Verified today
Visit Health - Security and Compliance Manager
About the role
The Security and Compliance Manager will oversee security frameworks, regulatory compliance, and risk management for a health-tech platform. Responsibilities include developing security policies, conducting audits, ensuring adherence to global standards, and managing incident response. The role requires collaboration with IT and legal teams to protect data and maintain compliance with regulations like ISO 27001, HIPAA, and GDPR. The ideal candidate will also educate internal teams on security best practices and stay updated on emerging threats and regulations.
What you’ll do
- Develop and implement security policies, standards, and guidelines
- Conduct risk assessments and security audits to identify vulnerabilities
- Ensure compliance with industry regulations like ISO 27001, HIPAA, GDPR, SOC 2, PCI-DSS, NIST
- Lead internal and external security audits and manage relationships with auditors
- Implement and maintain data protection policies to safeguard sensitive information
- Develop and maintain incident response plans and security monitoring mechanisms
- Conduct security awareness training for employees to promote a security-first culture
What you’ll bring
- 2.5 to 5 years of experience in security and compliance management
- Knowledge of industry regulations like ISO 27001, HIPAA, GDPR, SOC 2, PCI-DSS, NIST
- Experience in conducting risk assessments and security audits
- Ability to develop and implement security policies and guidelines
- Collaboration skills with IT and legal teams for secure infrastructure
Nice to have
- Experience in data protection and privacy laws (e.g., GDPR, CCPA)
- Knowledge of incident response plans and security monitoring mechanisms
- Ability to conduct security awareness training for employees
- Stay updated on new regulations and industry trends