Information Security Officer
Medvidi
MEDvidi is a multi-state telehealth practice delivering behavioral health and psychiatric services through a licensed Professional Corporation structure. As our organization and provider workforce continue to grow, protecting highly sensitive behavioral-health information and maintaining a strong, operational HIPAA security program are critical to our continued success.
We are seeking an experienced Information Security Officer (ISO) to own and operate MEDvidi's HIPAA Security Program.
About the Role
The Information Security Officer will have end-to-end ownership of MEDvidi's information security program, with particular responsibility for safeguarding electronic protected health information (ePHI).
You will inherit a completed Security Risk Analysis and be responsible for turning identified risks and recommendations into a sustainable operating program. This includes remediation execution, ongoing risk management, technical and administrative safeguards, vendor security, incident response, security policies, and security compliance.
This is a hands-on ownership role for someone comfortable independently running a security program in a lean, fast-moving healthcare environment.
Responsibilities:- Serve as MEDvidi's designated HIPAA Security Official under 45 CFR § 164.308(a)(2).
- Own the organization's security risk analysis and ongoing risk-management cycle, including maintaining the risk register and driving remediation items to closure.
- Develop, operate, document, and maintain HIPAA administrative safeguards, including workforce security, access authorization, security awareness and training, incident procedures, and contingency planning.
- Partner with IT to implement and maintain technical safeguards involving access controls, authentication, audit controls, data integrity, logging, and encryption of ePHI in transit and at rest.
- Maintain security policies for MEDvidi's distributed workforce, including workstation security, device and media controls, and remote-work ePHI handling.
- Own the security incident response process, including detection, containment, forensics coordination, documentation, and annual tabletop exercises.
- Partner with the Privacy Officer on breach investigations and other areas where privacy and security requirements overlap.
- Lead vendor and Business Associate security diligence, including security questionnaires, SOC 2/HITRUST reviews, subcontractor risk, and remediation of security findings.
- Support security architecture and tooling decisions involving telehealth platforms, EHR access, endpoint management, logging, and SIEM coverage.
- Review the security implications of AI tools and AI-assisted security and compliance processes used within the organization.
- Manage and operate MEDvidi's GRC platform in partnership with Compliance leadership.
- Monitor changes to the HIPAA Security Rule and help MEDvidi assess and implement new requirements as they become applicable.
REQUIREMENTS
- 6+ years of information security experience.
- 2+ years of experience in healthcare or another regulated ePHI/PII environment.
- Demonstrated hands-on ownership of a HIPAA security program or equivalent regulated security program ; advisory-only experience is not sufficient.
- Strong working knowledge of the HIPAA Security Rule .
- Working knowledge of at least one relevant security/control framework, such as:
- NIST Cybersecurity Framework (CSF) 2.0
- NIST SP 800-66r2
- HITRUST
- Demonstrated ability to independently run a security program in a lean environment.
- Strong risk-based prioritization, practical control implementation, and security documentation skills.
- CISSP, HCISPP, CISM, or equivalent certification.
- Experience securing telehealth platforms or other healthcare technology environments.
- Cloud security experience with AWS, Azure, and/or GCP.
- Experience leading security incident response.
- Experience working with fractional or external security resources, penetration testers, and independent security advisors.
- Familiarity with evolving HIPAA Security Rule requirements.
- Closing Security Risk Analysis remediation items or placing them on documented, formally accepted remediation schedules.
- Maintaining a security policy suite mapped to applicable HIPAA safeguards, with clear owners, review cadences, and evidence.
- Testing the incident response plan through a tabletop exercise.
- Maintaining workforce security training completion of at least 95% .
- Completing security reviews for critical vendors handling ePHI.
- Coordinating an annual penetration test and ensuring findings are incorporated into the remediation program.
Preferred Qualifications
What Success Looks Like
During your first year, you will be expected to establish a mature, well-documented, and operational security program. Key outcomes include:
Why Join MEDvidi?
