Security and Compliance Manager

🕒 Abril 28

🇺🇸 Estados Unidos – Remoto (EUA)

⏰ Tempo Integral

🟡 Pleno

🟠 Sênior

👮‍♂️ Cibersegurança / Engenheiro de Segurança

🗣️🇺🇸🇬🇧 Inglês obrigatório

Candidatar-se
Encontrar Vagas Remotas Similares

📊 Verifique sua pontuação de currículo para esta vaga

Melhore suas chances de conseguir uma entrevista verificando sua pontuação de currículo antes de se candidatar.

Logo of Rezilient Health

Rezilient Health

51 - 200 funcionários

⚕️ Seguro de Saúde

☁️ SaaS

Healthcare Insurance • SaaS

A Rezilient Health é uma empresa de saúde que oferece um benefício de cuidado primário e multi-especialidades projetado para ser abrangente e rentável para empresas e seus funcionários. Ela fornece serviços de saúde integrados através de suas CloudClinics, cuidado virtual e dispositivos digitais conectados, permitindo que os funcionários acessem cuidados de saúde de alta qualidade de forma eficiente e acessível. A empresa enfatiza o cuidado preventivo e resultados de saúde sustentáveis, ao mesmo tempo que reduz a dependência de serviços de emergência e cuidados de urgência, reduzindo assim os custos gerais de saúde para as empresas. A abordagem inovadora da Rezilient Health inclui consultas no mesmo dia tanto na clínica quanto virtualmente, além de acesso a mensagens 24/7 com fornecedores de saúde.

Descrição

• At Rezilient, we’re redefining primary care by making access to healthcare more convenient, timely, and seamless. Our innovative CloudClinic model combines virtual provider visits with cutting-edge technology to create a personalized digital healthcare experience that puts patients at the center of their care. • - Develop, implement, and maintain the security & compliance program aligned with company goals and regulatory requirements (HIPAA, HITECH, HITRUST, SOC 2, etc.). • - Lead certification and attestation efforts, including SOC 2 audits, HITRUST readiness, and other healthcare/security frameworks. • - Develop and maintain security and compliance policies, standards, and procedures; ensure they are operationalized and enforced across the organization. • - Oversee governance activities including risk assessments, internal audits, compliance reviews, and reporting of KPIs/metrics to leadership. • - Own and manage the third-party/vendor risk management program, including security assessments, ongoing monitoring, and partnership with legal/procurement on contract requirements. • - Oversee incident response from a governance and compliance perspective, ensuring response plans are in place, coordinating cross-functional efforts, and managing regulatory reporting when required. • - Maintain and manage the enterprise risk register, including tracking remediation efforts and escalating risks appropriately. • - Coordinate and oversee security awareness and compliance training programs, ensuring effectiveness and adoption across the organization. • - Provide regular reporting to the CISO and executive team on security posture, compliance status, and risk landscape. • - Monitor the evolving regulatory and industry landscape (healthcare, privacy, SaaS/cloud) and ensure the organization adapts proactively. • - Partner closely with Product and Engineering teams to embed security and compliance into the product lifecycle. • - Lead or support security and compliance reviews of new features, infrastructure, and architecture decisions. • - Ensure adherence to secure development practices, data protection requirements, and regulatory considerations in platform design (especially for PHI/PII handling). • - Act as a key stakeholder in design reviews, threat modeling, and release readiness from a compliance standpoint. • - Work closely with Clinical Operations teams to maintain and evolve the compliance program for care delivery (both virtual and in-clinic). • - Ensure workflows, protocols, and systems used in care delivery meet HIPAA/HITECH and other regulatory requirements. • - Support audits, documentation, and training related to clinical compliance and patient data handling. • - Partner with IT on clinic and corporate security, including device management, endpoint security, access controls, and software governance. • - Ensure consistent enforcement of security policies across physical clinics and distributed environments. • - Support implementation and monitoring of controls related to identity/access management, endpoint protection, and SaaS tools. • - Partner with Growth (Sales) and Client Success teams to support security and compliance needs throughout the customer lifecycle. • - Respond to security questionnaires, RFPs, and due diligence requests from prospective and existing clients. • - Act as a subject matter expert in sales cycles, helping articulate the company’s security posture and build trust with buyers. • - Develop and maintain standardized security materials (e.g., trust center content, policies, certifications, FAQs) to streamline sales and client interactions.

🎯 Requisitos

• - Bachelor’s degree in cybersecurity, IT, risk, or compliance (or equivalent experience) is required; advanced degree a plus. • - 5–10 years of experience in security/compliance in healthcare, digital health, or SaaS/cloud environments is required. • - Strong familiarity with frameworks such as SOC 2, HITRUST, HIPAA/HITECH, ISO 27001/27002, NIST CSF. • - Experience working cross-functionally with engineering, product, IT, and clinical/operational teams. • - Hands-on experience with audits, external assessors, and certification processes. • - Strong knowledge of third-party risk management, incident response, and security governance. • - Excellent communication skills with the ability to translate technical and compliance risks into business impact. • - Relevant certifications (CISSP, CISM, CISA, CRISC) strongly preferred.

🏖️ Benefícios

• This opportunity offers the chance to shape the future of healthcare in a culture where your ideas and contributions have a meaningful impact on the organization's future. You’ll be part of a supportive, collaborative, and diverse team, with competitive compensation and benefits that include generous PTO, paid family leave, comprehensive medical, dental, vision, and life insurance, as well as stock options.

Candidatar-se

Vagas Similares

🕒 Abril 28

CDW

10.000+ funcionários

🏢 Corporativo

☁️ SaaS

🔒 Cibersegurança

Security Engineer I focusing on Identity Access Management at CDW. Supporting IAM solutions and collaborating with Agile teams for secure access governance.

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $106.000 - $151.400 / ano

💰 Post-IPO Equity em 2015-07

⏰ Tempo Integral

🟠 Sênior

👮‍♂️ Cibersegurança / Engenheiro de Segurança

🦅 Patrocina Visto H1B

info

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Abril 28

Conduent

10.000+ funcionários

🤝 B2B

🛍️ Comércio Eletrônico

🏛️ Governo

Network Security Architect responsible for designing and implementing network solutions on Palo Alto and Azure. Collaborating with teams to enhance system architecture and documentation.

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $124.509 - $150.000 / ano

💰 Venture Round em 2009-01

⏰ Tempo Integral

🟡 Pleno

🟠 Sênior

👮‍♂️ Cibersegurança / Engenheiro de Segurança

🦅 Patrocina Visto H1B

info

🗣️🇺🇸🇬🇧 Inglês obrigatório

Azure

Firewalls

🕒 Abril 28

Guild Mortgage

1001 - 5000

💸 Finanças

🏠 Imobiliário

IT Security Coordinator supporting Information Security functions at Guild Mortgage Company. Engaging in project tasks for security awareness, training, and risk management.

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $27 - $38 / hora

⏰ Tempo Integral

🟢 Júnior

🟡 Pleno

👮‍♂️ Cibersegurança / Engenheiro de Segurança

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Abril 28

WVU Online

1001 - 5000

📚 Educação

👥 B2C

🛍️ Comércio Eletrônico

Workday Security Administrator managing security configuration and access controls for WVU. Collaborating across HR, Finance, and IT to ensure system integrity and compliance.

🇺🇸 Estados Unidos – Remoto (EUA)

⏰ Tempo Integral

🟢 Júnior

🟡 Pleno

👮‍♂️ Cibersegurança / Engenheiro de Segurança

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Abril 28

WVU Online

1001 - 5000

📚 Educação

👥 B2C

🛍️ Comércio Eletrônico

Workday Security Administrator optimizing security configuration in Workday for West Virginia University. Collaborating across HR, Finance, and IT to ensure data security and access control.

🇺🇸 Estados Unidos – Remoto (EUA)

⏰ Tempo Integral

🟢 Júnior

🟡 Pleno

👮‍♂️ Cibersegurança / Engenheiro de Segurança

🗣️🇺🇸🇬🇧 Inglês obrigatório