Compliance Manager, IT Security

Midi Health
Summary
Join Midi Health as their Compliance Manager and lead the implementation of key IT governance and security-related compliance strategies. You will ensure alignment with industry standards and internal policies, enhancing operational resilience and data security. Responsibilities include preparing for and leading IT governance meetings, conducting risk assessments, developing business continuity testing scenarios, managing vendor relationships, and driving SOC II or related certification processes. This critical role strengthens Midi Health's security posture and ensures adherence to HIPAA and other regulatory standards. The ideal candidate possesses a Bachelor's degree in a related field, relevant certifications (CISSP, CISM, or CISA are highly regarded), and strong knowledge of IT governance, risk management, and compliance frameworks. Exceptional attention to detail, analytical skills, and communication abilities are essential.
Requirements
- Bachelorβs degree in Information Technology, Cybersecurity, or a related field
- Strong knowledge of IT governance, risk management, and compliance frameworks
- Exceptional attention to detail, analytical skills, and communication abilities
- Ability to collaborate cross-functionally and drive security initiatives
Responsibilities
- Prepare for and lead IT governance meetings, providing follow-up reporting on action items and decisions
- Conduct risk assessments, track remediation efforts, and oversee HIPAA incident resolution
- Develop and lead business continuity testing scenarios, present findings, and drive necessary follow-ups
- Manage vendor relationships, complete annual certifications, and ensure compliance with organizational needs
- Drive SOC II or related certification processes through gap analysis and certification efforts
- Strengthen security posture by implementing proactive governance strategies
- Conduct access and certificate verification to maintain a robust security framework
- Ensure adherence to HIPAA, cybersecurity frameworks, and other regulatory standards
Preferred Qualifications
Relevant certifications such as CISSP, CISM, or CISA