
Information Security Manager
Posted Aug 4

Posted Aug 4
This is a fully remote position, open to applicants in California.
• Develop, implement, and manage the information security program for an expanding healthcare organization operating under the PACE model.
• Implement HIPAA-compliant security architecture across Microsoft 365 and Meraki-based WAN.
• Establish, execute, and sustain administrative, technical, and physical security controls.
• Make decisions regarding security design and control selection by balancing risk, regulatory obligations, and operational realities.
• Set up and monitor security tools, logs, and alerts; assess activities and investigate potential incidents.
• Act as the primary escalation point for security issues for internal teams and external partners.
• Lead incident response planning, conduct tabletop exercises, perform post-incident reviews, and track remediation efforts.
• Manage vulnerability assessments based on both internal and external scans and coordinate remediation efforts.
• Maintain the enterprise security risk register, which includes risk scoring, mitigation strategies, and executive-level reporting.
• Assist with business continuity and disaster recovery security requirements in collaboration with IT and Operations.
• Oversee identity and access management processes, including privileged access, role-based access controls, joiner/mover/leaver procedures, and access reviews.
• Ensure data protection measures for PHI, including encryption, logging, and monitoring.
• Draft, update, and enforce security policies, standards, and procedures that align with HIPAA, NIST, and partner requirements.
• Conduct ongoing security oversight and audit processes, including evidence collection and remediation tracking.
• Coordinate both internal and external security audits, assessments, and partner security evaluations.
• Establish and oversee third-party security and risk management, including vendor risk assessments and continuous monitoring.
• Collaborate with IT, Compliance, Legal, Clinical, and Operations teams to integrate security into everyday workflows.
• Bachelor’s degree in Computer Science with a focus on Information Security, or equivalent experience.
• Over 7 years of progressive experience in information security or cybersecurity roles, including direct implementation experience.
• 3 to 5 years of experience in owning or leading security programs, controls, or governance functions.
• Practical experience in implementing information security best practices, particularly in security monitoring, incident response, or vulnerability management.
• Hands-on experience within a healthcare organization.
• Strong knowledge of HIPAA, NIST, and associated regulatory and standards frameworks.
• Experience in cloud-based environments, particularly Microsoft 365.
• Familiarity with networking concepts, operating systems, and cloud environments.
• Excellent analytical and problem-solving abilities with a keen attention to detail.
• Capability to lead by influence and effectively communicate complex issues to both technical and non-technical audiences.
• Must reside in California.
• Travel requirement of up to 2 weeks per quarter for site visits.
• Experience in a startup environment, supporting audits or security assessments, developing technology solutions based on business needs, working remotely, or with technology managed service providers is a plus.
• CISSP, CISM, CISA, or Security+ certifications are preferred.
• Compliance with applicable infection control protocols, PPE requirements, and vaccination mandates associated with the role and work location.
• Authorization to work in the United States is verified through E-Verify.
• Reasonable accommodation for disabilities, medical conditions, or sincerely held religious beliefs, practices, or observances.
• Applicable vaccination and infection control policies.
• PPE requirements and relevant vaccination mandates based on the role/location.
• Commitment to equal opportunity and inclusion.
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.