IT Security & Compliance Lead (Healthcare)
Premium Health Center · Brooklyn, NY · 2 mo ago
Information TechnologyFull-time
Responsibilities
- Own and operate the organization’s security program, ensuring policies, procedures, and controls are consistently implemented
- Maintain and update security policies, standards, and procedures
- Ensure alignment with regulatory and organizational requirements
- Support ongoing maturation of the organization’s security posture and controls framework, including alignment with industry-standard practices such as NIST
- Stay current on emerging cybersecurity threats, vulnerabilities, technologies, AI-related risks, and evolving industry best practices, proactively identifying opportunities to strengthen the organization’s security posture and risk management capabilities
- Administer and support security technologies and operational controls across the environment, including email security, endpoint protection, identity and access management, MFA, conditional access, DLP, and firewall/security platforms
- Configure, tune, monitor, and maintain security rules, alerts, policies, and protections across Microsoft 365, SaaS, endpoint, and network security platforms in collaboration with internal IT teams and external security partners
- Support email security administration, including phishing protection, impersonation protection, quarantine management, and coordination of SPF/DKIM/DMARC-related controls
- Coordinate and manage phishing simulations, user remediation, and security awareness follow-up activities
- Support SaaS application governance and review of third-party application access, permissions, and security risks
- Partner with outsourced SOC/EDR providers to investigate alerts, validate remediation actions, and continuously improve detection and response capabilities
- Lead HIPAA compliance efforts, including risk assessments and remediation tracking
- Care for internal and external audits, ensuring documentation and evidence are maintained continuously
- Monitor compliance with security policies and regulatory requirements
- Ensure controls are functioning and documented (not just defined)
- Own vendor security review process
- Ensure BAAs and security requirements are in place and tracked
- Maintain vendor inventory and risk classification
- Oversee user access controls, including onboarding, offboarding, and role-based access controls
- Lead periodic access reviews across key systems
- Ensure least-privilege access and proper audit trails
- Serve as the internal point of contact for security incidents, coordinating response with outsourced SOC/EDR providers
- Define and maintain incident response processes and escalation paths
- Track and ensure follow-up on security alerts and incidents
- Establish and maintain practical AI governance guidelines, including acceptable use of tools such as ChatGPT and Microsoft Copilot
- Define guardrails for responsible use of AI, including PHI protection and data handling
- Support evaluation of AI-enabled tools and vendors
- Partner with IT and operational teams to enable safe adoption
- Support security awareness initiatives, including phishing simulations and staff education
- Provide guidance on secure use of systems, data, and AI tools
- Partner with IT, Clinical Applications, Data, and Operations teams to ensure security practices align with workflows and business needs
- Provide regular reporting on security posture, risks, and compliance status to leadership
- Identify opportunities to improve processes, reduce risk, and strengthen controls
Qualifications
- 5+ years of experience in IT security, compliance, or risk management
- Experience in healthcare or regulated environments (HIPAA strongly preferred)
- Experience managing or supporting security programs, audits, and compliance initiatives
- Strong understanding of identity and access management, vendor risk, and security controls
- Ability to work cross-functionally and translate security requirements into practical processes
- Hands-on experience administering or supporting security technologies and operational controls, including areas such as identity and access management, endpoint protection, email security, MFA/conditional access, DLP, or SaaS security administration
Preferred
- Experience working with SaaS-heavy environments and third-party vendors
- Experience working with Microsoft 365 security technologies, endpoint protection, email security, SIEM, DLP, conditional access, or related security platforms
- Experience developing or supporting security policies and governance frameworks
- Familiarity with NIST, CIS Controls, or similar frameworks
- Exposure to AI tools and interest in emerging technology governance