Director of Cybersecurity, Risk & Compliance

Posted on 01 July 26 by Michael Myers

  • $ - $
Logo

Powered by Tracker

Job Description

Job Title: Director of Cybersecurity, Risk & Compliance
Reports To: Chief Technology Officer
Department: Technology
FLSA Status: Exempt
Position Summary
Leads cybersecurity governance, cloud compliance, and healthcare security assurance,
including the client's AWS-based OS proprietary whole-person care platform. Responsible for
establishing, operationalizing, and continuously managing the company’s cybersecurity
compliance framework across AWS cloud infrastructure, healthcare data protection, SOC 2
certification efforts, HIPAA technical safeguards, business continuity planning, disaster recovery
governance, and technical third-party risk management. Serves as the primary technical
compliance authority for cybersecurity and cloud governance, working closely with Engineering,
DevOps, Infrastructure, Legal, Corporate Governance, external auditors, Managed Care Plans,
and healthcare partners to ensure security and compliance requirements are translated into
practical control activities, documented evidence, remediation tracking, and ongoing operational
execution. Leads key assurance workstreams, coordinates control owners, maintains audit
readiness, validates technical control evidence, and escalates material risks or unresolved
decisions to the CTO and appropriate business stakeholders. Strategic cybersecurity direction,
final risk acceptance, budget authority, and executive security decisions remain with the CTO
and company leadership.
Responsibilities
SOC 2 Governance & Audit Leadership
● Lead end-to-end SOC 2 Type I and Type II readiness and audit execution.
● Own technical control implementation tracking and evidence collection.
● Coordinate external CPA auditors, internal control owners, audit requests, walkthroughs,
and remediation activities.
● Maintain SOC 2 control documentation, evidence repositories, audit calendars,
readiness trackers, and control owner assignments.
● Maintain continuous compliance and control monitoring programs.
● Track open control gaps, audit findings, exceptions, and remediation activities through
completion.
1
● Escalate unresolved control issues, delayed remediation items, or material compliance
risks to the CTO.
Cloud Security Governance (AWS)
● Govern AWS security standards and technical compliance controls.
● Oversee IAM, encryption, logging, monitoring, environment segmentation, and access
governance.
● Ensure least-privilege access models and PHI protection controls are documented,
implemented, and maintained.
● Validate separation between production and non-production environments.
● Maintain AWS security assurance documentation aligned with SOC 2, HIPAA, internal
security policies, and AWS security expectations.
● Track AWS security control gaps, evidence requests, exceptions, and remediation items.
● Coordinate with technical owners to confirm remediation progress and validate
supporting evidence.
HIPAA & Healthcare Security Compliance
● Operationalize HIPAA technical safeguards across the organization.
● Support DHCS, CalAIM, and healthcare payer security requirements.
● Ensure healthcare data handling controls meet regulatory, contractual, and internal
security expectations.
● Oversee secure data exchange governance, including APIs, SFTP workflows, file
transfers, and other mechanisms involving sensitive healthcare information.
● Maintain documentation related to PHI protection, access controls, encryption, logging,
monitoring, auditability, and secure healthcare data handling.
● Work with technical and business stakeholders to ensure healthcare security obligations
are reflected in policies, procedures, vendor reviews, and technical control
documentation.
Business Continuity & Disaster Recovery
● Lead Business Impact Analysis (BIA) initiatives with business stakeholders.
● Develop and maintain Business Continuity Plans (BCP).
● Coordinate Disaster Recovery (DR) governance, testing and evidence collection.
● Ensure recovery objectives and resilience controls are documented and validated.
● Track BCP/DR gaps, lessons learned, and remediation activities.
● Maintain BCP/DR evidence for audit, payer, partner, and internal governance purposes.
● Escalate unresolved resilience gaps, recovery objective conflicts, or testing deficiencies
to the CTO and appropriate business owners.
Security Awareness & Organizational Security Culture
● Deploy and manage enterprise security awareness training.
● Conduct phishing simulation campaigns and workforce education.
2
● Lead the development, approval, publication, and ongoing maintenance of all core IT
and Information Security policies, including the Generative AI Policy, Data Classification
Policy, and the consolidated Third-Party Risk Management(TPRM) Policy.
● Coordinate policy review cycles with the CTO, Legal, Corporate Governance, and other
stakeholders.
● Track completion metrics, phishing results, exceptions, and organizational risk reduction
activities.
● Maintain documentation supporting training completion, policy acknowledgments,
