Head of Information Security/Compliance

Posted 25 Days Ago
Be an Early Applicant
Hiring Remotely in Denver, CO, USA
In-Office or Remote
175K-220K Annually
Expert/Leader
Artificial Intelligence • Healthtech • Machine Learning • Software
The Role
Own Frontera’s AWS cloud security architecture, IAM design, security posture, and hands-on SOC 2 audits. Build the company’s compliance program, policies, processes, and tooling while partnering with Engineering. Represent security and compliance in customer, prospect, partner, and board discussions. Establish the security function as Frontera scales into enterprise and healthcare markets, ensuring trusted management of sensitive data.
Summary Generated by Built In

Frontera is reimagining how children with autism and other behavioral health needs get the care they deserve. We bring together world-class clinicians, technologists, and autism specialists to build cutting-edge AI tools that help care teams work smarter and spend more time with the children and families who need them most.

Our platform is HIPAA-compliant and designed for the real-world needs of behavioral health teams - from psychologists to ABA therapists. By combining evidence-based care with powerful technology, we’re expanding access to high-quality services for families everywhere.


Our Mission

Frontera exists to close the care gap: every child, no matter where they live, should be able to access effective behavioral healthcare.

Role Overview

Frontera is hiring a Head of Information Security/Compliance to own our cloud security posture and compliance program as we scale. This isn't a compliance-generalist seat that partners with engineering from the outside - we need someone with real cloud security depth who can operate inside our AWS infrastructure, hold SOC 2 audits, and be the senior security voice both internally and in front of customers and boards. As we sell into healthcare and enterprise, this role is central to Frontera being trusted with sensitive data at scale.

What You'll Own

  • Compliance program ownership
    • Own Frontera's HIPAA program across both Frontera Health and FronteraCare, and serve as the designated HIPAA Security and Privacy Officer.
    • Own the SOC 2 program end to end, including audit scope, observation periods, the auditor relationship, evidence collection in our compliance platform, and tracking remediation to closure.
    • Run the annual HIPAA risk assessment and keep a living risk register that leadership reviews regularly.
    Internal policies and standards
    • Build Frontera's internal policy framework across both entities, covering acceptable use, access control, data classification and handling, device and endpoint use, AI tool use, vendor onboarding, incident response, and data retention and deletion.
    • Write role-specific procedures for FronteraCare clinic staff, so front-line teams know exactly what to do in common situations like texting families, using personal devices, or trying a new app.
    • Set up a clear, fast way for employees to request new tools, so staff don't feel they have to go around security to get their work done.
    • Keep policies current as the business changes, including new products, new AI vendors, and new clinic locations. Run annual reviews and have leadership sign off on changes.
    • Make sure each policy maps to HIPAA and SOC 2 requirements, so one set of policies serves both audits and nothing is duplicated.
    • Define workforce accountability, including policy acknowledgment, training requirements, and a fair, consistent process when policies aren't followed. Work with HR, Legal, and IT Operations on the parts they own.
    Risk, incidents, and vendors
    • Lead incident response on the compliance side, including breach risk assessments, reportability decisions, and notifications to regulators and affected parties.
    • Own vendor risk management, including security reviews of new tools, BAA coverage, and documented data deletion when vendors are offboarded.
    • Set data governance standards for AI vendors, covering data residency, retention, zero-data-retention requirements, and the conditions for using de-identified data in model training.
    • Oversee privacy and consent for clinic-facing products, including in-clinic video, working with Product and Clinical.
    Security culture and FronteraCare operations
    • Build security and privacy practices that clinic staff actually follow, through training and simple guidance.
    • Prevent and catch shadow IT, especially tools that handle PHI (protected health information) without a BAA.
    • Run security awareness training and phishing simulations, and track completion across both entities.
    • Act as the go-to person for employees with security or privacy questions, so asking is easier than working around the rules.
    Customers and the business
    • Lead security and compliance reviews with customers and prospects, including questionnaires, BAA negotiations, and live calls. Bring in Engineering for deep technical questions.
    • Own our public trust center and the process for sharing the SOC 2 report.
    • Report on security and compliance posture to the executive team, and to the board when asked.
    Partnership with Engineering
    • Set security requirements for cloud infrastructure, access control, and device management. Engineering and IT implement and run those controls.
    • Review security architecture decisions, penetration test results, and vulnerability findings, and track them against the risk register.
    • Join product planning early so that HIPAA and SOC 2 requirements shape the design rather than being added after launch.
    Team and structure
    • Manage the transition from outside security support to an in-house function, and decide when to wind that support down.
    • Recommend how the security and compliance function should grow as FronteraCare scales, including whether to add headcount or use outside support.

