
Information Security Officer
Posted Aug 28

Posted Aug 28
This is a fully remote position, open to applicants in United States.
• Act as MEDvidi's appointed HIPAA Security Official in accordance with 45 CFR § 164.308(a)(2)
• Take ownership of the security risk analysis and ongoing risk-management process, which includes maintaining the risk register and ensuring remediation items are resolved
• Create, implement, document, and sustain HIPAA administrative safeguards
• Collaborate with the IT department to establish and uphold technical safeguards for ePHI, such as access controls, authentication, audit controls, data integrity, logging, and encryption
• Develop and maintain security policies for MEDvidi's remote workforce, including workstation security, device and media controls, and handling ePHI while working remotely
• Oversee the security incident response procedure, encompassing detection, containment, forensics coordination, documentation, and annual tabletop exercises
• Work alongside the Privacy Officer on breach investigations and the intersection of privacy and security obligations
• Lead security diligence efforts for vendors and Business Associates, which includes conducting security questionnaires, SOC 2/HITRUST reviews, assessing subcontractor risks, and addressing security findings
• Assist in security architecture and tooling decisions related to telehealth platforms, EHR access, endpoint management, logging, and SIEM coverage
• Evaluate the security implications of AI tools and AI-assisted security and compliance processes
• Manage and operate MEDvidi's GRC platform in collaboration with Compliance leadership
• Keep abreast of changes in the HIPAA Security Rule and aid in assessing and implementing new requirements
• Establish a comprehensive, well-documented, and operational security program within the first year
• Organize an annual penetration test and integrate findings into the remediation strategy
• Minimum of 6 years of experience in information security
• At least 2 years of experience in a healthcare or similarly regulated ePHI/PII environment
• Proven hands-on responsibility for a HIPAA security program or a comparable regulated security program; advisory experience alone is not adequate
• In-depth understanding of the HIPAA Security Rule
• Familiarity with at least one relevant security/control framework, such as NIST Cybersecurity Framework (CSF) 2.0, NIST SP 800-66r2, or HITRUST
• Demonstrated capability to independently manage a security program in a streamlined setting
• Strong skills in risk-based prioritization, practical control implementation, and security documentation
• Preferred: CISSP, HCISPP, CISM, or a similar certification
• Preferred: Experience in securing telehealth platforms or other healthcare technology environments
• Preferred: Cloud security expertise with AWS, Azure, and/or GCP
• Preferred: Experience in leading security incident response efforts
• Preferred: Experience collaborating with fractional or external security resources, penetration testers, and independent security consultants
• Preferred: Knowledge of the evolving requirements of the HIPAA Security Rule
• Competitive salary and performance-based bonuses
• Comprehensive health, dental, and vision insurance
• Flexible working hours and remote work options
• Opportunities for professional development and training
• Supportive and inclusive work environment
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.