Remote job
Manager of Security and Compliance
Job details
About this role
Role overview
This role leads the day-to-day execution and continued maturation of a security, privacy, and compliance program within a healthcare SaaS organization serving Programs of All-Inclusive Care for the Elderly (PACE). The position owns key compliance programs, security governance, risk management, audit readiness, and incident response while partnering closely with Engineering, Product, SRE, IT, Legal, and customer-facing teams.
Responsibilities
- Own and continuously mature security and compliance programs across HIPAA, SOC 2, HITRUST, and applicable privacy requirements. - Lead HITRUST certification end-to-end, including scoping, evidence collection, assessor coordination, and corrective action plans. - Manage internal and external audits, risk assessments, penetration tests, and remediation efforts. - Partner with Engineering, Product, SRE, and IT to embed security into architecture, infrastructure, and the SDLC. - Oversee critical controls including access management, logging, encryption, vulnerability management, and vendor risk. - Lead incident response and maintain security policies, BAAs, data handling standards, and breach response plans.
Requirements
- 7+ years in information security, healthcare compliance, privacy, or risk management, preferably in healthcare SaaS. - Strong knowledge of HIPAA, SOC 2, HITRUST, and security control frameworks. - Proven experience leading at least one HITRUST (i1 or r2) certification end-to-end as the accountable owner. - Practical understanding of cloud/SaaS security, IAM, encryption, logging, data protection, and incident response. - Experience partnering with Engineering and Product to embed security into development processes. - Strong communication skills with the ability to translate requirements for technical and non-technical audiences.
Nice to have
- Background in PACE, value-based care, Medicare/Medicaid, or other regulated healthcare environments. - Experience scaling security and compliance programs in a growing SaaS company. - Cloud-native security experience, ideally with Azure and Kubernetes/AKS, including DevSecOps and automation. - Relevant certifications such as CCSFP, CISSP, CISM, or HCISPP.
Benefits and work setup
Fully remote role based in the United States. Base salary range of $130,000-$150,000, with final compensation determined by experience, skills, and organizational needs. This position is not eligible for sponsorship.