Jobs · Information Technology

Chief Information Security Officer

HendrenAI · New Jersey, United States · 1 mo ago
RemoteRemoteInformation TechnologyFull-time

Location: Hybrid for candidates within commutable distance of our Montvale, NJ office. Fully remote options are also available for candidates based anywhere in New Jersey.

Team: Security (reporting to the CEO)
Type: Full-time
Travel: Occasional, for audits, customer security reviews, and industry events

About HendrenAI

HendrenAI builds voice automation, AI agents, and large language model solutions purpose-built for the healthcare ecosystem. Our platform automates inbound and outbound workflows across pharmacy operations, scheduling, insurance verification, and billing, with deep integrations into pharmacy management systems (Liberty/RedSail) and leading EHR platforms (Epic, athenahealth). We operate on HIPAA-, SOC 2-, and HITECH-compliant infrastructure, and we serve pharmacies, health systems, and pharmaceutical companies.

Role Overview

We’re looking for a Chief Information Security Officer to own and lead security, privacy, and compliance across HendrenAI. As the executive accountable for protecting sensitive healthcare data, you’ll define our security strategy, mature our HIPAA, SOC 2, and HITECH programs, and serve as the trusted authority for customers, partners, and auditors. This is a hands-on leadership role at a company where enterprise-grade security is central to the product and the sale; you’ll build the security function and embed it into how we operate.

Responsibilities

  • Define and own the company-wide information security strategy, roadmap, and policies
  • Lead and mature HIPAA, HITECH, and SOC 2 compliance programs, including audits, evidence, and continuous monitoring
  • Establish and enforce security controls across infrastructure, applications, data, and endpoints
  • Own risk management like identify, assess, prioritize, and remediate security and privacy risks
  • Lead incident response planning and execution, including detection, containment, and post-incident review
  • Serve as the security authority in customer and partner security reviews, questionnaires, and contract negotiations
  • Oversee vendor and third-party risk management
  • Build security awareness and training programs across the organization
  • Ensure secure handling of PHI and sensitive data across all integrations (Epic, athenahealth, Liberty/RedSail)
  • Advise executive leadership and the board on security posture, risk, and investment
  • Build and lead the security team as the organization scales

Requirements

  • 10+ years of information security experience, including senior security leadership (CISO, Director/VP of Security, or equivalent)
  • Deep expertise in healthcare security and compliance frameworks: HIPAA, HITECH, and SOC 2
  • Proven experience building and running security and compliance programs from the ground up
  • Strong knowledge of cloud security, application security, identity/access management, and data protection
  • Experience leading incident response and risk management in a regulated environment
  • Excellent communication skills, able to serve as the security authority for customers, auditors, and the board
  • Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent practical experience

Preferred Qualifications

  • Relevant certifications (e.g., CISSP, CISM, CCSP, HCISPP)
  • Experience in health tech, digital health, or handling PHI at scale
  • Familiarity with EHR (Epic, athenahealth) and pharmacy management systems (Liberty/RedSail)
  • Experience supporting enterprise and health-system procurement and security review processes
  • Experience at an early- or growth-stage company building the security function early

Why Join Us

HendrenAI is bringing modern voice AI and agentic automation to a healthcare system still buried in manual administrative work. As CISO, you'll own the security posture that makes trusted healthcare AI possible, protecting patient data and enabling every enterprise deal. You’ll join with a proven product and existing compliance foundation, with the ownership and upside that come from building the security function at a defining stage.

Similar jobs