
201 - 500 employees
🏥 Healthcare
⚕️ Healthcare Insurance
☁️ SaaS
💰 $100M Series C on 2021-03
Healthcare • Healthcare Insurance • SaaS
Rightway is a healthcare company focused on providing care navigation and pharmacy benefits management solutions. It specializes in helping employers and health systems lower healthcare costs and improve outcomes through personalized, proactive clinical support and transparent pharmacy benefits management. Rightway offers a human-first approach, providing real-time, one-on-one support to members to help them make better healthcare decisions and navigate the complexities of healthcare systems. The company aims to reduce healthcare costs while improving employee satisfaction with healthcare services.
🔥 4 minutes ago
🐊 Florida – Remote
💵 $144k - $175k / year
⏰ Full Time
🟡 Mid-level
🟠 Senior
👮♂️ Cybersecurity / Security Engineer
🦅 H1B Visa Sponsor
👻 Ghost score 3%
Improve your chances of getting an interview by checking your resume score before you apply.

201 - 500 employees
🏥 Healthcare
⚕️ Healthcare Insurance
☁️ SaaS
💰 $100M Series C on 2021-03
Healthcare • Healthcare Insurance • SaaS
Rightway is a healthcare company focused on providing care navigation and pharmacy benefits management solutions. It specializes in helping employers and health systems lower healthcare costs and improve outcomes through personalized, proactive clinical support and transparent pharmacy benefits management. Rightway offers a human-first approach, providing real-time, one-on-one support to members to help them make better healthcare decisions and navigate the complexities of healthcare systems. The company aims to reduce healthcare costs while improving employee satisfaction with healthcare services.
• Lead and mentor a small GRC team, setting priorities, reviewing work, and growing the function • Own and evolve the unified control library, maintaining mappings across SOC 2, SOC 1, and the latest HITRUST version • Lead the audit program for control requirements and evidence production in partnership with Engineering, IT, People, and Finance • Partner with Legal on data privacy programs, including HIPAA/HITECH, BAAs, privacy and protection impact assessments, incident/breach analysis, and data handling requirements • Own and mature the AI governance program modeled after ISO/IEC 42001, including the AI risk register, Statement of Applicability, and AI risk assessments • Respond to customer and partner AI governance questionnaires and maintain alignment with emerging requirements such as Colorado ADMTA • Review and negotiate security, privacy, data protection, incident notification, audit rights, AI, and related language in customer and vendor agreements • Monitor, measure, and report control effectiveness in Drata, maintaining continuous control monitoring and evidence collection • Improve policies and procedures to increase operational efficiency, control maturity, security, and compliance • Lead business continuity planning and testing, focusing on a BIA-informed program • Revamp and execute the Third Party Risk Management program • Own the security risk management program, including enterprise risk preparation, discussion, tracking, remediation, and annual risk assessments • Develop and implement security and compliance training programs • Own and maintain the customer assurance program, including security questionnaires, RFP responses, trust center content, and supporting tooling
• 5-10 years of related work experience • Maintains a certification relevant to the role (e.g, CISSP, CISA, CISM) • Personally led SOC2 with HITRUST CSF certification in a high growth environment and understands how to mature controls consistent with organizational maturity and capacity • Familiarity with AI governance frameworks (e.g., ISO/IEC 42001) and the risk considerations of AI systems that process sensitive data • Experience leading or mentoring GRC analysts • Deep understanding of risk assessment methodology, HIPAA, and HITECH, including the practical distinction between covered entity and business associate obligations • Comfortable negotiating and redlining BAAs and conducting four-factor breach risk assessments alongside Privacy and legal • Intermediate to advanced understanding of the Software Development Life Cycle and IT and security tooling (Jamf, CrowdStrike, Arctic Wolf, Wiz, Serval, Knowbe4, Drata, AWS, Okta, JIRA, GIT/GITHUB) as it relates to controls • Ability to perform qualitative and quantitative risk assessment • Experience with joint SOC 2/HITRUST attestations (extra credit) • A blend of deep, technical and compliance knowledge and experience (extra credit)
• Bonus • Equity • Equal Opportunity Employer with an inclusive culture where differences are celebrated
Apply Now🔥 2 hours ago
Cybersecurity analyst monitoring government agency networks through SIEM threat detection and incident response. Supporting Defense Logistics Agency cybersecurity operations and Defense-in-Depth controls.
🔥 3 hours ago
Cybersecurity specialist overseeing RMF compliance, ATO packages, STIG compliance, and Azure Government security. Supporting VSolvit’s cybersecurity and cloud solutions for Department of Navy systems.
🇺🇸 United States – Remote
💵 $155k - $170k / year
⏰ Full Time
🟢 Junior
🟡 Mid-level
👮♂️ Cybersecurity / Security Engineer
🦅 H1B Visa Sponsor
🔥 11 hours ago
Software Engineer securing Ruby on Rails and React applications through penetration-test remediation. Building secure features across Rails, React, AWS, Fargate, and real-time systems.
🔥 14 hours ago
Senior Security and Compliance Specialist securing Veterans Affairs technology programs. Applying NIST, FISMA, and compliance expertise to support federal digital services and ATO activities.
🇺🇸 United States – Remote
💵 $150k - $170k / year
⏰ Full Time
🟠 Senior
👮♂️ Cybersecurity / Security Engineer
🔥 16 hours ago
Senior Security Engineer researching vulnerabilities in Tanium’s autonomous IT software and cloud services. Building AI-assisted security workflows, fuzzing tools, and remediation guidance.