Senior Compliance Specialist

Spring HealthNew York City, NY
104d$125,000 - $145,850

About The Position

Reporting to the Sr Manager, IT Compliance, the Senior Compliance Specialist will assist with all matters relating to Information Security compliance including SOC 2 Type II, HITRUST, Health Insurance Portability and Accountability Act (HIPAA), General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), ISO 27001, ISO 42001 and ITGC-SOX. This is a full time position that is fully remote.

Requirements

  • Bachelor's degree plus 5+ years of experience in a compliance focused role.
  • Proven experience developing, implementing, and maintaining a comprehensive Third Party Risk Management (TPRM) program in alignment with frameworks such as SOC 2, ISO 27001, and HITRUST, including vendor due diligence, risk assessments, contract and security reviews, ongoing monitoring, and remediation processes.
  • Experience with common security frameworks and regulations such as SOC2, HIPAA, GDPR, HITRUST ISO and SOX.
  • Demonstrated understanding of emerging information security trends, including changes to security frameworks and regulatory requirements
  • Self-starter, organized, efficient, and proactive
  • Strong communication and cross organization collaboration skills

Responsibilities

  • Develop, execute and ensure adherence to existing and planned compliance programs: Existing: SOC2 / HITRUST / HIPAA and GDPR Compliance; Planned: ISO 27001 / ITGC SOX / FedRAMP etc.
  • Lead and manage annual assessment and audit related works (assessment planning, internal assessments, actual assessment interviews, evidence requests coordination, remediation coordination etc.) with external (external assessors other certification authorities) and internal stakeholders (organization wide engineering teams)
  • Execution of Supply Chain and Third Party Vendor Management Program
  • Support Customer Assurance Program - support customer calls, responding to customer questionnaires etc.
  • Provide timely updates and escalations to leadership.
  • Use, manage and maintain the GRC tool for effective compliance initiatives and activities
  • Perform internal information security risk assessments, document control deficiencies, and develop recommendations for improvement
  • Develop and maintain the necessary plans, policies, procedures, and standard operating protocols (SOPs) to support compliance assessments and strengthen Spring Health's overall security posture.
  • Conduct continuous monitor activities by regularly documenting updates to artifacts, risk management, access reviews etc.
  • Support Remediation Tracking and Implementation
  • Evolve, execute and delivery of information security and privacy awareness training and other role based training programs to build security aware organizational culture

Benefits

  • Health, Dental, Vision benefits start on your first day at Spring.
  • Employer sponsored 401(k) match of up to 2% for retirement planning
  • A yearly allotment of no cost visits to the Spring Health network of therapists, coaches, and medication management providers for you and your dependents.
  • Competitive paid time off policies including vacation, sick leave and company holidays.
  • Parental leave of 18 weeks for birthing parents and 16 weeks for non-birthing parents after 6 months tenure.
  • Access to Noom, a weight management program-based in psychology.
  • Access to fertility care support through Carrot, in addition to $4,000 reimbursement for related fertility expenses.
  • Access to Wellhub, which connects employees to the best options for fitness, mindfulness, nutrition, and sleep in one subscription.
  • Access to BrightHorizons, which provides sponsored child care, back-up care, and elder care.
  • Up to $1,000 Professional Development Reimbursement a year.
  • $200 per year donation matching to support your favorite causes.

Stand Out From the Crowd

Upload your resume and get instant feedback on how well it matches this job.

Upload and Match Resume

What This Job Offers

Job Type

Full-time

Career Level

Mid Level

Industry

Ambulatory Health Care Services

Education Level

Bachelor's degree

Number of Employees

1,001-5,000 employees

© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service