Full-Time

Security Audit and Compliance Lead-HITRUST

Posted on 9/25/2024

Datavant

Datavant

5,001-10,000 employees

Health data technology for secure information exchange

Compensation Overview

$135k - $165k/yr

Mid

No H1B Sponsorship

Remote in USA

Category
Legal
Risk & Compliance
Legal & Compliance
Requirements
  • 4+ years experience in security and privacy frameworks, such as SOC 2, ISO 27001, HIPAA, PCI, NIST 800-53, FedRAMP, etc.
  • Specific experience with HITRUST Common Security Framework (CSF).
  • Experience in performing technical assessments and documentation around key controls and security processes, as well as auditing IT processes, including working knowledge of key controls across a number of industry best practices
  • Excellent analytical, problem-solving, and project management skills
  • Strong communication and interpersonal skills, with the ability to work effectively with cross-functional teams, stakeholders, and customers
  • Detail-oriented and able to handle multiple priorities in a fast-paced environment
  • Ability to operate effectively in ambiguity
  • One or more industry-recognized security, cloud, or audit professional certifications (e.g., CISA, CISM, CISSP, CCSP, etc.)
  • IT security and audit experience in the healthcare industry
Responsibilities
  • Develop, implement, and manage a comprehensive HITRUST compliance program that aligns with industry standards and ensures ongoing compliance.
  • Develop and maintain project plans, timelines, and milestones for HITRUST certification.
  • Facilitate audit procedures and evidence gathering with external auditors and internal partners
  • Communicate effectively and regularly with internal teams, external auditors, and customers
  • Manage a wide range of compliance and control efforts relating to HITRUST and audits; coordinate remediation efforts throughout the organization, analyze risks, and implement mitigation actions
  • Create a comprehensive HITRUST program utilizing unified control frameworks and monitoring of controls to ensure alignment with other control frameworks such as NIST CSF, CIS, etc.
  • Oversee issue, gap and remediation plans, compensating and mitigating control activities and retesting; scale and standardize the deviation process.
  • Create standard operating processes for managing changes to the control environment, managing HITRUST, and guiding control owners in readiness.
  • Liaise with customers and auditors, articulating control implementation, and describing considerations for applying security and compliance concepts to a technical environment.
  • Field and address requests for team support in collaboration with internal and external stakeholders.

Datavant focuses on health data technology, enabling the secure exchange of patient information while preserving privacy. Its main product is software that de-identifies patient health data and links records from different sources, allowing healthcare providers and researchers to share data securely. The company operates on a subscription-based model, charging clients for access to its customizable software. Datavant differentiates itself by addressing the critical need for data interoperability and privacy in the healthcare sector.

Company Size

5,001-10,000

Company Stage

Series B

Total Funding

$80.5M

Headquarters

San Francisco, California

Founded

2017

Simplify Jobs

Simplify's Take

What believers are saying

  • Growing demand for de-identified data solutions enhances Datavant's market position.
  • The rise of value-based care models aligns with Datavant's Clinical Insights Platform.
  • Potential IPO could provide capital for expansion and innovation.

What critics are saying

  • Phishing attacks have led to data breaches, exposing sensitive information.
  • Avandra's federated network poses competitive pressure on Datavant.
  • M&A activities may lead to integration challenges and distract from core operations.

What makes Datavant unique

  • Datavant specializes in de-identifying and linking patient health data securely.
  • The company has a vast network of over 70,000 hospitals and clinics.
  • Datavant's SaaS model provides customizable solutions for diverse healthcare data needs.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Competitive Salaries & Rewards

Generous Parental & Family Leave

Ability to work anywhere in the US and Canada

Meaningful equity

Competitive Benefits – Full Family Coverage

WFH Stipend & Monthly Credit

Commitment to Learning & Development

Unlimited PTO

Growth & Insights and Company News

Headcount

6 month growth

2%

1 year growth

2%

2 year growth

0%
HR Today
Mar 26th, 2025
Cathy Hoenig Appointed as Director, People Operations Project Management Office at Datavant

United States, March 2025 - Cathy Hoenig has joined Datavant as Director, People Operations Project Management Office.

Stock Titan
Mar 10th, 2025
31 Million Patient Journeys, One Mission

By incorporating OneMedNet's patient tokens into Datavant's network of over 300 real-world data partners, researchers can efficiently discover and access targeted Real-World Data for specific patient populations.

HR Tech Wire
Mar 6th, 2025
Datavant Unveils Enhanced Clinical Insights Platform to Transform Data Intelligence for Payers and Providers

Datavant, the leading health data platform company, today announced the launch of the Datavant Clinical Insights Platform, an integrated offering that empowers health plans and risk-bearing providers to seamlessly identify, access, analyze and act on clinical data.

Business Insider
Jan 7th, 2025
Datavant is on the M&A hunt as the $7B health data company bulks up before a potential IPO

Datavant is on the M&A hunt as the $7B health data company bulks up before a potential IPO.

Business Wire
Dec 17th, 2024
DeVry University Presents Datavant with Healthcare Relationship Excellence Award

DeVry University presents Datavant with Healthcare Relationship Excellence Award.

INACTIVE