Назад
Company hidden
2 часа назад

Manager, Security & Compliance (Healthcare SaaS)

130 000 - 150 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Manager, Security & Compliance (Healthcare SaaS): Leading security, privacy, and healthcare compliance programs for a SaaS platform supporting PACE healthcare organizations with an accent on HIPAA, SOC 2, HITRUST, audit readiness, and risk management. Focus on achieving HITRUST certification, integrating security into cloud and software development processes, leading incident response, and driving remediation across engineering and business teams.

Location: Fully remote, based in the United States

Base salary: $130,000–$150,000 per year

Company

hirify.global provides an end-to-end healthcare SaaS ecosystem for PACE programs, supporting care coordination, risk adjustment, population health, utilization management, compliance, and operational performance for dual-eligible seniors.

What you will do

  • Own and continuously mature security, privacy, and compliance programs covering HIPAA, SOC 2, HITRUST, and applicable privacy requirements.
  • Lead HITRUST certification end to end, including scoping, readiness assessments, evidence collection, assessor coordination, and corrective action plans.
  • Direct internal and external audits, risk assessments, penetration tests, security reviews, remediation, and continuous compliance evidence collection.
  • Partner with Engineering, Product, Platform, SRE, and IT to integrate security, PHI-handling standards, and AI-assisted development guardrails into architecture and the SDLC.
  • Oversee access management, logging and monitoring, encryption, vulnerability management, data retention, vendor risk, and security incident response.
  • Manage external security partners, support customer security reviews, establish security metrics, and lead security awareness and compliance training.

Requirements

  • 7+ years of experience in information security, healthcare compliance, privacy, or risk management, preferably in healthcare SaaS or health technology.
  • Strong knowledge of HIPAA, SOC 2, HITRUST, healthcare privacy requirements, and security control frameworks.
  • End-to-end ownership of at least one HITRUST i1 or r2 certification, including scoping, evidence collection, assessor management, and corrective action plans.
  • Experience with cloud and SaaS security, identity and access management, vulnerability management, encryption, logging, data protection, incident response, vendor risk, and third-party assessments.
  • Experience partnering with Engineering and Product teams to integrate security into technology and development processes.
  • Must be based in the United States; visa sponsorship is not available.

Nice to have

  • Experience with PACE, value-based care, Medicare/Medicaid, or regulated healthcare environments.
  • Experience scaling security and compliance programs in a growing SaaS company.
  • Experience with Azure, Kubernetes/AKS, DevSecOps, and security automation.
  • Experience leading a small security and compliance team or cross-functional security initiatives.
  • Certifications such as CCSFP, CISSP, CISM, or HCISPP.

Culture & Benefits

  • Fully remote work within the United States.
  • Cross-functional collaboration with Engineering, Product, SRE, IT, Legal, and customer-facing teams.
  • Opportunity to build a proactive, measurable, audit-ready security and compliance function.
  • Work focused on protecting sensitive healthcare information and improving outcomes for socially vulnerable and clinically complex populations.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →