Назад
Company hidden
2 дня назад

Technology Risk Manager (SOX/HIPAA)

191 200 - 286 800$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US/India/Canada
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Technology Risk Manager (SOX/HIPAA): Driving Hinge Health’s technology risk posture across security, infrastructure, and IT with an accent on SOX IT General Controls, HIPAA compliance, vulnerability remediation, and executive risk reporting. Focus on maintaining the technology risk register, coordinating control and vulnerability remediation, and translating complex technical risks into clear decisions for engineering and IT leadership.

Location: Hybrid in San Francisco, United States; in-person attendance is required three days per week for a full 8-hour business day. Remote days follow core business hours. Occasional off-site or on-site events may occur.

Salary: $191.2K–$286.8K annual base salary, plus equity and benefits.

Company

hirify.global uses AI-powered, human-centered technology to deliver personalized digital healthcare for musculoskeletal conditions.

What you will do

  • Own and continuously refine the Technology Risk Register, including cyber, operational, and regulatory risks, ratings, owners, and mitigation plans.
  • Drive remediation across engineering and IT teams, escalating blockers and tracking agreed SLAs.
  • Serve as the primary interface for internal and external auditors on SOX IT General Controls testing, documentation, evidence collection, and remediation.
  • Partner with Application Security, SRE, Infrastructure, Security, IT, Legal/Compliance, and Accounting to prioritize vulnerabilities and maintain effective controls.
  • Design risk and control dashboards and produce executive-ready reports on security posture, compliance status, and remediation velocity.
  • Recommend KPIs and KRIs to measure technology risk, SOX ITGC health, and vulnerability reduction.

Requirements

  • 2+ years of experience in technology risk, IT audit, cybersecurity, or information security, including recent work in SOX-driven or heavily regulated environments.
  • Experience leading complex, cross-functional risk or compliance programs as a senior individual contributor.
  • Deep experience designing, testing, and remediating SOX IT General Controls in cloud-first environments.
  • Strong understanding of access management, change management, computer operations, and related control frameworks.
  • Experience working with PHI or similarly sensitive data environments.
  • Exceptional ability to communicate technical risk, influence senior engineering and IT stakeholders, and document decisions and action plans.

Nice to have

  • CISA, CISSP, or an equivalent certification.
  • Big 4 or similar experience in IT audit, SOX, or technology risk.
  • Experience with broader security frameworks.

Culture & Benefits

  • Hybrid, dog-friendly San Francisco office environment.
  • Medical, dental, and vision coverage for employees and family members.
  • Gender-affirming care, family and fertility planning support, and healthcare travel reimbursements.
  • Traditional or Roth 401(k) options with a 2% company match.
  • Learning and development stipends and discounted company stock through an ESPP.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →