Information & Security Program Manager

Posted 2 Days Ago
Hiring Remotely in United States
Remote
130K-130K Annually
Senior level
Healthtech • Information Technology • Software
The Role
The Information Security Program Manager will lead internal compliance and security programs, ensuring adherence to regulations like HIPAA and SOC 2, while developing security strategies and managing audits.
Summary Generated by Built In

About Medicom

Medicom is a leading enterprise imaging software company that solves longstanding interoperability challenges for clinicians, staff, patients, and researchers. Its core platform, Connect, supports diverse enterprise imaging interoperability use cases. These include access to prior and unread imaging studies, point-of-care workflows, patient access to images, orders and results workflows for teleradiology, telestroke and trauma, and cross-institution sharing of digital imaging. Medicom's Network is adopted by over 1,000 US healthcare institutions and backed by leading venture capital firms, such as UPMC Enterprises. Data and insights from the Medicom Connect network drive Medicom's Intellect offering, which helps clinicians and researchers advance patient care and develop new therapies.

About the role

Medicom is seeking an Information Security Program Manager to join our Compliance team and lead the company’s information security and regulatory compliance programs. As a healthcare data company, Medicom must meet the highest standards for data protection while supporting rapid product development and growth.


In this role, you will own Medicom’s internal compliance programs and partner closely with Engineering and cross-functional leaders to ensure security and compliance are embedded into our products, systems, and processes. You will play a critical role in maintaining HIPAA compliance while preparing the organization for additional frameworks such as SOC 2, GDPR, and FedRAMP.


What you'll do

  • Own and lead Medicom’s internal compliance and security programs, ensuring ongoing adherence to HIPAA, HITRUST, GDPR, SOC 2, and other evolving regulatory frameworks and standards.
  • Partner closely with the Engineering team to incorporate security and compliance requirements into product design, feature development, and system architecture.
  • Develop, maintain, and clearly communicate to internal and external stakeholders Medicom’s information security program, including controls, risk areas, and known limitations.
  • Lead preparation for new compliance certifications and readiness efforts (e.g., SOC 2 Type 2, GDPR certification, FedRAMP readiness). 
  • Serve as the primary coordinator for the Confidentiality & Security Team (CST), including agenda setting, monthly meetings, and executive-level reporting.
  • Manage all aspects of SOC 2 audits, including coordination with third-party auditors and internal stakeholders.
  • Act as a trusted internal advisor, providing guidance, education, and support on compliance and security-related topics across the organization.
  • Monitor changes in relevant laws, regulations, and industry standards, recommending and implementing updates to internal policies and processes.

Qualifications

  • 8+ years of experience in compliance, information security, privacy, or risk management, preferably within healthcare, health tech, or SaaS environments.
  • CISSP (Certified Information Systems Security Professional) certification strongly preferred or other advanced technical security certifications (e.g. Information Systems Security Architecture Professional, Information Systems Security Engineering Professional) 
  • Strong working knowledge of industry frameworks and federal, regional, and state regulations such as HIPAA, SOC 2, CCPA, and GDPR; experience with FedRAMP is a plus.
  • Proven ability to interpret complex regulatory requirements and translate them into practical, actionable guidance.
  • Experience leading external audits, certifications, or regulatory assessments.
  • Excellent documentation, organizational, and program management skills.
  • Strong written and verbal communication skills, with the ability to align cross-functional stakeholders.
  • Comfortable working independently and proactively in a fast-paced, growing organization.


Equal Opportunity Employer Statement

Medicom Technologies is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.


Reasonable Accommodation Notice

If you require a reasonable accommodation in the application process, please contact [email protected] to discuss your needs.


Salary

Starting at $130k

Top Skills

Fedramp
Gdpr
Hipaa
Hitrust
Soc 2
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Raleigh, North Carolina
64 Employees
Year Founded: 2015

What We Do

We created the first federated health information network: a powerful platform that connects disparate data silos through a single interface. The value of a health information network is dependent on the willing participation of providers, hospitals, and imaging centers in a community.

While technology can support the adoption of health information networks — from large hospitals and IDNs to private practices alike — the technology on its own has little to no value. Many medical image sharing solutions and health information networks are implemented within an organization’s walls, without considering how to support and connect providers in the community.

Medicom has taken the unique approach to better serve providers by building health information networks with service and support organizations that are experts on their local communities. These service and support organizations provide local resources to hospitals around the United States, with teams who are familiar with their customers, and able to quickly and efficiently establish community-based solutions.

Similar Jobs

Square Logo Square

Account Executive

eCommerce • Fintech • Hardware • Payments • Software • Financial Services
Remote or Hybrid
8 Locations
12000 Employees
84K-104K Annually

Square Logo Square

Account Executive

eCommerce • Fintech • Hardware • Payments • Software • Financial Services
Remote or Hybrid
8 Locations
12000 Employees
84K-104K Annually

Square Logo Square

Senior Machine Learning Engineer

eCommerce • Fintech • Hardware • Payments • Software • Financial Services
Remote or Hybrid
8 Locations
12000 Employees
161K-284K Annually

Rapid7 Logo Rapid7

Revenue Operations Manager

Artificial Intelligence • Cloud • Information Technology • Sales • Security • Software • Cybersecurity
Remote or Hybrid
Boston, MA, USA
2400 Employees
88K-120K Annually

Similar Companies Hiring

Scotch Thumbnail
Software • Retail • Payments • Fintech • eCommerce • Artificial Intelligence • Analytics
US
25 Employees
Milestone Systems Thumbnail
Software • Security • Other • Big Data Analytics • Artificial Intelligence • Analytics
Lake Oswego, OR
1500 Employees
Fairly Even Thumbnail
Software • Sales • Robotics • Other • Hospitality • Hardware
New York, NY

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account