Senior Cybersecurity & Compliance Specialist

Posted Yesterday
Be an Early Applicant
Minneapolis, MN, USA
In-Office
120K-140K Annually
Senior level
Retail
The Role
Lead implementation and monitoring of cybersecurity controls and regulatory compliance (HITRUST, SOC2, HIPAA). Conduct risk assessments, support audits, manage security controls and incident response, evaluate threats, perform vendor/third-party risk assessments, maintain compliance documentation, and drive security awareness and governance across IT and business stakeholders.
Summary Generated by Built In

Amp Up Your Career

We are seeking a Senior Cybersecurity & Compliance Specialist who is ready to join an organization that combines passion and performance to shape a better world. As a Global Top Employer 2026, Amplifon is a place where your expertise improves lives and accelerates your career.

In this role, you will support the implementation, monitoring, and enforcement of cybersecurity measures and regulatory compliance across the organization, ensuring IT systems and processes align with internal policies, data protection laws, and industry standards like HITRUST r2 and SOC2 Type II. Key responsibilities include conducting risk assessments, supporting audits, managing security controls, incident response coordination, and promoting awareness to foster a culture of security and compliance throughout the organization.

Compensation: Based on qualifications we anticipate the hiring range will be $120,000-$140,000

Hybrid Work: We require team members to be in our downtown Minneapolis office three days per week, offering flexibility while fostering in-person collaboration.

Benefits Offered:

  • Health & Financial: Medical, Dental, Vision, 401(k) with company match, family hearing aid benefits, and tuition reimbursement.
  • Work-life Balance: Generous vacation, safe and sick leave, paid holidays, paid volunteer time off, parental leave and bereavement.
  • Well-being: Access to our Wellness Hub and Employee Assistance Program (EAP), providing holistic support for you and your family.
  • Career Development: Access to Ampli-Academy, LinkedIn Learning, Coursera, team training, and additional specialized training.
  • Commuter Support: Reimbursement for transportation (parking downtown, bus or train).

Key Responsibilities:

Cybersecurity & Risk Management

  • Implement and monitor cybersecurity controls to protect organizational systems and data.
  • Assist with risk assessments and security reviews to identify vulnerabilities and coordinate mitigation actions.
  • Develop and maintain the organization's cybersecurity posture in alignment with HITRUST r2 and SOC2 Type II frameworks.
  • Support threat detection, incident response, and timely reporting per regulatory timelines.
  • Monitor threat intelligence feeds and assist in evaluating emerging cyber threats.

Compliance & Regulatory Management

  • Ensure compliance with internal security policies and regulatory frameworks (e.g. HITRUST, SOC2, HIPAA, ISO 27001, CIS Controls and NIST CSF).
  • Maintain HITRUST and HIPPA controls including supply chain security, vulnerability management, and business continuity planning.
  • Support internal and external audits by gathering evidence, providing documentation, and tracking remediation efforts.
  • Manage the lifecycle of compliance documentation and maintain accurate, up-to-date records of security controls and procedures.
  • Monitor regulatory changes and apply new compliance obligations.

Governance & Stakeholder Collaboration

  • Partner with IT, business stakeholders, and vendors to embed security and compliance requirements into processes, projects and procurement activities.
  • Conduct vendor risk assessments and third-party evaluations to satisfy HITRUST & SOC2 supply chain compliance.
  • Participate in governance committees and security steering groups to provide compliance insights and recommendations.
  • Support security training and awareness initiatives to foster a culture of compliance and accountability.

Required Qualifications:

  • 5+ years of professional experience in cybersecurity, IT compliance, IT risk management, or IT audit roles.
  • Solid knowledge of cybersecurity frameworks and standards (e.g., HITRUST CSF, ISO 27001, NIST CSF, CIS Controls) and relevant healthcare regulations (e.g., HIPAA).
  • Familiarity with risk assessment methodologies, security monitoring tools, audit processes, vulnerability management, and incident response procedures.
  • Knowledge of supply chain security and third-party risk management practices.
  • Strong organizational and documentation skills, an analytical mindset, and exceptional attention to detail.
  • Good communication and interpersonal skills to work effectively with cross functional teams and external auditors. 
  • Ability to work independently and manage multiple priorities in a dynamic environment.

Preferred Qualifications:

  • Relevant professional certifications such as Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), or HITRUST CSFP. 
  • Direct experience with compliance management platforms and GRC (Governance, Risk & Compliance) tools.
  • Demonstrated ability to lead technology risk changes across a large organization.
  • Knowledge of healthcare industry regulations and data protection requirements.