awareness metrics, and security culture initiatives.
Third-Party Technical Risk Management
● Perform technical security reviews of vendors and sub-processors.
● Review SOC reports, penetration tests, security questionnaires, BAAs, security
addenda, and related assurance artifacts.
● Maintain vendor technical risk assessments, risk ratings, remediation trackers, and
review schedules.
● Coordinate with Legal, Corporate Governance, Technology, and business stakeholders
on vendor security requirements.
● Escalate material vendor risks to the CTO or appropriate risk owner.
● Help document vendor risk acceptance decisions, compensating controls, remediation
plans, and renewal-related security requirements.
Offshore DevOps & Technical Oversight
● Audit offshore DevOps security practices and privileged access controls.
● Ensure offshore resources do not access live production PHI unless explicitly approved
and controlled.
● Validate data masking, logging, monitoring, and environment segregation standards.
● Maintain documentation related to offshore access, production data protection, and
technical control evidence.
● Track offshore access or control gaps and coordinate remediation with technical teams.
● Escalate material access, PHI exposure, or segregation concerns to the CTO.
Qualifications
Required
● Bachelor’s degree in Cybersecurity, Information Security, Computer Science, Information
Systems or related field, or equivalent practical experience.
● A minimum of 8 years progressive experience in cybersecurity, cloud governance, risk
management, compliance audit readiness, vendor risk management or information
security operations.
● A minimum of 3 years leading cybersecurity compliance programs within healthcare or
other regulated environments.
3
● Demonstrated experience leading SOC 2 Type I and Type II readiness, audit
coordination, technical control implementation, and continuous compliance monitoring.
● Experience developing and managing Business Continuity Plans (BCP), Disaster
Recovery (DR) programs, Business Impact Analyses (BIA), and organizational security
awareness initiatives.
● Strong working knowledge of AWS cloud security architecture and governance, including
identity and access management using AWS IAM and Okta, SSO/MFA implementation,
privileged access controls, encryption, logging, monitoring, environment segmentation,
and least-privilege access principles.
● Deep understanding of HIPAA technical safeguards, PHI protection requirements,
healthcare data governance, and secure data exchange technologies including APIs and
SFTP workflows.
● Strong understanding of cybersecurity frameworks and vendor risk management
practices, including SOC reports, penetration testing reviews, security questionnaires,
BAAs, NIST CSF, CIS Controls, and AWS security standards.
● Strong cross-functional leadership, communication, and stakeholder management skills
with the ability to collaborate across technical, operational, legal, and executive teams in
a fast-paced healthcare technology environment.
● Ability to organize audit evidence, manage remediation trackers, follow up with control
owners, and translate compliance requirements into actionable technical and operational
tasks.
● Proficiency with documentation systems, reporting tools, and enterprise collaboration
platforms including Google Workspace, Salesforce, Smartsheet, and virtual
communication tools.
Desired
● Master’s degree in Cybersecurity, Information Security, Business Administration, or
related field.
● Experience supporting DHCS, CalAIM, or similar healthcare payer and regulatory
security environments.
● Experience within healthcare technology, SaaS, cloud-native environments, or digital
health platforms.
● Familiarity with ISO 27001, AWS Well-Architected Framework, SOC 2 Trust Services
Criteria, and HIPAA Security Rule requirements.
● Experience using GRC tools, ticketing systems, evidence management repositories,
security awareness platforms, or phishing simulation tools.
● Relevant certifications such as Security+, CISA, CRISC, CCSK, AWS Cloud Practitioner,
AWS Security Specialty, HCISPP, CISSP, or similar are helpful but not required.
Work Environment / Physical Requirements
● Ability to work remotely, with reliable internet access.
● Frequent use of computers, phones, video conference tools and related office
equipment.
4
● May require extended periods of sitting or standing during meetings or tasks.
● Adequate hearing and clear speech for in-person or telephone communication.
● Vision suitable for reading various documents, including memos, screens, and forms.
● Able to reach above the shoulder level to work, must be able to bend, squat and sit,
stand, stoop, crouch, reach, kneel, twist/turn, etc.
● Occasional travel between locations may be required depending on organizational
needs.
● May require occasional evening or early-morning hours to support business needs.

Job Information

Rate / Salary

$ - $

Sector

Healthcare

Category

Not Specified

Skills / Experience

Not Specified

Benefits

Not Specified

Our Reference

SolluCIO1474

Job Location