First Stop Health

Director of Information Security and Compliance

First Stop Health

full-time

Posted on:

Origin:  • 🇺🇸 United States

Visit company website
AI Apply
Apply

Job Level

Lead

Tech Stack

AWSCloudSDLC

About the role

  • Develop and execute a comprehensive security and compliance strategy in collaboration with the vCISO
  • Own the security roadmap aligned to business goals and regulatory requirements
  • Chair the Security Committee, lead policy creation and refresh cycles, and drive company-wide security culture
  • Lead SOC 2 Type 2 and HIPAA compliance programs, including audit coordination, controls, and evidence collection
  • Manage vendor due diligence, client security questionnaires, third-party security reviews, and maintain BAAs and PIAs
  • Conduct regular risk assessments, pen testing, access reviews, vulnerability scans, and patching reviews
  • Implement and manage IAM (SSO, conditional access, granular permissioning) and SIEM/logging/monitoring
  • Deploy and operate security tooling (DLP, endpoint protection, vulnerability management) and automate security processes
  • Coordinate incident response with IT, Engineering, Legal, and vCISO; lead tabletop exercises and after-action reviews
  • Partner with engineering to embed security into SDLC, CI/CD, and infrastructure as code; implement secure cloud architecture and container security
  • Design and deliver company-wide security training, phishing simulations, and guidelines for safe AI tool usage
  • Report to the VP of IT and work closely with the virtual CISO and cross-functional teams

Requirements

  • 7+ years of experience in information security roles, with a balance of compliance and technical expertise
  • Proven experience with HIPAA, SOC 2, and healthcare privacy regulations
  • Strong technical skills in cloud security (AWS), IAM, SIEM, DLP, vulnerability management, and security architecture
  • Experience leading SOC 2 Type 2 audits and evidence collection
  • Experience conducting risk assessments, pen testing, access reviews, vulnerability scans, and patching reviews
  • Experience managing vendor due diligence, client security questionnaires, and third-party security reviews
  • Experience maintaining BAAs, PIAs, and supporting CCPA/CPRA compliance
  • Experience implementing and managing identity and access management (SSO, conditional access, granular permissioning)
  • Experience building and maintaining SIEM, logging, and monitoring
  • Experience deploying and operating security tooling: DLP, endpoint protection, vulnerability management
  • Experience automating security processes (account administration, onboarding/offboarding, compliance workflows)
  • Experience coordinating incident response and leading tabletop exercises and after-action reviews
  • Ability to influence executives and cross-functional stakeholders; strong communication and project management skills
  • Preferred certifications: CISSP, CISM, CISA, HCISPP, CCSP, or healthcare-specific equivalents
  • Startup/SaaS and remote-first work experience highly valued
Centene Corporation

Data Security Engineer II

Centene Corporation
Junior · Midfull-time$30–$54New York · 🇺🇸 United States
Posted: 25 days agoSource: centene.wd5.myworkdayjobs.com
AWSAzureCloudCyber Security
Kidde Global Solutions

Senior Cybersecurity Engineer

Kidde Global Solutions
Seniorfull-time$127k–$150k / year🇺🇸 United States
Posted: 1 day agoSource: carrier.wd5.myworkdayjobs.com
AWSAzureCloudCyber SecurityGoogle Cloud PlatformPythonSDLCSplunk
Ball Corporation

Cybersecurity Lead

Ball Corporation
Seniorfull-time$96k–$137k / yearColorado · 🇺🇸 United States
Posted: 15 days agoSource: jobs.ball.com
AWSAzureCloudCyber SecurityDNSFirewallsGoJenkinsLinux
Huntress

Cybersecurity Advisor, vCISO

Huntress
Senior · Leadfull-time$190k–$205k / year🇺🇸 United States
Posted: 4 days agoSource: boards.greenhouse.io
AWSAzureCloudCyber SecurityGoGoogle Cloud PlatformPython
Palo Alto Networks

Consulting Director – Specialized and Proactive Services

Palo Alto Networks
Leadfull-time$183k–$252k / yearCalifornia · 🇺🇸 United States
Posted: 28 days agoSource: jobs.smartrecruiters.com
AWSAzureCloudCyber SecurityGoogle Cloud Platform