Qualifications

  • 8-12 years of security/compliance experience, including hands-on work running SOC 2 audits against AWS cloud infrastructure — not managed a team that did, or partnered with engineering from a compliance-manager seat
  • Hands-on IAM architecture experience
  • Cloud security certification(s)
  • Has sat on security reviews directly with prospects or customers, and can speak to how those conversations went
  • Enterprise fluency — comfortable being the senior security presence in front of customers, partners, and boards

Preferred

  • Healthcare or regulated-industry background
  • Fractional CISO experience at a digital health company, especially if you're looking to move in-house
  • Security leadership at a Series B-D health tech company
  • An engineering background that grew into compliance ownership, with strong infrastructure or platform depth

We have determined a salary range for this position that takes into account several factors including experience, knowledge, education, skills, and abilities. Please note that the salary information is a general guideline and the exact salary will be determined based on the individual’s qualifications and experience, with consideration given to the factors listed above. All full-time employee benefits include a stake in shared success through stock options, health benefits, 401(k) plan, and 4 weeks of PTO per year.

This role is based in Denver, CO or remote within the US.

Expected Salary Range: $175,000 to $220,000

Why Frontera?

  • Opportunity to be at the forefront of innovation in pediatric healthcare.
  • Work on challenging and impactful projects that leverage cutting-edge technologies.
  • Collaborate with a talented and passionate team in a fast-paced and dynamic environment.
  • Make a real difference in the lives of children and families in rural communities.
  • Competitive salary and benefits package.
Our Denver Office & Perks
  • Dog-friendly office.
  • Catered lunch from local Denver restaurants five days a week, plus occasional breakfasts and dinners.
  • Robust snack program and great coffee options (including cappuccino machine and cold brew cans).
  • Regular team events and low-key socials.
  • Up to $150/month commuter stipend, discounted nearby parking, and a discounted Colorado Athletic Club membership.
  • Thoughtfully designed space for focus, collaboration, and connection.
  • Competitive health benefits, stock options, 401(k), and generous PTO.

Join us in building the future of behavioral healthcare!

Skills Required

  • 8–12 years of security and compliance experience
  • Hands-on experience running SOC 2 audits against AWS cloud infrastructure
  • Hands-on IAM architecture experience
  • Cloud security certification(s)
  • Experience participating directly in security reviews with prospects or customers
  • Enterprise fluency and ability to represent security before customers, partners, and boards
  • Healthcare or regulated-industry background
  • Fractional CISO experience at a digital health company
  • Security leadership at a Series B–D health technology company
  • Engineering background with infrastructure or platform depth and compliance ownership
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company

What We Do

Frontera Health is an AI-native platform and care delivery organization dedicated to scaling access to autism care. The company leverages AI/ML and digital phenotyping to provide clinical automation tools, such as diagnostic and assessment report builders, while also operating full-service ABA clinics in rural New Mexico. Its mission is to close the care gap and improve health equity for children with autism and related disorders.

Similar Jobs

CrowdStrike Logo CrowdStrike

Consultant

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
USA
11000 Employees
110K-160K Annually

CrowdStrike Logo CrowdStrike

Consultant

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
USA
11000 Employees
110K-160K Annually

PNC Bank Logo PNC Bank

Technology Solution Center Analyst Lead

Machine Learning • Payments • Security • Software • Financial Services
Remote or Hybrid
USA
55000 Employees
41K-83K Annually

Enverus Logo Enverus

Consultant

Big Data • Information Technology • Software • Analytics • Energy
In-Office or Remote
5 Locations
1800 Employees
95K-110K Annually

Similar Companies Hiring

Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees
Vega Thumbnail
Artificial Intelligence • Automotive • Insurance • Transportation
US
43 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account