Director of Legal, Risk & Compliance

Sorry, this job was removed at 04:07 p.m. (CST) on Wednesday, Apr 08, 2026
Be an Early Applicant
Hiring Remotely in United States
Remote
150K-180K Annually
Healthtech • Information Technology • Software
The Role

About Medicom

Medicom is a leading enterprise imaging software company that solves longstanding interoperability challenges for clinicians, staff, patients, and researchers. Its core platform, Connect, supports diverse enterprise imaging interoperability use cases. These include access to prior and unread imaging studies, point-of-care workflows, patient access to images, orders, and results workflows for teleradiology, telestroke, and trauma, and cross-institution sharing of digital imaging. Medicom's Network is adopted by over 1,000 US healthcare institutions and backed by leading venture capital firms, such as UPMC Enterprises. Data and insights from the Medicom Connect network drive Medicom's Intellect offering, which helps clinicians and researchers advance patient care and develop new therapies.

About the role

Medicom is seeking a Director of Legal, Risk & Compliance (GRC) to lead the Company’s information security, regulatory compliance, and contractual risk management programs. As a healthcare data company, Medicom must meet the highest standards for data protection while supporting rapid product development and enterprise growth.


This role will own Medicom’s security and compliance frameworks (HIPAA, HITRUST, SOC 2, GDPR, FedRAMP readiness) while also serving as the primary reviewer of customer contractual obligations. The Director will partner closely with Engineering, Sales, Legal, and executive leadership to ensure security, compliance, and legal commitments are aligned and operationally achievable.


What you'll do

  • Own and lead Medicom’s information security and compliance programs, ensuring adherence to HIPAA, HITRUST, SOC 2, GDPR, and evolving regulatory standards.
  • Define, document, and continuously improve the company’s security control framework and risk management processes.
  • Leadership sponsor for SOC 2 audits and other certification efforts, coordinating with third-party auditors and internal stakeholders.
  • Prepare the organization for advanced frameworks and certifications, including FedRAMP readiness.
  • Serve as chair of the Confidentiality & Security Team (CST), including meeting leadership and agenda setting.
  • Review and assess customer MSAs, BAAs, and ISAs to ensure alignment with Medicom’s security controls and compliance posture.
  • Partner with Sales and Legal during enterprise negotiations to balance commercial objectives with risk mitigation.
  • Ensure ongoing compliance with contractual obligations, federal and state regulations, and customer procurement policies.
  • Coordinate with external counsel as appropriate regarding legal contracts and compliance matters.
  • Partner closely with Engineering to embed security and compliance requirements into product design and architecture.
  • Act as a trusted advisor across the organization on security, compliance, and risk-related matters.

Qualifications

  • 8–12+ years of experience in information security, governance, compliance, and legal within healthcare, health tech, or SaaS environments.
  • CISSP strongly preferred (or equivalent advanced security certification).
  • Deep working knowledge of HIPAA, SOC 2, HITRUST, GDPR, CCPA; FedRAMP experience strongly preferred.
  • Experience leading audits, certifications, and regulatory assessments.
  • Demonstrated experience reviewing and negotiating contractual language (MSAs, BAAs, DPAs, ISAs).
  • Strong communication skills and ability to influence cross-functional stakeholders.


Equal Opportunity Employer Statement

Medicom Technologies is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.


Reasonable Accommodation Notice

If you require a reasonable accommodation in the application process, please contact [email protected] to discuss your needs.

Similar Jobs

Coupa Logo Coupa

Marketing Manager

Artificial Intelligence • Fintech • Information Technology • Logistics • Payments • Business Intelligence • Generative AI
In-Office or Remote
Ann Arbor, MI, USA
2500 Employees
104K-135K Annually

Wipfli Logo Wipfli

Manager, Technical Program Management

Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Remote or Hybrid
United States
3000 Employees
117K-158K Annually

PwC Logo PwC

Partner Tax Preparation Advisor Senior Manager

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Remote or Hybrid
61 Locations
370000 Employees
91K-322K Annually

PwC Logo PwC

Consultant

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Remote or Hybrid
58 Locations
370000 Employees
77K-202K Annually
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Raleigh, North Carolina
64 Employees
Year Founded: 2015

What We Do

We created the first federated health information network: a powerful platform that connects disparate data silos through a single interface. The value of a health information network is dependent on the willing participation of providers, hospitals, and imaging centers in a community. While technology can support the adoption of health information networks — from large hospitals and IDNs to private practices alike — the technology on its own has little to no value. Many medical image sharing solutions and health information networks are implemented within an organization’s walls, without considering how to support and connect providers in the community. Medicom has taken the unique approach to better serve providers by building health information networks with service and support organizations that are experts on their local communities. These service and support organizations provide local resources to hospitals around the United States, with teams who are familiar with their customers, and able to quickly and efficiently establish community-based solutions.

Similar Companies Hiring

Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account