FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in leading HITRUST and SOC 2 Type II certifications, managing security compliance programs, and implementing security controls across cloud infrastructure. Proficient in assessing third-party risks and maintaining HIPAA security and privacy standards.
Highest-signal resume keywords
HITRUST Certification ManagementSOC 2 Type II Audit OwnershipHIPAA Security ComplianceGCP Cloud InfrastructureSecurity Program Development
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
HITRUST FrameworkSOC 2 FrameworkHIPAA Security RulesSecurity QuestionnairesControl MappingRisk AssessmentRemediation PlanningData Stack KnowledgeThird-Party Risk ReviewsSecurity Policy Development
Soft Skills
Judgment MakingLeadership CommunicationCollaboration with EngineeringStakeholder ManagementPrioritization
Tools & Technologies
GCPVantaDrataSecureframe
Certifications & Qualifications
CISSPCISACISMCRISC
Industry Keywords
Healthcare Information SecurityGovernance Risk CompliancePatient Health DataHealth TechDigital Health
Tech Stack
Tools & technologiesCloudGoogle Cloud Platform
About the role
Key responsibilities & impact- Lead HITRUST certification from kickoff through completion, including gap assessment, control mapping, remediation, and assessor management
- Own SOC 2 Type II end to end, including evidence collection, auditor relationship, and gap closure
- Maintain HIPAA security and privacy controls, core policies, and BAA obligations
- Review Leap’s security posture and deliver a prioritized improvement and tooling roadmap
- Roll out controls, policies, and processes across the company
- Partner with Engineering on implementation across GCP and the data stack
- Assess new vendors and tools, including AI tools
- Run ongoing third-party risk reviews
- Complete security questionnaires, RFP security sections, and controls reviews
- Determine security obligations in client and partner agreements
- Build a response library and repeatable review process
- Represent Leap with client and partner security teams
- Select and manage the external security partner
- Keep leadership informed on security posture, risk, and compliance status
- Flag areas where security investment is needed
Requirements
What you’ll need- 7+ years in healthcare information security, governance/risk/compliance (GRC), or IT audit
- Direct ownership of at least one full SOC 2 Type II audit cycle
- Deep familiarity with SOC 2, HIPAA, and HITRUST frameworks
- Experience building a security or compliance program from scratch, or owning one end to end as an early security hire at a startup or growth-stage company
- Hands-on experience completing security questionnaires and representing a company with enterprise or health plan security teams
- Working knowledge of HIPAA Security and Privacy Rules
- Experience handling patient health data (PHI) in B2B healthcare
- Technical depth in cloud infrastructure; GCP preferred
- Knowledge of modern data stacks
- Ability to review controls and advise engineers through implementation
- Comfort making judgment calls that commit the company
- Bonus: hands-on HITRUST certification experience
- Bonus: health tech, digital health, or benefits experience
- Bonus: experience with health plans and large self-funded employers
- Bonus: ISO 27001 experience
- Bonus: experience with Vanta, Drata, or Secureframe
- Bonus: CISSP, CISA, CISM, or CRISC certification
Benefits
Comp & perks- Equity/stock options
- Competitive total rewards package
- Benefits
- Equal opportunity employer committed to diversity of perspectives, experiences, and identities
- Application limit: up to 3 applications in any 90-day period
- Applicants not extended an offer may reapply to the same role after 60 days