Amplifon is the global leader in the hearing care retail market, empowering people to rediscover all the emotions of sound. With a presence in 25 countries and 20,300 employees worldwide, we are a team of diverse, innovative talent dedicated to improving lives through customer experience.

Amplifon Americas, headquartered in Minneapolis, MN, supports Amplifon Canada, Amplifon Hearing Health Care, GAES, and Miracle-Ear bridging retail and insurance industries to provide comprehensive hearing well-being across Canada, LATAM, and the United States.

Please note that AI tools may be used to assist in resume screening. All hiring decisions are made by our recruitment team.

We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. If selected for an interview, please advise our Human Resources team if you require accommodation during the interview and assessment process and we will work with you to meet your accessibility needs.

Candidates must be authorized to work in the United States on a full-time basis without the need for current or future sponsorship. This role is not eligible for visa sponsorship, including but not limited to OPT, CPT, or H-1B.

#IND1

Skills Required

  • 5+ years professional experience in cybersecurity, IT compliance, IT risk management, or IT audit
  • Solid knowledge of HITRUST CSF, SOC2, HIPAA, ISO 27001, NIST CSF, and CIS Controls
  • Familiarity with risk assessment methodologies, security monitoring tools, vulnerability management, and incident response procedures
  • Knowledge of supply chain security and third-party/vendor risk management practices
  • Strong organizational and documentation skills, analytical mindset, and attention to detail
  • Good communication and interpersonal skills to work with cross-functional teams and external auditors
  • Ability to work independently and manage multiple priorities in a dynamic environment
  • Relevant certifications such as CISA, CISM, or HITRUST CSFP
  • Direct experience with compliance management platforms and GRC tools
  • Demonstrated ability to lead technology risk changes across a large organization
  • Knowledge of healthcare industry regulations and data protection requirements

Amplifon Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Amplifon and has not been reviewed or approved by Amplifon.

  • Strong & Reliable Incentives Performance-related bonuses and commission structures can meaningfully lift total earnings in some sales and clinic roles. Incentives appear more favorable for high performers where targets are attainable and variable pay is a consistent part of the package.
  • Healthcare Strength Health coverage is described as comprehensive in many markets, often including core medical needs and hearing-related care. Added supports such as EAP/psychological counseling and wellness programs broaden the health-and-wellbeing value of the package.
  • Leave & Time Off Breadth Time-off offerings are frequently characterized as generous in parts of Europe, with substantial PTO allowances and additional leave provisions in some locations. Flexibility options such as hybrid arrangements further increase the perceived value of time-related benefits.

Amplifon Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Milan, Milan
10,034 Employees
Year Founded: 1950

What We Do

As the global leader in the hearing care retail industry, we have been changing the lives of millions of customers across the globe since 1950. With stores and offices spanning across 26 countries and a team of 20,300 dedicated professionals, we take pride in setting the industry standard as we empower people to rediscover all the emotions of sound. Although we are constantly growing, we have the drive of a start-up and are committed to striving for innovation every day. Whatever role our employees take on at Amplifon, they each make more possible - more brands for customers, more support for colleagues, more opportunities for their own careers and more innovative possibilities. We are guided by our values and are motivated by our purpose, ensuring each new day brings opportunities for innovation as we explore new horizons for our business, our customers and each other. At Amplifon, we make more possible. Amplifon operates in: Argentina, Australia, Belgium, Canada, Chile, China, Colombia, Ecuador, Egypt, France, Germany, Hungary, India, Israel, Italy, Mexico, New Zealand, Panama, Poland, Portugal, Spain, Switzerland, the Netherlands, UK, United States, and Uruguay. Read our Netiquette and help us create an inclusive environment to interact within: https://corporate.amplifon.com/en/netiquette?formSearchPage=true

Similar Jobs

Identity Digital Logo Identity Digital

Staff Devops Engineer

Consumer Web • eCommerce • Internet of Things
Remote or Hybrid
United States
240 Employees
175K-220K Annually

MetLife Logo MetLife

Senior Consultant

Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Remote or Hybrid
United States
43000 Employees
121K-149K Annually

MetLife Logo MetLife

Software Engineer

Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Remote or Hybrid
United States
43000 Employees
210K-210K Annually

PwC Logo PwC

Architect

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
53 Locations
370000 Employees
99K-232K Annually

Similar Companies Hiring

Grocery TV Thumbnail
Software • Retail • Marketing Tech • Hardware • Digital Media • AdTech
Austin, TX
56 Employees
Scotch Thumbnail
Artificial Intelligence • eCommerce • Fintech • Payments • Retail • Software • Analytics
US
35 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account