
Vice President, Information Security and IT
Posted 14 hours ago

Posted 14 hours ago
This is a fully remote position, open to applicants in United States.
• Develop cybersecurity and corporate IT strategies, priorities, and plans aligned with company objectives, regulatory obligations, and identified risks.
• Formulate security policies and controls while collaborating with Enterprise Risk Management to identify, monitor, report, and mitigate cybersecurity risks.
• Direct the HIPAA Security Rule program, ensuring the protection of ePHI and sensitive data throughout its lifecycle.
• Enhance capabilities in threat detection and response, identity security, security architecture and engineering, product and cloud security, vulnerability management, vendor security, security awareness, and physical security standards.
• Collaborate with Product, Engineering, and Platform teams to integrate security into software, cloud environments, APIs, integrations, and production systems.
• Oversee AI governance, including acceptable-use policies, AI-tool evaluation and approval, data-handling guidelines, risk assessments, and ongoing monitoring.
• Manage major security incident responses and establish requirements for cyber-resilience and technology recovery.
• Work alongside ERM and business continuity leaders on crisis management and recovery testing.
• Supervise HITRUST, SOC 2, cybersecurity mandates, audits, regulatory reviews, and customer security assessments.
• Keep executive leadership and the Board updated on significant risks, incidents, program performance, and necessary investments.
• Act as the representative of the security program to customers, auditors, and regulatory bodies.
• Enhance business processes and productivity through business applications, integrations, automation, and AI.
• Oversee security and IT budgets, vendor management, technology investments, team development, and performance assessments.
• Extensive experience in cybersecurity, including senior leadership of an organization-wide security program.
• Direct cybersecurity leadership experience within a HIPAA-regulated healthcare organization.
• In-depth, practical understanding of the HIPAA Security Rule and the protection of ePHI in a covered entity or business associate context.
• Proven experience in developing or enhancing a security program in a startup, scale-up, or other dynamic organizations with limited resources and shifting priorities.
• Strong technical expertise in cloud security, identity and access management, product and application security, information protection, incident response, vendor risk, and resilience.
• Experience collaborating with Product and Engineering teams in cloud-based software settings.
• Familiarity with HITRUST, SOC 2, healthcare audits, and security evaluations for enterprise clients.
• Experience leading corporate IT for a distributed workforce, covering business applications, endpoints, identity management, employee support, and IT service delivery.
• Practical experience in AI governance and utilizing business applications, automation, integrations, APIs, and AI tools to enhance workflows and productivity across the organization.
• Exceptional leadership and communication skills, including experience in team development, budget management, vendor oversight, handling major incidents, and presenting risks and recommendations to executives and the Board.
• Authorization to work in the United States is mandatory.
• Must indicate whether employer visa sponsorship is necessary.
• Provides equity.
• Includes bonus opportunities.
• Covers alternative medicine.
• Offers flexible PTO.
• Provides up to 16 weeks of paid parental leave.
• Includes paid holidays.
• Features a 401k program.
• Offers transportation perks.
• Provides education reimbursement.
• Includes 2 days of paid paw-ternity leave.
• Standard health and wellness benefits are provided.
GuidePoint Security
Your Software Supplier
Dragonfli Group
Headway
Get handpicked remote jobs straight to your inbox weekly.