2 дня назад
Technology Risk Manager (SOX/HIPAA)
191 200 - 286 800$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Technology Risk Manager (SOX/HIPAA): Driving Hinge Health’s technology risk posture across security, infrastructure, and IT with an accent on SOX IT General Controls, HIPAA compliance, vulnerability remediation, and executive risk reporting. Focus on maintaining the technology risk register, coordinating control and vulnerability remediation, and translating complex technical risks into clear decisions for engineering and IT leadership.
Location: Hybrid in San Francisco, United States; in-person attendance is required three days per week for a full 8-hour business day. Remote days follow core business hours. Occasional off-site or on-site events may occur.
Salary: $191.2K–$286.8K annual base salary, plus equity and benefits.
Company
uses AI-powered, human-centered technology to deliver personalized digital healthcare for musculoskeletal conditions.
What you will do
- Own and continuously refine the Technology Risk Register, including cyber, operational, and regulatory risks, ratings, owners, and mitigation plans.
- Drive remediation across engineering and IT teams, escalating blockers and tracking agreed SLAs.
- Serve as the primary interface for internal and external auditors on SOX IT General Controls testing, documentation, evidence collection, and remediation.
- Partner with Application Security, SRE, Infrastructure, Security, IT, Legal/Compliance, and Accounting to prioritize vulnerabilities and maintain effective controls.
- Design risk and control dashboards and produce executive-ready reports on security posture, compliance status, and remediation velocity.
- Recommend KPIs and KRIs to measure technology risk, SOX ITGC health, and vulnerability reduction.
Requirements
- 2+ years of experience in technology risk, IT audit, cybersecurity, or information security, including recent work in SOX-driven or heavily regulated environments.
- Experience leading complex, cross-functional risk or compliance programs as a senior individual contributor.
- Deep experience designing, testing, and remediating SOX IT General Controls in cloud-first environments.
- Strong understanding of access management, change management, computer operations, and related control frameworks.
- Experience working with PHI or similarly sensitive data environments.
- Exceptional ability to communicate technical risk, influence senior engineering and IT stakeholders, and document decisions and action plans.
Nice to have
- CISA, CISSP, or an equivalent certification.
- Big 4 or similar experience in IT audit, SOX, or technology risk.
- Experience with broader security frameworks.
Culture & Benefits
- Hybrid, dog-friendly San Francisco office environment.
- Medical, dental, and vision coverage for employees and family members.
- Gender-affirming care, family and fertility planning support, and healthcare travel reimbursements.
- Traditional or Roth 401(k) options with a 2% company match.
- Learning and development stipends and discounted company stock through an ESPP.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
Discord
6 дней назад
Technology Risk Audit Manager (AI)
180 000 - 202 500$
2 часа назад
Sr Vulnerability Management Engineer (Cybersecurity)
143 200 - 196 900$
1 день назад
Security Engineer (AI/ML Security)
200 000 - 400 000$
2 дня назад
Manager, Customer Trust (Cybersecurity)
93 500 - 182 850$
3 дня назад
Cybersecurity Manager (ITSM)
117 400 - 176 000$
2 дня назад
Director, IT & Security
200 000 - 250 000$