Cyber Security Lead

Mednition
  • Burlingame, CA
  • $165,000–$215,000
4 days ago

Job Description

Mednition, Inc.

Cyber Security Lead

 

Position Overview:

The Cyber Security Manager is responsible for building, maintaining, and continuously improving the Mednition Information Security Program across our AI SaaS platform (including KATE Triage and KATE Sepsis). This role involves managing the Governance, Risk, and Compliance (GRC) program, overseeing HIPAA compliance and SOC2 Type 2 certification audits, supervising Google Cloud Platform (GCP) and MongoDB Atlas security architectures, and ensuring security across EHR integrations (HL7, FHIR). The Cyber Security Manager will also support regulatory alignment with FDA SaMD guidelines, NIST AI Risk Management Framework, and predetermined change control plans.

 

Key Responsibilities:

  • Build, maintain, and continuously improve the Mednition Information Security Program, including developing and implementing policies, processes, and procedures to protect the organization's information systems and data.

  • Manage the GRC program, including the development of policies, processes, and procedures to ensure compliance with regulatory requirements and industry standards.

  • Oversee the IT Security Program across cloud environments, Kubernetes clusters, and MongoDB Atlas databases, including continuous monitoring, SIEM, security architecture, and vulnerability assessments.

  • Supervise security monitoring operations, including vulnerability and threat assessments, network access control, incident response, and maintenance activities.

  • Support briefings and meetings with key stakeholders, providing recommendations to development teams regarding security best practices and requirements.

  • Ensure compliance with HIPAA, SOC2 Type 2 audits, FDA SaMD cybersecurity requirements, and NIST AI Risk Management Framework standards.

  • Effectively communicate and collaborate with internal and external key stakeholders, such as senior management, IT teams, customer security teams, vendors, and auditors.

  • Manage secure data integration architectures for HL7/FHIR EHR data pipelines, ensuring proper handling and protection of Patient Health Information (PHI).

  • Stay updated with the latest cyber security trends, threats, and technologies, and evaluate their applicability to the organization's security program.

  • Foster a culture of security awareness and compliance throughout the organization, promoting the importance of information security and privacy.

  • Collaborate with cross-functional teams to implement security controls, mitigate risks, and address security-related issues and incidents.

Required Skills/Abilities:

  • Proven experience in managing information security programs and teams.

  • Strong understanding of governance, risk management, and compliance principles and practices.

  • In-depth knowledge of cloud cybersecurity operations (GCP, MongoDB Atlas, Cloud Run, Kubernetes), container security, CI/CD pipeline security, and SIEM.

  • Familiarity with healthcare data privacy and security standards (HIPAA, SOC2 Type 2, FDA SaMD regulations, NIST AI RMF, and HL7/FHIR security protocols).

  • Excellent communication and collaboration skills, with the ability to effectively engage with stakeholders at all levels.

  • Strong project management and organizational skills, with the ability to prioritize tasks and manage multiple initiatives.

  • Experience in working with security audit processes and frameworks.

  • Commitment to staying up-to-date with industry trends and advancements in the field of cyber security.

Education and Experience:

  • Bachelor's degree in computer science, information security, or a related field. A master's degree is preferred.

  • Relevant certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or Certified Ethical Hacker (CEH).

 

Physical Requirements:

  • Prolonged periods of sitting at a desk and working on a computer.

  • Must be able to lift 15 pounds at times.

Other Requirements:

  • Does not now, or in the future, require sponsorship for employment visa status (e.g. H-1B visa status)

Numbers & Facts

LocationBurlingame, CA
Salary$165,000–$215,000

Skills

  • Artificial Intelligence (AI)unmatched
  • Artificial Intelligence (AI) Programming Languagesunmatched
  • Auditingunmatched
  • Best Practicesunmatched
  • CEH - Certified Ethical Hackerunmatched
  • CISM - Certified Information Security Managerunmatched
  • CISSP - Certified Information Systems Security Professionalunmatched
  • Change Controlunmatched
  • Cloud Computingunmatched
  • Communication Skillsunmatched
  • Computer Scienceunmatched
  • Computer Securityunmatched
  • Continuous Deployment/Deliveryunmatched
  • Continuous Improvementunmatched
  • Continuous Integrationunmatched
  • Cross-Functionalunmatched
  • Data Managementunmatched
  • Establish Prioritiesunmatched
  • FDA Requirementsunmatched
  • GCP (Good Clinical Practices)unmatched
  • HIPAA (Health Insurance Portability and Accountability Act)unmatched
  • HL7 (Health Level 7)unmatched
  • Healthcareunmatched
  • Incident Responseunmatched
  • Industry Standardsunmatched
  • Industry/Trade Analysisunmatched
  • Information Technology & Information Systemsunmatched
  • Information/Data Security (InfoSec)unmatched
  • Internet Securityunmatched
  • Maintain Complianceunmatched
  • Medical Record Systemunmatched
  • Medical Recordsunmatched
  • MongoDBunmatched
  • Network Access Control (NAC)unmatched
  • Operations Managementunmatched
  • Organizational Skillsunmatched
  • Physical Demandsunmatched
  • Policy Developmentunmatched
  • Policy Implementationunmatched
  • Privacy Controlsunmatched
  • Procedure Developmentunmatched
  • Project/Program Managementunmatched
  • Regulatory Complianceunmatched
  • Regulatory Requirementsunmatched
  • Riskunmatched
  • Risk Managementunmatched
  • Risk Management Framework (RMF)unmatched
  • Security Architectureunmatched
  • Security Attacksunmatched
  • Security Auditingunmatched
  • Security Information and Event Management (SIEM)unmatched
  • Security Monitoringunmatched
  • Security Protocolsunmatched
  • Software as a Service (SaaS)unmatched
  • Team Playerunmatched
  • Trend Analysisunmatched
  • U.S. National Institute of Standards and Technology (NIST)unmatched
  • Vendor/Supplier Evaluationunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder