HIPAA Security Engineer
Overview
Lead design and operation of US Healthcare security controls as part of Security Architecture team. Own roadmap for HIPAA compliance and SOC2 Type II certification while partnering with Engineering and Legal to build secure compliant platform for millions of users.
What You'll Do9
- 1Lead annual SOC 2 and HIPAA certifications managing interfaces with external auditors and professional services
- 2Define and maintain security policies embedding risk assessment activities within engineering processes and vendor management
- 3Partner with control owners to automate evidence gathering ensuring controls reduce friction rather than create it
- 4Serve as primary Security POC for US regulators and partners supporting wider Security team with ISO 27001/27701 alignment
- 5Manage and integrate GRC platforms to streamline compliance monitoring and reporting
- 6Drive translation of complex compliance requirements into clear actions for engineering teams
- 7Utilize deep expertise in SOC 2 and HIPAA frameworks within Cloud-based SaaS environment
- 8Familiarity with PHI handling GRC platforms and compliance automation
- 9Support performance incentive scheme and meaningful rewards
Requirements5
- 17+ years in security compliance with 3+ years in leadership roles
- 2Bachelor's degree in related field
- 3CISA/CISSP certifications preferred
- 4Experience with NIST HiTrust Docker Kubernetes DevSecOps
- 5Strong ability to communicate complex compliance requirements
Salary Insight
Salary not disclosed in listing
Location
Required Skills
Similar open positions
Explore active roles that match your skills and interests.
Clinicallyai
VerifiedSecurity and Compliance Manager at Clinically AI
Security and Compliance Manager leading compliance program end to end at Clinically AI. Own frameworks SOC2 Type II HIPAA NIST ensuring audit readiness and continuous compliance while scaling rapidly.
Sightview Software LLC
VerifiedVP Information Security & IT Operations, Healthcare SaaS
You will own Sightview's corporate IT infrastructure and enterprise security program end-to-end, securing a healthcare SaaS platform used by ophthalmology and optometry practices. You lead the SOC 2 Type II and HITRUST certification processes, manage GRC managers and security teams, and embed security into DevOps and Engineering workflows. With AWS hands-on depth, you review CloudTrail logs, WAF rules, and firewall configs to keep infrastructure intact. This remote role reports to the CTO and shapes security strategy for a fast-growing eye care software company.
Inizio Partners
VerifiedAVP – Cybersecurity
Lead cybersecurity operations and strategy for Health and Life Sciences business units ensuring confidentiality integrity and availability of sensitive data. Oversee application security infrastructure security SOC operations incident response and third party risk management. Drive resilient security programs and mentor teams.
Health Care Service Corp.
VerifiedPrivacy Analyst HCSC Dallas
Join HCSC as a Privacy Analyst in Richardson TX to lead privacy compliance efforts. This hybrid role drives HIPAA and HITECH compliance while supporting cross-functional teams. You will own privacy operations and deliver actionable insights from PHI data. Stand out by shaping our privacy culture through data-driven strategies.
Wellsky
VerifiedSr. Compliance Manager WellSky
Lead compliance programs ensuring healthcare and privacy regulatory alignment across state and federal laws. Manage policy development and internal controls while driving AI integration into compliance workflows. Report to the Compliance Committee and shape future of healthcare.
USA Solventum Health Information Systems, Inc.
VerifiedProject Leader at Solventum Health Information Systems
Lead security initiatives at Solventum to drive enterprise compliance and enhance product development. You will coordinate cross-functional teams to build secure solutions while translating security requirements into actionable plans. This role influences product roadmaps and establishes governance frameworks to mitigate risks and improve processes.