This is an opportunity to take genuine ownership of information security within a growing multi-state behavioral healthcare organization. Rather than serving solely as an advisor, you will have the mandate to build, operate, improve, and demonstrate the effectiveness of the security program while working closely with Compliance, Privacy, IT, and organizational leadership.
If you are an experienced healthcare security professional who enjoys translating regulatory requirements and risk assessments into practical, sustainable security operations, we would like to hear from you.
Equal Opportunity Employer Statement
MEDvidi is an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees and contractors. All qualified applicants will receive consideration without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.
$250.44k - $375.67k
...Proof of Reserves. Across our multiple offices globally, we are united by our core principles... ...the opportunityWe're looking for a security leader for the Americas who's equally comfortable... ...regardless of race, color, genetic information, creed, religion, sex, sexual...Suggested- ...Chief Information Security Officer (CISO) About the Company Innovative provider of data safety & recovery solutions Industry Information Technology and Services Type Privately Held Founded 2024 Employees 51-200 Specialties cloud backup...Suggested
- ...Chief Information Security Officer (CISO), Growth About the Company Accomplished provider of top-tier security services Industry Security and Investigations Type Privately Held About the Role The Company is seeking a Chief Information Security...Suggested
- ...grow, protecting highly sensitive behavioral-health information and maintaining a strong, operational HIPAA security program are critical to our continued success.... ...are seeking an experienced Information Security Officer (ISO) to own and operate MEDvidi's HIPAA Security...SuggestedFor contractorsFor subcontractorRemote work
- ...Deputy Chief Information Security Officer (CISO), Security Technology About the Company Popular provider of revenue cycle management solutions Industry Hospital & Health Care Type Privately Held, Private Equity-backed Founded 2003 Employees...Suggested
- ...Chief Information Security Officer (CISO), Information Security & Compliance About the Company Innovative artificial intelligence (AI) & marketing analytics platform Industry Information Technology and Services Type Public Company Founded 2014...
- ...Deputy Chief Information Security Officer (CISO) About the Company Industry-leading cybersecurity platform Industry Computer & Network Security Type Privately Held, VC-backed Founded 2019 Employees 201-500 Funding $200+ million Categories...
- ...Field Chief Information Security Officer (CISO) About the Company Industry leading provider of security & compliance solutions Industry Outsourcing/Offshoring Type Privately Held Founded 2020 Employees 501-1000 Funding $200+ million Categories...Remote work
- ...Chief Information Security Officer (CISO) About the Company Innovative cybersecurity ratings platform Industry Information Technology and Services Type Privately Held, VC-backed Founded 2012 Employees 201-500 Funding $26-$50 million Categories...Remote work
- ...Staff Product Security Engineer - Vulnerability Manager The Product Security team within Johnson & Johnson’s Information Security & Risk Management (ISRM) is recruiting for a full-time Staff Product Security Engineer to join the ISRM Product Security-JJSV team to provide...Full time
$243k - $365k
...Verily is seeking a passionate and experienced leader for the company’s centralized Security organization. The scope of Security encompasses security and privacy engineering, information security, and governance, risk, and compliance, in support of a wide range of...Full timeWork experience placement- ...Chief Trust Officer (CTO) About the Company Highly respected wealth management firm with boutique, client-centric service for sophisticated families. Industry Financial Services Type Privately Held About the Role The Company is in search of a Chief...
- ...Deputy Chief Information Security Officer (CISO) About the Company Prominent cyber security platform Industry Computer & Network Security Type Public Company Founded 2000 Employees 10,001+ Categories Network Security Cyber Security...
