Information Security Officer

Posted Aug 28

This is a fully remote position, open to applicants in United States.

📋 Description

• Act as MEDvidi's appointed HIPAA Security Official in accordance with 45 CFR § 164.308(a)(2)

• Take ownership of the security risk analysis and ongoing risk-management process, which includes maintaining the risk register and ensuring remediation items are resolved

• Create, implement, document, and sustain HIPAA administrative safeguards

• Collaborate with the IT department to establish and uphold technical safeguards for ePHI, such as access controls, authentication, audit controls, data integrity, logging, and encryption

• Develop and maintain security policies for MEDvidi's remote workforce, including workstation security, device and media controls, and handling ePHI while working remotely

• Oversee the security incident response procedure, encompassing detection, containment, forensics coordination, documentation, and annual tabletop exercises

• Work alongside the Privacy Officer on breach investigations and the intersection of privacy and security obligations

• Lead security diligence efforts for vendors and Business Associates, which includes conducting security questionnaires, SOC 2/HITRUST reviews, assessing subcontractor risks, and addressing security findings

• Assist in security architecture and tooling decisions related to telehealth platforms, EHR access, endpoint management, logging, and SIEM coverage

• Evaluate the security implications of AI tools and AI-assisted security and compliance processes

• Manage and operate MEDvidi's GRC platform in collaboration with Compliance leadership

• Keep abreast of changes in the HIPAA Security Rule and aid in assessing and implementing new requirements

• Establish a comprehensive, well-documented, and operational security program within the first year

• Organize an annual penetration test and integrate findings into the remediation strategy


⛳️ Requirements

• Minimum of 6 years of experience in information security

• At least 2 years of experience in a healthcare or similarly regulated ePHI/PII environment

• Proven hands-on responsibility for a HIPAA security program or a comparable regulated security program; advisory experience alone is not adequate

• In-depth understanding of the HIPAA Security Rule

• Familiarity with at least one relevant security/control framework, such as NIST Cybersecurity Framework (CSF) 2.0, NIST SP 800-66r2, or HITRUST

• Demonstrated capability to independently manage a security program in a streamlined setting

• Strong skills in risk-based prioritization, practical control implementation, and security documentation

• Preferred: CISSP, HCISPP, CISM, or a similar certification

• Preferred: Experience in securing telehealth platforms or other healthcare technology environments

• Preferred: Cloud security expertise with AWS, Azure, and/or GCP

• Preferred: Experience in leading security incident response efforts

• Preferred: Experience collaborating with fractional or external security resources, penetration testers, and independent security consultants

• Preferred: Knowledge of the evolving requirements of the HIPAA Security Rule


🏝️ Benefits

• Competitive salary and performance-based bonuses

• Comprehensive health, dental, and vision insurance

• Flexible working hours and remote work options

• Opportunities for professional development and training

• Supportive and inclusive work environment

People also viewed

Sony Interactive Entertainment20 hours ago

Senior Security AI Risk Analyst

US flagCalifornia OnlyFull-timeCybersecurity / Security Engineer$167.5k – $251.3k/year
ApplyView job
Squads21 hours ago

Security Engineer

North AmericaFull-timeCybersecurity / Security Engineer$175k – $220k/year
ApplyView job
Neo4j21 hours ago

Senior Director, Product, Security and Privacy

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$260k – $300k/year
ApplyView job
PingWind Inc. (SDVOSB)22 hours ago

Cloud Security Architect – Engineer

US flagAlabama, +1 more stateFull-timeCybersecurity / Security Engineer
ApplyView job
CSCI Consulting22 hours ago

SAP S/4HANA Defense & Security Functional Lead

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Strategic Systems International23 hours ago

AI Security Engineer – AI, Agentic Security

MX flagMexico, +4 more countriesFreelanceCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers