healthcare compliance program. This role will own key compliance programs, security governance, risk management, audit readiness, and incident response while partnering with Engineering, Product, SRE, IT, Legal, and customer-facing teams.

The right candidate translates regulatory and security requirements into practical controls, processes, and measurable

Qualifications

  • Seven-plus years in information security, healthcare compliance, privacy, or risk management.
  • Proven track record delivering audits, risk assessments, and remediation under healthcare regimes.
  • Experience with HITRUST certification and working with external assessors.

Responsibilities

  • Own and mature security and compliance programs (HIPAA, SOC 2, HITRUST).
  • Lead HITRUST certification end-to-end: scoping, evidence, assessor coordination, remediation.
  • Manage audits, risk assessments, security reviews, pen tests, and remediation actions.

Skills

HIPAA compliance
SOC 2
HITRUST
Audit readiness
Risk management
Incident response
Security governance
Cloud security

Job description

About IntusCare:

IntusCare is the only end-to-end ecosystem built specifically to help Programs of All-Inclusive Care for the Elderly (PACE) programs deliver exceptional care, strengthen financial performance, and stay compliant. IntusCare replaces outdated technology and manual workarounds with purpose-built solutions for care coordination, risk adjustment, population health, and utilization management. We empower teams to take control of their operations and improve outcomes for dual-eligible seniors- some of the most socially vulnerable and clinically complex individuals in the US healthcare system.

Role Overview:

Intus Care is seeking a Manager, Security & Compliance to lead the day-to-day execution and continued maturity of our security, privacy, and healthcare compliance program. This individual will own key compliance programs, security governance, risk management, audit readiness, and incident response while partnering closely with Engineering, Product, SRE, IT, Legal, and customer-facing teams. We are looking for someone who combines strong healthcare compliance knowledge with practical security experience and is comfortable being hands-on in a growing healthcare SaaS organization. The right candidate can translate regulatory and security requirements into practical controls, processes, and measurable outcomes.

Key Responsibilities:
  • Own and continuously improve Intus Care's security and compliance programs across HIPAA, SOC 2, HITRUST, and applicable privacy requirements.
  • Lead Intus Care's HITRUST certification end to end, including scoping, readiness assessment, evidence collection, assessor coordination, and corrective action plans.
  • Lead internal and external audits, risk assessments, security reviews, penetration tests, evidence collection, and remediation efforts, moving evidence from point-in-time collection toward continuous, system-generated compliance.
  • Manage Intus Care's external security and compliance partners, including the advisory firm supporting audit preparation, HITRUST assessors, and penetration testers. Direct their scope and priorities, hold them accountable to deliverables, ensure their findings translate into owned remediation, and keep advisory and assessment roles independent.
  • Maintain the security and compliance roadmap, ensuring risks, vulnerabilities, audit findings, and control gaps have clear owners and resolution plans.
  • Partner with Engineering, Product, the Platform team, SRE, and IT to integrate security into architecture, infrastructure, product development, and the SDLC, including security and PHI-handling standards and guardrails for AI-assisted development.
  • Oversee critical controls including access management, logging and monitoring, encryption, vulnerability management, data retention, and vendor risk.
  • Lead security incident responses, including investigation, communication, post-incident reviews, and corrective actions, as part of Intus Care's unified incident management process across SRE, Security, and IT.
  • Maintain security policies, procedures, Business Associate Agreements (BAAs), data handling requirements, and breach response plans.
  • Serve as the day-to-day lead for HIPAA Security Rule obligations, supporting Intus Care's designated HIPAA Security Official and partnering with the Privacy Officer on HIPAA and HITRUST attestations.
  • Support customer security reviews, due diligence, onboarding, and security/privacy requirements during contract negotiations.
  • Establish security and compliance metrics and provide leadership with visibility into risks, incidents, vulnerabilities, remediation progress, and audit readiness.
  • Lead security awareness and compliance training, and manage, develop, and mentor the security and compliance team.
Requirements
  • 7+ years of experience in information security, healthcare compliance, privacy, or risk management, preferably within healthcare SaaS or health technology.
  • Strong knowledge of HIPAA, SOC 2, HITRUST, healthcare privacy requirements, and security control frameworks.
  • Proven experience leading audits, risk assessments, compliance programs, and remediation activities, including directing external advisors and assessors.
  • Proven experience leading at least one HITRUST certification (i1 or r2) end to end as the accountable owner, including scoping, evidence collection, assessor management, and corrective action plans.
  • Practical understanding of cloud/SaaS security, identity and access management, vulnerability management, encryption, logging, data protection, and incident response.
  • Experience partnering with Engineering and Product teams to incorporate security into technology and development processes.
  • Experience with vendor risk management and third-party security assessments.
  • Strong communication skills with the ability to translate security and regulatory requirements for technical and non-technical audiences.
  • Experience working with healthcare technology, EMRs, clinical systems, or healthcare data e
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Manager of Security and Compliance
Manager of Security and Compliance

Collab Capital • United States

Remote
USD 130,000 - 150,000
Manager of Security and Compliance
Manager of Security and Compliance

IntusCare • United States

Remote
USD 130,000 - 150,000
Manager, Security & Compliance (Fully Remote)
Manager, Security & Compliance (Fully Remote)

IntusCare • United States

Remote
USD 150,000 - 230,000
Security & Compliance Lead - HIPAA/HITRUST SaaS
Security & Compliance Lead - HIPAA/HITRUST SaaS

intus • United States

On-site
USD 140,000 - 200,000
Remote Security & Compliance Leader (HIPAA/HITRUST)
Remote Security & Compliance Leader (HIPAA/HITRUST)

Collab Capital • United States

Remote
USD 130,000 - 150,000
Security & Compliance Leader: HITRUST, HIPAA & SOC 2
Security & Compliance Leader: HITRUST, HIPAA & SOC 2

IntusCare • United States

Remote
USD 150,000 - 230,000
Security & Compliance Lead — HIPAA/HITRUST (Remote)
Security & Compliance Lead — HIPAA/HITRUST (Remote)

IntusCare • United States

Remote
USD 130,000 - 150,000
IT Security & Compliance Lead (Healthcare)
IT Security & Compliance Lead (Healthcare)

Premium Health Center • New York (NY)

Hybrid
USD 120,000 - 160,000
Senior Security Engineer
Senior Security Engineer

AgelessRx • Town of Montana (WI)

On-site
USD 140,000 - 170,000
Enterprise Cybersecurity Architect
Enterprise Cybersecurity Architect

Cybersecurity Jobs • Plano (TX)

Remote
USD 140,000 - 180,000