- ...gender, marital status, sexual orientation and identity, genetic information, veteran status, citizenship, or any other factors prohibited... ...law.Compensation Range: $271K - $425KLocationSan Francisco Office (Second St); Bellevue Office; San Jose Office (Zanker)Employment...Work at officeLocal areaFlexible hours
$189k - $260k
Who We AreApplied Materials is a global leader in materials engineering solutions used to produce virtually every new chip and advanced display in the world. We design, build and service cutting-edge equipment that helps our customers manufacture display and semiconductor...Full time$197.5k - $316k
Please Note:1. If you are a first time user, please create your candidate login account before you apply for a job. (Click Sign In > Create Account)2. If you already have a Candidate Account, please Sign-In before you apply.Job Description:WSD is a world leader in advanced...Full timeLocal area- ...Chief Impact Officer (CIO) About the Company Large-scale food bank serving 450,000 individuals per month Industry Non-Profit Organization Management Type Non Profit Founded 1974 Employees 201-500 Categories Retail Non-Profit & Philanthropy...Temporary work
$80k - $86k
...,United States Base Pay $80,000.00 - $86,000.00 / Year Other Compensation Bonus Potential Employee Type Full Time Exempt Contact information Name Hiring Manager Email ****@*****.*** Description Chiropractor (DC) – Fast-Growing Chiropractic Clinic | The...Full timePart timeFlexible hours$200k - $230k
...detailsTitle of position: Innovation Lead - Office of the CTOPosition type: Full time -... ...networking, committed to simplifying and securing IT operations through its unified... ...Extreme Networks does not seek salary history information from applicants and will not rely on salary...Full timeH1bWork at officeLocal areaRemote workWork from homeWorldwideWork visa- ...management and data protection solutions at the heart of digital security. Business and governments rely on us to bring trust to the... ...grant access to digital services, analyze vast quantities of information and encrypt data to make the connected world more secure.Position...Full timeLocal areaRemote workDay shiftAfternoon shift
- ...a Prisma AIRS business unit aligned Domain Consultant for AI Security, you provide technical expertise and guidance in securing customers... ...or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical...Full timeRemote work
- ...Managing Director, Chief Technology Officers Practice, Retained Search About the Company Dynamic executive search firm specializing... .... The position is pivotal in helping clients make informed leadership decisions and is suited to individuals who thrive in...
- ...Deputy Chief Technology Officer (CTO) About the Company Prominent political organization... ...the Chief Technology Officer, Chief Security Officer, and Heads of Data & Engineering... ...Technology Officer Functions Engineering Information Technology ConfidentialRemote work
- ...Regional Field Chief Technology Officer (CTO) About the Company Globally recognized provider of automated solutions for securing & managing open source software Industry... ...ability to translate complex technical information into clear narratives for both technical...
- Ernst & Young U.S. LLP in San Jose, CA, seeks an Assurance - Technology Risk Manager for multiple openings. This full-time role involves planning and performing IT audit and attestation work with 40-hour weeks, and up to travel as needed. The position requires 5 years ...Full time
- Company DescriptionIDEALFORCE has a Contract position available immediately for a Information Security Program Manager to join our customer in Santa Clara, CA. This is an ONSITE position. Please find below additional details about this job. Kindly respond with your most...Contract workImmediate start
- ...Chief Technology Officer (CTO) About the Company Global talent marketplace connecting businesses with top freelance professionals... ...2010 Employees 1001-5000 Categories Technology Information Technology & Services Internet Business Services Career...FreelanceRemote work
- ...Chief Technology Officer (CTO) About the Company Prominent financial services firm specializing in investment management, research... ...be responsible for the delivery of cloud-native applications, secure infrastructure, and automation pipelines to support agile product...
- ...Chief Technology Officer (CTO) About the Company Builds a proactive smart assistant... ...engineering standards for reliability, security, performance, testing, and code quality.... ...daily lives of its users. Functions Engineering Information Technology Confidential
- ...Chief Technology Officer (CTO) About the Company Venture-backed fintech startup.... ...responsible for ensuring the reliability, security, and scalability of the products, as well... ...cutting-edge technology. Functions Engineering Information Technology Confidential
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Information Security Officer. Be the first to apply!
- information security San Jose, CA
- sr information security engineer San Jose, CA
- entry level information security analyst San Jose, CA
- senior information security analyst San Jose, CA
- data center security officer San Jose, CA
- information security lead San Jose, CA
- director information security San Jose, CA
- information technology security engineer San Jose, CA
- information security officer
- information security officer iso


