via Lensa
$90K - 150K a year
Lead cybersecurity compliance and governance programs focusing on cloud security, healthcare data protection, SOC 2 certification, and risk management.
Requires 8+ years in cybersecurity with 3+ years leading compliance in healthcare or regulated environments, strong AWS cloud security knowledge, and experience managing SOC 2 audits and HIPAA safeguards.
Director of Cybersecurity, Risk & Compliance Leads cybersecurity governance, cloud compliance, and healthcare security assurance, including the client's AWS-based OS proprietary whole-person care platform. Responsible for establishing, operationalizing, and continuously managing the company's cybersecurity compliance framework across AWS cloud infrastructure, healthcare data protection, SOC 2 certification efforts, HIPAA technical safeguards, business continuity planning, disaster recovery governance, and technical third-party risk management. Serves as the primary technical compliance authority for cybersecurity and cloud governance, working closely with Engineering, DevOps, Infrastructure, Legal, Corporate Governance, external auditors, Managed Care Plans, and healthcare partners to ensure security and compliance requirements are translated into practical control activities, documented evidence, remediation tracking, and ongoing operational execution. Leads key assurance workstreams, coordinates control owners, maintains audit readiness, validates technical control evidence, and escalates material risks or unresolved decisions to the CTO and appropriate business stakeholders. Strategic cybersecurity direction, final risk acceptance, budget authority, and executive security decisions remain with the CTO and company leadership. Responsibilities • SOC 2 Governance & Audit Leadership • Cloud Security Governance (AWS) • HIPAA & Healthcare Security Compliance • Business Continuity & Disaster Recovery • Security Awareness & Organizational Security Culture • Third-Party Technical Risk Management • Offshore DevOps & Technical Oversight Qualifications Required Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Systems or related field, or equivalent practical experience. A minimum of 8 years progressive experience in cybersecurity, cloud governance, risk management, compliance audit readiness, vendor risk management or information security operations. A minimum of 3 years leading cybersecurity compliance programs within healthcare or other regulated environments. Demonstrated experience leading SOC 2 Type I and Type II readiness, audit coordination, technical control implementation, and continuous compliance monitoring. Experience developing and managing Business Continuity Plans (BCP), Disaster Recovery (DR) programs, Business Impact Analyses (BIA), and organizational security awareness initiatives. Strong working knowledge of AWS cloud security architecture and governance, including identity and access management using AWS IAM and Okta, SSO/MFA implementation, privileged access controls, encryption, logging, monitoring, environment segmentation, and least-privilege access principles. Deep understanding of HIPAA technical safeguards, PHI protection requirements, healthcare data governance, and secure data exchange technologies including APIs and SFTP workflows. Strong understanding of cybersecurity frameworks and vendor risk management practices, including SOC reports, penetration testing reviews, security questionnaires, BAAs, NIST CSF, CIS Controls, and AWS security standards. Strong cross-functional leadership, communication, and stakeholder management skills with the ability to collaborate across technical, operational, legal, and executive teams in a fast-paced healthcare technology environment. Ability to organize audit evidence, manage remediation trackers, follow up with control owners, and translate compliance requirements into actionable technical and operational tasks. Proficiency with documentation systems, reporting tools, and enterprise collaboration platforms including Google Workspace, Salesforce, Smartsheet, and virtual communication tools. Work Environment / Physical Requirements Ability to work remotely, with reliable internet access. Frequent use of computers, phones, video conference tools and related office equipment. May require extended periods of sitting or standing during meetings or tasks. Adequate hearing and clear speech for in-person or telephone communication. Vision suitable for reading various documents, including memos, screens, and forms. Able to reach above the shoulder level to work, must be able to bend, squat and sit, stand, stoop, crouch, reach, kneel, twist/turn, etc. Occasional travel between locations may be required depending on organizational needs. May require occasional evening or early-morning hours to support business needs.
This job posting was last updated on 7/8/2026