VP, Cybersecurity
XpertDox · Scottsdale, AZ
Apply & track with Apply EdgeVP, Cybersecurity & ComplianceLocation: Scottsdale, Arizona (on-site)Employment type: Full-timeReports to: Chief Technology OfficerCompensation: $160,000 to $210,000 base, plus performance bonus and stock optionsWho We AreXpertDox is a healthcare AI company. Our platform, XpertCoding, codes outpatient medical claims autonomously for more than 1,000 providers across all 50 states. We run production systems that handle protected health information every day, so our security and compliance posture is not a back-office function: it is one of the main reasons health systems and provider groups choose us. We hold SOC 2 Type 2, ISO 27001, ISO 22301, and HIPAA attestations, and HITRUST certification is underway.Role OverviewWe are hiring a Vice President of Cybersecurity and Compliance to lead our security and compliance program and to be the person large healthcare organizations trust when they evaluate us. You will own the certification roadmap, set the security governance and risk framework, and represent XpertDox directly to client security teams and their CISOs. Success in this role is measured by trust: certifications maintained and expanded, enterprise security reviews cleared quickly, and health systems naming our security posture as a reason they signed.Key ResponsibilitiesCertification and compliance: Own the certification portfolio (SOC 2 Type 2, ISO 27001, ISO 22301, HIPAA) and lead HITRUST certification, including the roadmap, assessor relationships, and audit strategy.Client assurance: Act as the senior security voice with enterprise clients and health systems, leading security reviews, questionnaires, and CISO-level conversations so security speeds deals up rather than slowing them down.Security strategy and governance: Own the security posture, the policy and governance framework, and enterprise risk management.HIPAA and regulatory ownership: Own the HIPAA program and the Business Associate Agreement framework across a hybrid cloud, on-premise, and distributed environment.AI governance: Work with our AI and machine learning teams on AI governance aligned to the NIST AI Risk Management Framework, including controls on how PHI moves through AI-assisted workflows.Executive reporting: Report security and compliance posture, key risks, and remediation status to the Chief Technology Officer, and present to the CEO, board, and investors as needed.Team leadership: Build and lead the security and compliance team and raise security awareness across the company.Required QualificationsTen or more years in cybersecurity and compliance, including running a security or compliance program.Track record building and maintaining SOC 2 Type 2, ISO 27001, and HIPAA programs and managing third-party audits.Direct experience representing security and compliance to enterprise customers, health systems, and their security leaders.Strong executive presence, with the ability to give a large organization confidence in a smaller vendor.Deep HIPAA and healthcare regulatory knowledge.Experience owning enterprise risk management and security governance frameworks.Experience leading and growing a security or compliance team.At least one of CISSP, CISM, CISA, or HCISPP.Preferred QualificationsHealthcare, health-tech, or another setting handling PHI at scale.HITRUST CSF experience as a program lead or assessor liaison.A record of helping close enterprise or health system deals on the security and compliance side.AI governance experience in a regulated environment.Experience running a continuous-compliance or GRC program.Why This Role MattersAutonomous coding only works if the organizations trusting us with patient data believe our controls hold. This role reports to the CTO, carries real decision authority over our security posture, and has a direct effect on whether large health systems say yes. You will be building the program, not inheriting a finished one.