Simplify Logo

Full-Time

Security Audit and Compliance Lead-HITRUST

Confirmed live in the last 24 hours

Datavant

Datavant

501-1,000 employees

Health data technology for secure information exchange

Consulting
Enterprise Software
Healthcare

Compensation Overview

$135k - $165kAnnually

Mid, Senior

Remote in USA

Category
Cybersecurity
IT & Security
Required Skills
Communications
Requirements
  • 4+ years experience in security and privacy frameworks, such as SOC 2, ISO 27001, HIPAA, PCI, NIST 800-53, FedRAMP, etc.
  • Specific experience with HITRUST Common Security Framework (CSF).
  • Experience in performing technical assessments and documentation around key controls and security processes, as well as auditing IT processes, including working knowledge of key controls across a number of industry best practices.
  • Excellent analytical, problem-solving, and project management skills.
  • Strong communication and interpersonal skills, with the ability to work effectively with cross-functional teams, stakeholders, and customers.
  • Detail-oriented and able to handle multiple priorities in a fast-paced environment.
  • Ability to operate effectively in ambiguity.
Responsibilities
  • Develop, implement, and manage a comprehensive HITRUST compliance program that aligns with industry standards and ensures ongoing compliance.
  • Develop and maintain project plans, timelines, and milestones for HITRUST certification.
  • Facilitate audit procedures and evidence gathering with external auditors and internal partners.
  • Communicate effectively and regularly with internal teams, external auditors, and customers.
  • Manage a wide range of compliance and control efforts relating to HITRUST and audits; coordinate remediation efforts throughout the organization, analyze risks, and implement mitigation actions.
  • Create a comprehensive HITRUST program utilizing unified control frameworks and monitoring of controls to ensure alignment with other control frameworks such as NIST CSF, CIS, etc.
  • Oversee issue, gap and remediation plans, compensating and mitigating control activities and retesting; scale and standardize the deviation process.
  • Create standard operating processes for managing changes to the control environment, managing HITRUST, and guiding control owners in readiness.
  • Liaise with customers and auditors, articulating control implementation, and describing considerations for applying security and compliance concepts to a technical environment.
  • Field and address requests for team support in collaboration with internal and external stakeholders.

Datavant specializes in health data technology, focusing on the secure exchange of patient information while maintaining privacy. The company's main product is software that de-identifies patient health data, removing personal identifiers and linking records from various sources. This allows healthcare providers, researchers, and other stakeholders to share and access health data securely, which is crucial for research, treatment, and public health initiatives. For instance, during the COVID-19 pandemic, Datavant's technology helped connect different datasets to analyze the virus's effects on populations. Unlike many competitors, Datavant operates on a software-as-a-service (SaaS) model, charging subscription fees that vary based on client size and data complexity. The goal of Datavant is to enhance data interoperability in the healthcare sector while ensuring patient privacy.

Company Stage

Series B

Total Funding

$80.5M

Headquarters

San Francisco, California

Founded

2017

Growth & Insights
Headcount

6 month growth

12%

1 year growth

3%

2 year growth

12%
Simplify Jobs

Simplify's Take

What believers are saying

  • Strategic partnerships with companies like Blockgraph and Promptly Health expand Datavant's market reach and application areas.
  • The acquisition of Healthjump and Swellbox enhances Datavant's capabilities in health data exchange and patient data access.
  • Datavant's role in critical public health initiatives, such as COVID-19 data linking, underscores its importance and potential for growth.

What critics are saying

  • The highly specialized nature of health data technology means Datavant must continuously innovate to stay ahead of competitors.
  • Dependence on subscription-based revenue could be risky if clients face budget constraints or switch to alternative solutions.

What makes Datavant unique

  • Datavant's unique de-identification and data linking technology ensures secure and cohesive patient data sharing, setting it apart from competitors.
  • The company's focus on privacy preservation while enabling data interoperability addresses a critical need in the healthcare sector.
  • Datavant's extensive network, surpassing 70,000 hospitals and clinics, provides a significant competitive edge in health data exchange.

Benefits

Competitive Salaries & Rewards

Generous Parental & Family Leave

Ability to work anywhere in the US and Canada

Meaningful equity

Competitive Benefits – Full Family Coverage

WFH Stipend & Monthly Credit

Commitment to Learning & Development

Unlimited PTO