Security Program Manager office
Listed on 2026-07-23
-
Security
Information Security & Data Protection, Cybersecurity
Location: New York
About the role
As a Security Program Manager at Forus, you will own the programs that let customers trust us with their most sensitive data. We operate on protected health information to automate healthcare, and our providers, payers, and life sciences partners hold us to a high bar.
You will own our compliance programs end to end – SOC 2, HIPAA, and HITRUST – and build the customer trust function that ensures security remains a core competency will run vendor and third‑party risk assessments, set up compliance automation, and partner closely with our engineering team to implement the technical controls that map to each framework.
This demanding role comes with a high level of autonomy and responsibility. You will be expected to act like an owner and commit yourself to Forus’ success.
All full‑time roles are in person in New York.
If you join, you will- Own our compliance programs end to end (SOC 2 Type II, HIPAA, and HITRUST) from readiness through audit and continuous monitoring.
- Build and run the customer trust function (security questionnaires, RFPs, due diligence, and our trust center) so security accelerates deals rather than blocks them.
- Stand up and administer compliance automation, turning evidence collection and control monitoring into a continuous, low‑toil system.
- Author security policies, run security‑awareness training, and drive access reviews and audit readiness across the company.
- Partner with engineering and legal to translate framework and customer requirements into concrete controls, and coordinate external auditors and penetration‑testing firms.
- Own the risk register and give leadership clear, honest visibility into our security and compliance posture.
- Typically 4–7 years in GRC, security compliance, or security program management, with a track record of running audits end to end.
- Hands‑on experience with SOC 2 and HIPAA; HITRUST experience is a strong plus, as is a track record of standing up a new framework from scratch.
- Experience in a regulated, high‑growth environment – ideally healthcare or another domain with serious data‑handling obligations.
- Fluency with compliance automation tooling and enough technical literacy to work credibly with engineers on cloud, identity, and logging controls.
- Experience owning customer‑facing security with enterprise buyers: questionnaires, trust centers, and due diligence.
- Strong written and verbal communication that allows you to be an effective participant in both internal debates and external relationships.
- A track record of moving quickly, finding shortcuts, and going to unreasonable lengths to deliver on goals.
- High NPS with your former teammates.
- Fully covered medical, vision, and dental insurance.
- Memberships for One Medical, Talkspace, Teladoc, and Kindbody.
- Unlimited paid time off (PTO) and 16 weeks of parental leave.
- 401K plan setup, FSA option, commuter benefits, and Dash Pass.
- Lunch at the office every day and dinner at the office after 6:30 pm.
Forus is an equal‑opportunity employer and does not discriminate on the basis of race, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition, or any other basis protected by law.
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).