Apply Edge Start your job search

Information Security Officer

Confidential Jobs · New York City Metropolitan Area

Apply & track with Apply Edge
Confidential Healthcare Technology CompanyRemote – United States | EST/CST preferredAbout the CompanyWe are a fast-growing healthcare technology company building software that helps healthcare and community-based organizations improve access to care and services for diverse populations across the United States.Our technology supports large-scale member engagement, workflow automation, and care coordination for organizations operating in highly regulated environments. As the company continues to expand its healthcare, enterprise, and public-sector customer base, information security, compliance, and operational maturity are becoming increasingly critical to our next stage of growth.We are conducting this search confidentially.About the RoleWe are looking for an experienced, hands-on Information Security Officer to lead the company's information security, compliance, and IT operations functions.This leader will own and mature the organization's security and compliance program as the business scales. The role is responsible for driving security strategy, maintaining regulatory and certification readiness, overseeing security and IT operations, managing organizational risk, and ensuring the company can meet increasingly sophisticated enterprise customer requirements.You will work closely with Engineering, Product, Operations, Legal, Compliance, and customer-facing teams to strengthen the company's security posture and build scalable security processes.The ideal candidate combines senior-level security leadership with a willingness to remain deeply hands-on across audits, security operations, IT administration, vendor management, and compliance initiatives.What You'll DoSecurity Strategy & Program LeadershipDefine and execute the company's information security roadmap. Establish security objectives, policies, standards, controls, and operational processes that support continued growth and regulatory requirements.Compliance & Audit ManagementLead activities required to achieve, maintain, and continuously improve compliance across frameworks including HITRUST, HIPAA, SOC 2, NIST, ISO 27001, GDPR, and related standards. Own audit readiness, evidence collection, remediation tracking, and ongoing compliance operations.Security Operations & Incident ResponseOversee security monitoring, vulnerability management, endpoint security, cloud security posture management, and incident response. Lead investigations, remediation activities, post-mortems, and continuous security improvements.IT Operations & Infrastructure OversightOwn corporate IT operations, including device lifecycle management, identity and access management, endpoint management, SaaS administration, network security, and the operational effectiveness of internal systems.Risk Management & Vendor SecurityEstablish and maintain enterprise risk management processes, including risk assessments, risk registers, mitigation planning, and third-party security reviews. Support procurement, customer due diligence, and vendor risk management.Leadership & Team DevelopmentLead and develop a small team spanning security, compliance, GRC, and IT. Establish clear priorities, accountability, operating rhythms, and performance expectations.Cross-Functional PartnershipPartner closely with Engineering, Product, Compliance, Operations, Legal, and commercial teams to embed security into product development, infrastructure, internal processes, and customer engagements.Executive Reporting & GovernanceProvide clear reporting on security posture, compliance readiness, risks, incidents, remediation progress, and operational metrics to executive leadership and, when required, board stakeholders.What We're Looking ForRequirements7+ years of relevant experience across information security, cybersecurity, IT, governance, risk, compliance, or related disciplines, including ownership of security programs or operational security functions.Strong security and compliance expertise, including experience with frameworks and regulations such as HITRUST, HIPAA, NIST, SOC 2, ISO 27001, and GDPR.Audit and certification leadership, including evidence collection, remediation, risk assessments, control implementation, and certification initiatives within regulated environments.Security operations experience across vulnerability management, SIEM, endpoint security, incident response, cloud security, IAM, monitoring, and related security disciplines.Corporate IT leadership experience, including identity providers, endpoint management, SaaS administration, MDM, access management, and enterprise technology operations.People management experience, including managing security, GRC, compliance, or IT professionals.Startup or growth-stage experience, with the ability to build scalable processes without excessive bureaucracy.Excellent written and verbal communication skills, including the ability to communicate effectively with executives, customers, auditors, regulators, and technical teams.Preferred QualificationsDirect experience leading HITRUST R2 certification and recertification.Experience within healthcare technology, digital health, health plans, healthcare services, or another highly regulated environment involving PHI and HIPAA.Experience supporting enterprise customer security questionnaires, procurement reviews, regulatory inquiries, and security due diligence.Experience managing auditors, MSSPs, security vendors, consultants, and third-party risk programs.Certifications such as CISSP, CISM, CISA, HITRUST CCSFP, or equivalent.Experience securing modern cloud-native environments and partnering closely with engineering teams on infrastructure and application security.Additional InformationLocation: United States, remoteWorking hours: Preference for candidates able to work primarily EST or CST hoursSearch: Confidential