Cyber Security Lead

Mednition•Burlingame, CA
•$165,000 - $215,000

About The Position

The Cyber Security Manager is responsible for building, maintaining, and continuously improving the Mednition Information Security Program across our AI SaaS platform (including KATE Triage and KATE Sepsis). This role involves managing the Governance, Risk, and Compliance (GRC) program, overseeing HIPAA compliance and SOC2 Type 2 certification audits, supervising Google Cloud Platform (GCP) and MongoDB Atlas security architectures, and ensuring security across EHR integrations (HL7, FHIR). The Cyber Security Manager will also support regulatory alignment with FDA SaMD guidelines, NIST AI Risk Management Framework, and predetermined change control plans.

Requirements

  • Proven experience in managing information security programs and teams.
  • Strong understanding of governance, risk management, and compliance principles and practices.
  • In-depth knowledge of cloud cybersecurity operations (GCP, MongoDB Atlas, Cloud Run, Kubernetes), container security, CI/CD pipeline security, and SIEM.
  • Familiarity with healthcare data privacy and security standards (HIPAA, SOC2 Type 2, FDA SaMD regulations, NIST AI RMF, and HL7/FHIR security protocols).
  • Excellent communication and collaboration skills, with the ability to effectively engage with stakeholders at all levels.
  • Strong project management and organizational skills, with the ability to prioritize tasks and manage multiple initiatives.
  • Experience in working with security audit processes and frameworks.
  • Commitment to staying up-to-date with industry trends and advancements in the field of cyber security.

Nice To Haves

  • A master's degree is preferred.
  • Relevant certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or Certified Ethical Hacker (CEH).

Responsibilities

  • Build, maintain, and continuously improve the Mednition Information Security Program, including developing and implementing policies, processes, and procedures to protect the organization's information systems and data.
  • Manage the GRC program, including the development of policies, processes, and procedures to ensure compliance with regulatory requirements and industry standards.
  • Oversee the IT Security Program across cloud environments, Kubernetes clusters, and MongoDB Atlas databases, including continuous monitoring, SIEM, security architecture, and vulnerability assessments.
  • Supervise security monitoring operations, including vulnerability and threat assessments, network access control, incident response, and maintenance activities.
  • Support briefings and meetings with key stakeholders, providing recommendations to development teams regarding security best practices and requirements.
  • Ensure compliance with HIPAA, SOC2 Type 2 audits, FDA SaMD cybersecurity requirements, and NIST AI Risk Management Framework standards.
  • Effectively communicate and collaborate with internal and external key stakeholders, such as senior management, IT teams, customer security teams, vendors, and auditors.
  • Manage secure data integration architectures for HL7/FHIR EHR data pipelines, ensuring proper handling and protection of Patient Health Information (PHI).
  • Stay updated with the latest cyber security trends, threats, and technologies, and evaluate their applicability to the organization's security program.
  • Foster a culture of security awareness and compliance throughout the organization, promoting the importance of information security and privacy.
  • Collaborate with cross-functional teams to implement security controls, mitigate risks, and address security-related issues and incidents.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service