×
Register Here to Apply for Jobs or Post Jobs. X

VP, Cybersecurity

Job in Scottsdale, Maricopa County, Arizona, 85261, USA
Listing for: XpertDox
Full Time position
Listed on 2026-09-09
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, IT Consultant
Salary/Wage Range or Industry Benchmark: 160000 - 210000 USD Yearly USD 160000.00 210000.00 YEAR
Job Description & How to Apply Below

Compensation: $160,000 to $210,000 base, plus performance bonus and stock options

Who We Are

Xpert Dox is a healthcare AI company. Our platform, Xpert Coding, codes outpatient medical claims autonomously for more than 1,000 providers across all 50 states. We run production systems that handle protected health information every day, so our security and compliance posture is not a back-office function: it is one of the main reasons health systems and provider groups choose us.

We hold SOC 2 Type 2, ISO 27001, ISO 22301, and HIPAA attestations, and HITRUST certification is underway.

Role Overview

We are hiring a Vice President of Cybersecurity and Compliance to lead our security and compliance program and to be the person large healthcare organizations trust when they evaluate us. You will own the certification roadmap, set the security governance and risk framework, and represent Xpert Dox directly to client security teams and their CISOs. Success in this role is measured by trust: certifications maintained and expanded, enterprise security reviews cleared quickly, and health systems naming our security posture as a reason they signed.

Key Responsibilities
  • Certification and compliance:
    Own the certification portfolio (SOC 2 Type 2, ISO 27001, ISO 22301, HIPAA) and lead HITRUST certification, including the roadmap, assessor relationships, and audit strategy.
  • Client assurance:
    Act as the senior security voice with enterprise clients and health systems, leading security reviews, questionnaires, and CISO-level conversations so security speeds deals up rather than slowing them down.
  • Security strategy and governance:
    Own the security posture, the policy and governance framework, and enterprise risk management.
  • HIPAA and regulatory ownership:
    Own the HIPAA program and the Business Associate Agreement framework across a hybrid cloud, on-premise, and distributed environment.
  • AI governance:
    Work with our AI and machine learning teams on AI governance aligned to the NIST AI Risk Management Framework, including controls on how PHI moves through AI-assisted workflows.
  • Executive reporting:
    Report security and compliance posture, key risks, and remediation status to the Chief Technology Officer, and present to the CEO, board, and investors as needed.
  • Team leadership:
    Build and lead the security and compliance team and raise security awareness across the company.
Required Qualifications
  • Ten or more years in cybersecurity and compliance, including running a security or compliance program.
  • Track record building and maintaining SOC 2 Type 2, ISO 27001, and HIPAA programs and managing third-party audits.
  • Direct experience representing security and compliance to enterprise customers, health systems, and their security leaders.
  • Strong executive presence, with the ability to give a large organization confidence in a smaller vendor.
  • Deep HIPAA and healthcare regulatory knowledge.
  • Experience owning enterprise risk management and security governance frameworks.
  • Experience leading and growing a security or compliance team.
  • At least one of CISSP, CISM, CISA, or HCISPP.
Preferred Qualifications
  • Healthcare, health-tech, or another setting handling PHI at scale.
  • HITRUST CSF experience as a program lead or assessor liaison.
  • A record of helping close enterprise or health system deals on the security and compliance side.
  • AI governance experience in a regulated environment.

    Experience running a continuous-compliance or GRC program.
Why This Role Matters

Autonomous coding only works if the organizations trusting us with patient data believe our controls hold. This role reports to the CTO, carries real decision authority over our security posture, and has a direct effect on whether large health systems say yes. You will be building the program, not inheriting a finished one.

#J-18808-Ljbffr
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary