Security Program Manager

ForusNew York, NY
Onsite

About The Position

As a Security Program Manager at Forus, you will own the programs that let customers trust us with their most sensitive data. We operate on protected health information to automate healthcare, and our providers, payers, and life sciences partners hold us to a high bar. You will own our compliance programs end to end - SOC 2, HIPAA, and HITRUST - and build the customer trust function that ensures security remains a core competency at Forus. You will run vendor and third-party risk assessments, stand up compliance automation, and partner closely with our engineering team to implement the technical controls you map to each framework. This is a demanding role, with a high level of autonomy and responsibility. You will be expected to "act like an owner" and commit yourself to Forus' success. If you are low-ego, hungry to learn, and excited about intense, impactful work that drives both company growth and accelerated career progression, we want to hear from you.

Requirements

  • Typically 4–7 years in GRC, security compliance, or security program management, with a track record of running audits end to end.
  • Hands-on experience with SOC 2 and HIPAA; HITRUST experience is a strong plus, as is a track record of standing up a new framework from scratch.
  • Experience in a regulated, high-growth environment — ideally healthcare or another domain with serious data-handling obligations.
  • Fluency with compliance automation tooling and enough technical literacy to work credibly with engineers on cloud, identity, and logging controls.
  • Experience owning customer-facing security with enterprise buyers: questionnaires, trust centers, and due diligence.
  • Strong written and verbal communication that allows you to be an effective participant in both internal debates and external relationships.
  • A track record of moving quickly, finding shortcuts, and going to unreasonable lengths to deliver on goals.
  • High NPS with your former teammates.

Responsibilities

  • Own our compliance programs end to end (SOC 2 Type II, HIPAA, and HITRUST) from readiness through audit and continuous monitoring.
  • Build and run the customer trust function (security questionnaires, RFPs, due diligence, and our trust center) so security accelerates deals rather than blocking them.
  • Stand up and administer compliance automation, turning evidence collection and control monitoring into a continuous, low-toil system.
  • Author security policies, run security-awareness training, and drive access reviews and audit readiness across the company.
  • Partner with engineering and legal to translate framework and customer requirements into concrete controls, and coordinate external auditors and penetration-testing firms.
  • Own the risk register and give leadership clear, honest visibility into our security and compliance posture.

Benefits

  • Fully covered medical, vision, and dental insurance.
  • Memberships for One Medical, Talkspace, Teladoc, and Kindbody.
  • Unlimited paid time off (PTO) and 16 weeks of parental leave.
  • 401K plan setup, FSA option, commuter benefits, and DashPass.
  • Lunch at the office every day and Dinner at the office after 7 pm.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service