
Information Security Officer
Posted 23 hours ago

Posted 23 hours ago
This is a fully remote position, open to applicants in Alabama, +44 more states.
• Supervise the design, implementation, and ongoing enhancement of the organization’s information security strategies, policies, and architecture.
• Ensure adherence to HIPAA, HITRUST, and SOC 2 compliance standards.
• Direct the creation and execution of the security incident response plan.
• Manage security incidents and perform post-mortem analyses to avert future occurrences.
• Conduct and lead internal security audits and risk evaluations.
• Address customer security audits and Requests for Proposals (RFPs).
• Develop and deliver comprehensive security awareness and training programs for all employees.
• Oversee the third-party vendor security assessment program.
• Collaborate with IT and engineering teams to implement security controls throughout the development lifecycle and cloud infrastructure.
• Provide reports on the status and effectiveness of the information security program to senior leadership and key stakeholders.
• A minimum of 8 years of progressive experience in an information security role, emphasizing governance, risk, and compliance.
• In-depth experience with HIPAA, HITRUST, and SOC 2 is essential.
• Proven track record in developing and managing an incident response program.
• Strong knowledge of network security, application security, and cloud security principles, ideally within an AWS or Azure environment.
• Experience in conducting thorough risk assessments and managing a vulnerability management program.
• Exceptional communication, leadership, and interpersonal abilities, with a talent for translating complex security concepts for both technical and non-technical audiences.
• Post-secondary education in Information Security, Computer Science, or equivalent relevant work experience.
• Possession of professional security certifications such as CISSP, CISM, CISA, or CRISC.
• Experience in a SaaS or healthcare technology company is preferred.
• Familiarity with data privacy regulations beyond HIPAA, such as CCPA/CPRA.
• 3 weeks of vacation and 5 personal days.
• Comprehensive medical, dental, and vision benefits starting on your first day.
• Employee stock ownership and RRSP/401k matching programs.
• Lifestyle rewards.
• Flexible work arrangements and opportunities for community involvement.
• Casual and supportive work environment.
• Significant opportunities for learning.
• Award-winning culture.
Zscaler
Viatris
ActBlue
AlphaSense
Get handpicked remote jobs straight to your inbox weekly.