VP, Cybersecurity

XpertDox

Scottsdale (AZ)

On-site

USD 160,000 - 210,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

XpertDox is seeking a Vice President of Cybersecurity and Compliance to lead the security and compliance program. You will own certification roadmaps, governance, and represent the company to client security teams and CISOs.

Success is measured by certifications maintained, rapid security reviews, and a trusted posture with health systems. This role leads a growing team across hybrid/cloud environments and oversees AI governance in regulated settings.

Qualifications

  • Minimum 10 years in cybersecurity and compliance leadership.
  • Proven SOC 2 Type 2, ISO 27001, HIPAA program experience.
  • Experience representing security to enterprise customers.
  • Strong executive presence to engage with CISOs of large organizations.
  • Deep HIPAA and healthcare regulatory knowledge.

Responsibilities

  • Own the certification portfolio (SOC 2 Type 2, ISO 27001, ISO 22301, HIPAA) and HITRUST roadmap.
  • Lead security reviews and enterprise security conversations with client teams.
  • Own the security posture, policy, governance, and enterprise risk management.
  • Oversee HIPAA program and BAA framework across hybrid/cloud environments.
  • Conduct AI governance aligned to NIST RMF for PHI handling in AI workflows.
  • Report security posture and risks to the CTO, CEO, and board as needed.
  • Build and lead the security and compliance team and elevate company security awareness.

Skills

Executive presence
Security governance
Risk management
Team leadership
Enterprise audits
Executive communication

Education

CISSP / CISM / CISA / HCISPP

Tools

SOC 2 Type 2 program
ISO 27001 program
HIPAA program
HITRUST knowledge

Job description

Compensation: $160,000 to $210,000 base, plus performance bonus and stock options

Who We Are

XpertDox is a healthcare AI company. Our platform, XpertCoding, codes outpatient medical claims autonomously for more than 1,000 providers across all 50 states. We run production systems that handle protected health information every day, so our security and compliance posture is not a back-office function: it is one of the main reasons health systems and provider groups choose us. We hold SOC 2 Type 2, ISO 27001, ISO 22301, and HIPAA attestations, and HITRUST certification is underway.

Role Overview

We are hiring a Vice President of Cybersecurity and Compliance to lead our security and compliance program and to be the person large healthcare organizations trust when they evaluate us. You will own the certification roadmap, set the security governance and risk framework, and represent XpertDox directly to client security teams and their CISOs. Success in this role is measured by trust: certifications maintained and expanded, enterprise security reviews cleared quickly, and health systems naming our security posture as a reason they signed.

Key Responsibilities
  • Certification and compliance: Own the certification portfolio (SOC 2 Type 2, ISO 27001, ISO 22301, HIPAA) and lead HITRUST certification, including the roadmap, assessor relationships, and audit strategy.
  • Client assurance: Act as the senior security voice with enterprise clients and health systems, leading security reviews, questionnaires, and CISO-level conversations so security speeds deals up rather than slowing them down.
  • Security strategy and governance: Own the security posture, the policy and governance framework, and enterprise risk management.
  • HIPAA and regulatory ownership: Own the HIPAA program and the Business Associate Agreement framework across a hybrid cloud, on-premise, and distributed environment.
  • AI governance: Work with our AI and machine learning teams on AI governance aligned to the NIST AI Risk Management Framework, including controls on how PHI moves through AI-assisted workflows.
  • Executive reporting: Report security and compliance posture, key risks, and remediation status to the Chief Technology Officer, and present to the CEO, board, and investors as needed.
  • Team leadership: Build and lead the security and compliance team and raise security awareness across the company.
Required Qualifications
  • Ten or more years in cybersecurity and compliance, including running a security or compliance program.
  • Track record building and maintaining SOC 2 Type 2, ISO 27001, and HIPAA programs and managing third-party audits.
  • Direct experience representing security and compliance to enterprise customers, health systems, and their security leaders.
  • Strong executive presence, with the ability to give a large organization confidence in a smaller vendor.
  • Deep HIPAA and healthcare regulatory knowledge.
  • Experience owning enterprise risk management and security governance frameworks.
  • Experience leading and growing a security or compliance team.
  • At least one of CISSP, CISM, CISA, or HCISPP.
Preferred Qualifications
  • Healthcare, health-tech, or another setting handling PHI at scale.
  • HITRUST CSF experience as a program lead or assessor liaison.
  • A record of helping close enterprise or health system deals on the security and compliance side.
  • AI governance experience in a regulated environment.Experience running a continuous-compliance or GRC program.
Why This Role Matters

Autonomous coding only works if the organizations trusting us with patient data believe our controls hold. This role reports to the CTO, carries real decision authority over our security posture, and has a direct effect on whether large health systems say yes. You will be building the program, not inheriting a finished one.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

VP, Cybersecurity & Compliance — Healthcare Trust Leader
VP, Cybersecurity & Compliance — Healthcare Trust Leader

XpertDox • Scottsdale (AZ)

On-site
USD 160,000 - 210,000
AVP Solutions Architecture
AVP Solutions Architecture

ScionHealth Corporate Support Center • Louisville (KY)

On-site
USD 180,000 - 240,000
AVP Solutions Architecture
AVP Solutions Architecture

ScionHealth • Louisville (KY)

On-site
USD 180,000 - 280,000
Director of Web Development
Director of Web Development

XpertDox • Scottsdale (AZ)

On-site
USD 120,000 - 160,000
IT Security & Compliance Lead (Healthcare)
IT Security & Compliance Lead (Healthcare)

Premium Health Center • New York (NY)

Hybrid
USD 140,000 - 210,000
Paid time off
Medical, dental, and vision plans
Retirement plans
+1
Director, Security
Director, Security

Sequencing Inc. • Northern (KY)

Hybrid
USD 150,000 - 200,000
Compliance Manager
Compliance Manager

UpDoc, Inc. • San Francisco (CA), Northern (KY)

Hybrid
USD 150,000 - 210,000
Senior Security Engineer
Senior Security Engineer

agelessrx • United States

On-site
USD 150,000 - 190,000
Director, Compliance
Director, Compliance

Brado AI • United States

On-site
USD 180,000 - 280,000
Manager of Information Security
Manager of Information Security

The Intersect Group • United States

On-site
USD 120,000 - 180,000