HIPAA Security Engineer
Core
Lead design and operation of US Healthcare security controls, owning the roadmap for HIPAA compliance and SOC2 Type II certification.
Role type
Senior Security Compliance Engineer (HIPAA/SOC2)
Builds
Secure, compliant platform for millions of users in the health & fitness sector
Domain
Health tech / Digital health / Cloud SaaS
Required skills
SOC 2 framework expertise, HIPAA framework expertise, risk assessment, vendor management, GRC platform management, compliance automation, PHI handling
Preferred skills
CISA certification, CISSP certification, NIST framework knowledge, HiTrust experience, Docker, Kubernetes, DevSecOps
Responsibilities
Lead annual SOC 2 and HIPAA certifications, define and maintain security policies, partner with control owners to automate evidence gathering, serve as primary Security POC for US regulators, manage and integrate GRC platforms
Seniority
Senior, hands-on IC with leadership responsibilities