
Senior Director, Security & Compliance
Posted Sep 10

Posted Sep 10
This is a fully remote position, open to applicants in United States.
• Act as the Compliance Officer for the organization and the appointed HIPAA Security Officer.
• Oversee the company's compliance and information security initiatives.
• Manage HIPAA/HITECH compliance, which encompasses the Security Risk Analysis, risk-management strategy, and continuous monitoring of necessary safeguards.
• Direct SOC 2 Type II and other compliance certifications, attestations, and assurance programs.
• Handle audit preparedness, relationships with auditors, remediation efforts, and the adequacy of evidence.
• Take charge of the compliance and information security policy framework, including the development, review, approval, exceptions, and ongoing governance of policies.
• Define control ownership and ensure that deficiencies, risks, and remediation strategies are recognized, monitored, and escalated appropriately.
• Collaborate with Engineering, DevOps, architecture, and IT leaders to assess security strategies and technical controls.
• Lead the security incident response framework and collaborate on incident evaluation, response, and remediation.
• Oversee security and compliance dimensions of third-party risk management, customer assessments, audits, RFPs/RFIs, and security escalations.
• Create governance for emerging technologies and sensitive data.
• Continuously enhance the compliance and security operational model.
• A minimum of 8 years of experience in compliance, information security, risk management, or related fields, including significant leadership roles.
• Extensive practical understanding of HIPAA/HITECH and healthcare compliance mandates, preferably in a covered entity or business associate context.
• Proven experience in leading SOC 2 Type II or similar certification and assurance initiatives.
• Experience in establishing or substantially enhancing compliance governance, control environments, policy frameworks, audit readiness, and cross-functional accountability.
• In-depth working knowledge of cloud security, application security, IAM, vulnerability management, endpoint security, secure SDLC practices, and contemporary SaaS architecture.
• Capability to engage effectively with technical leaders, assess proposed strategies, pinpoint material risks, and convert technical challenges into business, compliance, and customer implications.
• Strong executive judgment and communication abilities, with the capacity to collaborate efficiently across Legal, Engineering, Product, IT, People, Finance, auditors, customers, and executive leadership.
• Proven ability to instill accountability across various functions without relying solely on direct reporting structures.
• Relevant certifications such as CISSP, CISM, CRISC, CISA, CHC, or similar are preferred but not mandatory if equivalent experience is demonstrated.
• Must be legally authorized to work in the United States.
• Must be located in the United States.
• Potential equity compensation for exceptional performance.
• Flexible paid time off (PTO).
• Sponsored lunches for the entire company.
• Company-paid disability and life insurance benefits.
• Company-funded family and medical leave.
• Medical, dental, and vision insurance benefits.
• Discounted pet insurance options.
• Flexible Spending Account (FSA)/Dependent Care Account (DCA) and commuter benefits.
• 401(k) plan.
• Credits for online fitness classes and gym memberships.
• Recovery suite at headquarters, featuring a cold plunge, sauna, and shower.
• Remote or hybrid work environment.
LabConnect
Ripple Effect
Binance
biBerk Business Insurance
Get handpicked remote jobs straight to your inbox weekly.