MEDvidi Logo

MEDvidi

Information Security Officer

Posted 5 Hours Ago
Be an Early Applicant
Remote
Hiring Remotely in USA
Senior level
Remote
Hiring Remotely in USA
Senior level
Own and operate MEDvidi’s HIPAA security program, including risk management, remediation, administrative and technical safeguards, incident response, vendor security, policies, GRC operations, security architecture, and compliance monitoring. The role partners with IT, Privacy, Compliance, and leadership to protect ePHI, manage healthcare technology risks, coordinate penetration testing, conduct tabletop exercises, and maintain compliance with evolving HIPAA requirements.
The summary above was generated by AI
Description

MEDvidi is a multi-state telehealth practice delivering behavioral health and psychiatric services through a licensed Professional Corporation structure. As our organization and provider workforce continue to grow, protecting highly sensitive behavioral-health information and maintaining a strong, operational HIPAA security program are critical to our continued success.

We are seeking an experienced Information Security Officer (ISO) to own and operate MEDvidi's HIPAA Security Program.

About the Role

The Information Security Officer will have end-to-end ownership of MEDvidi's information security program, with particular responsibility for safeguarding electronic protected health information (ePHI).

You will inherit a completed Security Risk Analysis and be responsible for turning identified risks and recommendations into a sustainable operating program. This includes remediation execution, ongoing risk management, technical and administrative safeguards, vendor security, incident response, security policies, and security compliance.

This is a hands-on ownership role for someone comfortable independently running a security program in a lean, fast-moving healthcare environment.

Responsibilities
  • Serve as MEDvidi's designated HIPAA Security Official under 45 CFR § 164.308(a)(2).
  • Own the organization's security risk analysis and ongoing risk-management cycle, including maintaining the risk register and driving remediation items to closure.
  • Develop, operate, document, and maintain HIPAA administrative safeguards, including workforce security, access authorization, security awareness and training, incident procedures, and contingency planning.
  • Partner with IT to implement and maintain technical safeguards involving access controls, authentication, audit controls, data integrity, logging, and encryption of ePHI in transit and at rest.
  • Maintain security policies for MEDvidi's distributed workforce, including workstation security, device and media controls, and remote-work ePHI handling.
  • Own the security incident response process, including detection, containment, forensics coordination, documentation, and annual tabletop exercises.
  • Partner with the Privacy Officer on breach investigations and other areas where privacy and security requirements overlap.
  • Lead vendor and Business Associate security diligence, including security questionnaires, SOC 2/HITRUST reviews, subcontractor risk, and remediation of security findings.
  • Support security architecture and tooling decisions involving telehealth platforms, EHR access, endpoint management, logging, and SIEM coverage.
  • Review the security implications of AI tools and AI-assisted security and compliance processes used within the organization.
  • Manage and operate MEDvidi's GRC platform in partnership with Compliance leadership.
  • Monitor changes to the HIPAA Security Rule and help MEDvidi assess and implement new requirements as they become applicable.
Requirements
  • 6+ years of information security experience.
  • 2+ years of experience in healthcare or another regulated ePHI/PII environment.
  • Demonstrated hands-on ownership of a HIPAA security program or equivalent regulated security program; advisory-only experience is not sufficient.
  • Strong working knowledge of the HIPAA Security Rule.
  • Working knowledge of at least one relevant security/control framework, such as:
  • NIST Cybersecurity Framework (CSF) 2.0
  • NIST SP 800-66r2
  • HITRUST
  • Demonstrated ability to independently run a security program in a lean environment.
  • Strong risk-based prioritization, practical control implementation, and security documentation skills.

Preferred Qualifications

  • CISSP, HCISPP, CISM, or equivalent certification.
  • Experience securing telehealth platforms or other healthcare technology environments.
  • Cloud security experience with AWS, Azure, and/or GCP.
  • Experience leading security incident response.
  • Experience working with fractional or external security resources, penetration testers, and independent security advisors.
  • Familiarity with evolving HIPAA Security Rule requirements.

What Success Looks Like

During your first year, you will be expected to establish a mature, well-documented, and operational security program. Key outcomes include:

  • Closing Security Risk Analysis remediation items or placing them on documented, formally accepted remediation schedules.
  • Maintaining a security policy suite mapped to applicable HIPAA safeguards, with clear owners, review cadences, and evidence.
  • Testing the incident response plan through a tabletop exercise.
  • Maintaining workforce security training completion of at least 95%.
  • Completing security reviews for critical vendors handling ePHI.
  • Coordinating an annual penetration test and ensuring findings are incorporated into the remediation program.

Why Join MEDvidi?

This is an opportunity to take genuine ownership of information security within a growing multi-state behavioral healthcare organization. Rather than serving solely as an advisor, you will have the mandate to build, operate, improve, and demonstrate the effectiveness of the security program while working closely with Compliance, Privacy, IT, and organizational leadership.

If you are an experienced healthcare security professional who enjoys translating regulatory requirements and risk assessments into practical, sustainable security operations, we would like to hear from you.

Equal Opportunity Employer Statement

MEDvidi is an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees and contractors. All qualified applicants will receive consideration without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.

Similar Jobs

13 Days Ago
In-Office or Remote
240K-305K Annually
Expert/Leader
240K-305K Annually
Expert/Leader
Artificial Intelligence • Cloud • Consumer Web • eCommerce • Information Technology • Software
Leads the company-wide cybersecurity, compliance, governance, risk, and incident response programs across SaaS products, corporate systems, and cloud environments. Oversees security architecture, identity and access management, third-party risk, vulnerability management, audits, certifications, and customer assurance. Builds and manages global security teams, translates threats and regulatory requirements into business plans, and briefs executives and the board on security posture, incidents, risks, and investments.
Top Skills: AWSCcpaDevOpsGCPGdprIdentity And Access ManagementIso 27001MicroservicesPciSoc 2Sox
14 Days Ago
Remote or Hybrid
US
140K-175K Annually
Mid level
140K-175K Annually
Mid level
Information Technology
Performs IT audits and cybersecurity control validation for complex systems, applications, enclaves, and classified or unclassified networks. Assesses vulnerabilities, risks, security requirements, and mitigation effectiveness against Federal and DoD standards. Provides technical evaluations and recommends security improvements while balancing business needs with security concerns. Requires experience with RMF, DODI 8500.2 or NIST SP 800-53, eMASS, network implementation, and an active DoD Secret clearance.
Top Skills: Dodi 8500.2EmassMicrosoft AccessExcelMS OfficeMicrosoft PowerpointMicrosoft WordNetwork SecurityNist Sp 800-53Risk Management Framework (Rmf)
3 Days Ago
In-Office or Remote
Senior level
Senior level
Information Technology • Professional Services • Consulting • Cybersecurity
Serve as the cybersecurity subject matter expert for Assessment and Authorization processes. Assess threats, vulnerabilities, configurations, and risk; recommend mitigation controls; implement NIST RMF and ISO-aligned security practices; manage GRC documentation and accreditation activities; support cloud and enterprise security assessments; develop security architecture guidance; and coordinate initiatives with stakeholders and cross-functional teams.
Top Skills: Cloud ComputingGovernance Risk And Compliance (Grc) ToolsIso StandardsNetwork Scanning ToolsNist Risk Management Framework (Rmf)Security ArchitectureVulnerability Scanning Tools

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account