WellHive operates a healthcare technology platform under HIPAA, and they're seeking an IT and Security Project Manager to drive a roadmap of security hardening initiatives. The role involves managing external IT partners, overseeing audits, and ensuring compliance with industry standards.
Responsibilities:
- Own a multi-effort IT/security hardening roadmap and drive it to delivered, validated controls
- Direct external IT partner(s) on implementation: scope, acceptance, quality
- Make and defend implementation and sequencing decisions; escalate risk and budget
- Run validation, phased rollout, and user-facing change
- Keep the work aligned to HIPAA and to HITRUST / SOC 2 Type 2
- Own corporate-IT control domains for our audits, maintain evidence, and engage Assessors
Requirements:
- Senior IT/security experience with hands-on IAM and SaaS administration
- A track record in a regulated environment (HIPAA, SOC 2, HITRUST, or similar)
- Experience engaging auditors/assessors and maintaining control evidence (HITRUST CSF or SOC 2 a plus)
- Experience managing contractors/MSPs to a statement of work
- The judgment to make technical security decisions independently
- Program management across concurrent workstreams
- Google Workspace and/or Okta administration depth
- DLP and device-management (Jamf / Kandji / Intune) familiarity
- IaC literacy