Security and Compliance Manager
Verfasst am 2026-10-10
-
IT/Informationstechnik
Cyber-Sicherheit, Informationssicherheit & Datenschutz, IT Projekt Manager
At Rezilient, we?re redefining primary care by making access to healthcare more convenient, timely, and seamless. Our innovative Cloud Clinic model combines virtual provider visits with cutting-edge technology to create a personalized digital healthcare experience that puts patients at the center of their care. By streamlining care delivery and continuously expanding specialty services, we empower our care team to focus on patient well-being while providing the most comprehensive and accessible care possible.
As Rezilient scales, we are looking to add a Security and Compliance Manager to our growing team. This key member of the team will be responsible for executing and coordinating the company's security governance, risk, and compliance (GRC) functions. This role owns the operationalization of frameworks, certifications (SOC 2, HIPAA/HITECH, HITRUST, etc.), policies, audits, and vendor compliance. This role serves as a critical cross-functional bridge between security, product, engineering, clinical operations, and IT, ensuring that security and compliance are embedded into product development, care delivery, and internal systems from the ground up.
Security Program & Compliance Management
- Develop, implement, and maintain the security & compliance program aligned with company goals and regulatory requirements (HIPAA, HITECH, HITRUST, SOC 2, etc.).
- Lead certification and attestation efforts, including SOC 2 audits, HITRUST readiness, and other healthcare/security frameworks.
- Develop and maintain security and compliance policies, standards, and procedures; ensure they are operationalized and enforced across the organization.
- Oversee governance activities including risk assessments, internal audits, compliance reviews, and reporting of KPIs/metrics to leadership.
- Own and manage the third-party/vendor risk management program, including security assessments, ongoing monitoring, and partnership with legal/procurement on contract requirements.
- Oversee incident response from a governance and compliance perspective, ensuring response plans are in place, coordinating cross-functional efforts, and managing regulatory reporting when required.
- Maintain and manage the enterprise risk register, including tracking remediation efforts and escalating risks appropriately.
- Coordinate and oversee security awareness and compliance training programs, ensuring effectiveness and adoption across the organization.
- Provide regular reporting to the CISO and executive team on security posture, compliance status, and risk landscape.
- Monitor the evolving regulatory and industry landscape (healthcare, privacy, SaaS/cloud) and ensure the organization adapts proactively.
- Partner closely with Product and Engineering teams to embed security and compliance into the product lifecycle.
- Lead or support security and compliance reviews of new features, infrastructure, and architecture decisions.
- Ensure adherence to secure development practices, data protection requirements, and regulatory considerations in platform design (especially for PHI/PII handling).
- Act as a key stakeholder in design reviews, threat modeling, and release readiness from a compliance standpoint.
- Work closely with Clinical Operations teams to maintain and evolve the compliance program for care delivery (both virtual and in-clinic).
- Ensure workflows, protocols, and systems used in care delivery meet HIPAA/HITECH and other regulatory requirements.
- Support audits, documentation, and training related to clinical compliance and patient data handling.
- Partner with IT on clinic and corporate security, including device management, endpoint security, access…
(Wenn dieser Job tatsächlich in Ihrem Zuständigkeitsbereich liegt, verwenden Sie möglicherweise einen Proxy oder VPN, um auf diese Seite zuzugreifen. Um weiterzukommen, sollten Sie Ihre Verbindung zu einem anderen Mobilgerät oder PC wechseln).