Information Security Manager

🔥 57 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Habitat Health

Habitat Health

1 - 10 employees

Founded 2023

🏥 Healthcare

⚕️ Healthcare Insurance

🧘 Wellness

Healthcare • Healthcare Insurance • Wellness

Habitat Health is a healthcare organization focused on empowering older adults to live independently in their homes and communities. Through the Program of All-Inclusive Care for the Elderly (PACE), Habitat Health provides comprehensive health insurance coverage and medical and social care services. Their services include transportation, personal care, 24/7 care access, physical therapy, nutrition support, pharmacy and prescriptions, medical care, and social services. Operating in partnership with notable healthcare providers such as Kaiser Permanente, Habitat Health is committed to creating a supportive and inclusive environment for both participants and staff, ensuring the provision of personalized, coordinated care. Founded in 2023, the company aims to enhance the lives of older adults covered by Medicare or Medicaid.

📋 Description

• Design, implement, and operate the information security program for a growing healthcare organization operating under the PACE model • Deploy HIPAA-aligned security architecture across Microsoft 365 and Meraki-based WAN • Define, implement, and maintain administrative, technical, and physical security controls • Make security design and control-selection decisions balancing risk, regulatory requirements, and operational realities • Configure and monitor security tools, logs, and alerts; analyze activity and investigate potential incidents • Serve as the primary security escalation point for internal teams and external partners • Lead incident response planning, tabletop exercises, post-incident reviews, and remediation tracking • Perform vulnerability management based on internal and external scans and coordinate remediation • Maintain the enterprise security risk register, including risk scoring, mitigation plans, and executive-level reporting • Support business continuity and disaster recovery security requirements with IT and Operations • Lead identity and access management procedures, including privileged access, role-based access controls, joiner/mover/leaver processes, and access reviews • Ensure data protection controls for PHI, including encryption, logging, and monitoring • Draft, maintain, and enforce security policies, standards, and procedures aligned to HIPAA, NIST, and partner requirements • Operate recurring security oversight and audit processes, including evidence collection and remediation tracking • Coordinate internal and external security audits, assessments, and partner security reviews • Establish and manage third-party security and risk management, including vendor risk assessments and ongoing monitoring • Partner with IT, Compliance, Legal, Clinical, and Operations teams to embed security into daily workflows

🎯 Requirements

• Bachelor’s degree in Computer Science with an emphasis on Information Security, or equivalent experience • 7+ years of progressive experience in information security or cybersecurity roles, including hands-on implementation • 3–5 years of experience owning or leading security programs, controls, or governance functions • Hands-on experience implementing information security best practices, with experience in security monitoring, incident response, or vulnerability management • Practical experience in a Health Care organization • Expertise in HIPAA, NIST, and related regulatory and standards frameworks • Experience in cloud-based environments, specifically Microsoft 365 • Experience with networking concepts, operating systems, and cloud environments • Strong analytical and problem-solving skills with attention to detail • Ability to lead through influence and communicate complex issues clearly to technical and non-technical audiences • Must live in California • Travel requirement up to 2 weeks per quarter to visit sites • Experience in a startup organization, supporting audits or security assessments, creating technology solutions based on business requirements, working remotely, or with technology managed service providers are nice to haves • CISSP, CISM, CISA, or Security+ certifications are preferred • Compliance with applicable infection control protocols, PPE requirements, and vaccination requirements associated with the role and work location • Authorization to work in the United States is verified through E-Verify

🏖️ Benefits

• Reasonable accommodation for disability, medical condition, or sincerely held religious belief, practice, or observance • Applicable vaccination and infection control policies • PPE requirements and applicable role/location-related vaccination requirements • Equal opportunity and inclusion commitment

Apply Now

Similar Jobs

🔥 57 minutes ago

IonQ

201 - 500

🤖 Artificial Intelligence

🔌 API

🏢 Enterprise

IonQ, a quantum computing and security platform, seeks a senior sales executive for SLED cybersecurity accounts. Driving quantum-safe encryption opportunities through consultative selling, executive relationships, and full-cycle deal execution.

🔥 1 hour ago

Array

51 - 200

💳 Fintech

🤝 B2B

Offensive Security Engineer exploiting Array’s fintech products, APIs, and infrastructure. Finding business-impact vulnerabilities, validating remediations, and using AI to expand security testing coverage.

🔥 1 hour ago

AlphaSense

1001 - 5000

💼 Consulting

🏥 Healthcare

📣 Marketing

Staff Product Security Engineer securing AlphaSense’s AI-powered market intelligence platform. Designing security architecture and controls across AI/ML, cloud-native systems, containers, APIs, and software supply chains.

🔥 1 hour ago

Oddball

51 - 200

💼 Consulting

📦 Logistics

🎖️ Defense

Security Engineer embedding security into Oddball’s federal VA software delivery. Supporting ATO/RMF compliance, vulnerability management, monitoring, and DevSecOps for Veterans’ systems.