Full-Time

Security Audit and Compliance Lead-HITRUST

Posted on 9/25/2024

Datavant

Datavant

5,001-10,000 employees

Health data technology for secure information exchange

Data & Analytics
Healthcare

Compensation Overview

$135k - $165kAnnually

Mid

No H1B Sponsorship

Remote in USA

Category
Legal
Risk & Compliance
Legal & Compliance
Requirements
  • 4+ years experience in security and privacy frameworks, such as SOC 2, ISO 27001, HIPAA, PCI, NIST 800-53, FedRAMP, etc.
  • Specific experience with HITRUST Common Security Framework (CSF).
  • Experience in performing technical assessments and documentation around key controls and security processes, as well as auditing IT processes, including working knowledge of key controls across a number of industry best practices
  • Excellent analytical, problem-solving, and project management skills
  • Strong communication and interpersonal skills, with the ability to work effectively with cross-functional teams, stakeholders, and customers
  • Detail-oriented and able to handle multiple priorities in a fast-paced environment
  • Ability to operate effectively in ambiguity
  • One or more industry-recognized security, cloud, or audit professional certifications (e.g., CISA, CISM, CISSP, CCSP, etc.)
  • IT security and audit experience in the healthcare industry
Responsibilities
  • Develop, implement, and manage a comprehensive HITRUST compliance program that aligns with industry standards and ensures ongoing compliance.
  • Develop and maintain project plans, timelines, and milestones for HITRUST certification.
  • Facilitate audit procedures and evidence gathering with external auditors and internal partners
  • Communicate effectively and regularly with internal teams, external auditors, and customers
  • Manage a wide range of compliance and control efforts relating to HITRUST and audits; coordinate remediation efforts throughout the organization, analyze risks, and implement mitigation actions
  • Create a comprehensive HITRUST program utilizing unified control frameworks and monitoring of controls to ensure alignment with other control frameworks such as NIST CSF, CIS, etc.
  • Oversee issue, gap and remediation plans, compensating and mitigating control activities and retesting; scale and standardize the deviation process.
  • Create standard operating processes for managing changes to the control environment, managing HITRUST, and guiding control owners in readiness.
  • Liaise with customers and auditors, articulating control implementation, and describing considerations for applying security and compliance concepts to a technical environment.
  • Field and address requests for team support in collaboration with internal and external stakeholders.

Datavant focuses on health data technology, enabling the secure exchange of patient information while preserving privacy. Its main product is software that de-identifies patient health data and links records from different sources, allowing for cohesive data use without revealing personal information. Clients include hospitals, research institutions, and pharmaceutical companies, who rely on Datavant's technology for secure data access essential for research and public health initiatives. The company operates on a subscription-based model, aiming to provide vital tools for secure data sharing and privacy preservation in the healthcare sector.

Company Stage

Series B

Total Funding

$78.3M

Headquarters

San Francisco, California

Founded

2017

Growth & Insights
Headcount

6 month growth

2%

1 year growth

2%

2 year growth

0%
Simplify Jobs

Simplify's Take

What believers are saying

  • Growing demand for de-identified data solutions boosts Datavant's market potential.
  • Partnerships with pharmaceutical companies enhance Datavant's position in clinical research.
  • Expansion of telehealth services increases need for Datavant's secure data exchange solutions.

What critics are saying

  • Increased competition from Avandra threatens Datavant's market position.
  • A recent phishing attack exposed vulnerabilities in Datavant's cybersecurity measures.
  • Regulatory hurdles in Europe may impact Datavant's expansion with Promptly Health.

What makes Datavant unique

  • Datavant specializes in de-identifying and linking patient health data securely.
  • The company has a vast network of over 70,000 hospitals and clinics.
  • Datavant's SaaS model provides customizable solutions for diverse healthcare clients.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Competitive Salaries & Rewards

Generous Parental & Family Leave

Ability to work anywhere in the US and Canada

Meaningful equity

Competitive Benefits – Full Family Coverage

WFH Stipend & Monthly Credit

Commitment to Learning & Development

Unlimited PTO

INACTIVE