Full-Time

Security Audit and Compliance Lead-HITRUST

Posted on 9/25/2024

Datavant

Datavant

5,001-10,000 employees

Enables secure health data exchange and privacy

Compensation Overview

$135k - $165k/yr

Mid

No H1B Sponsorship

Remote in USA

Category
Legal
Risk & Compliance
Legal & Compliance
Connection
Connection
Connection
logo

Get referrals →

You have ways to get a Datavant referral from your network.

💡

Applications through a referral are 3x more likely to get an interview!

Requirements
  • 4+ years experience in security and privacy frameworks, such as SOC 2, ISO 27001, HIPAA, PCI, NIST 800-53, FedRAMP, etc.
  • Specific experience with HITRUST Common Security Framework (CSF).
  • Experience in performing technical assessments and documentation around key controls and security processes, as well as auditing IT processes, including working knowledge of key controls across a number of industry best practices
  • Excellent analytical, problem-solving, and project management skills
  • Strong communication and interpersonal skills, with the ability to work effectively with cross-functional teams, stakeholders, and customers
  • Detail-oriented and able to handle multiple priorities in a fast-paced environment
  • Ability to operate effectively in ambiguity
  • One or more industry-recognized security, cloud, or audit professional certifications (e.g., CISA, CISM, CISSP, CCSP, etc.)
  • IT security and audit experience in the healthcare industry
Responsibilities
  • Develop, implement, and manage a comprehensive HITRUST compliance program that aligns with industry standards and ensures ongoing compliance.
  • Develop and maintain project plans, timelines, and milestones for HITRUST certification.
  • Facilitate audit procedures and evidence gathering with external auditors and internal partners
  • Communicate effectively and regularly with internal teams, external auditors, and customers
  • Manage a wide range of compliance and control efforts relating to HITRUST and audits; coordinate remediation efforts throughout the organization, analyze risks, and implement mitigation actions
  • Create a comprehensive HITRUST program utilizing unified control frameworks and monitoring of controls to ensure alignment with other control frameworks such as NIST CSF, CIS, etc.
  • Oversee issue, gap and remediation plans, compensating and mitigating control activities and retesting; scale and standardize the deviation process.
  • Create standard operating processes for managing changes to the control environment, managing HITRUST, and guiding control owners in readiness.
  • Liaise with customers and auditors, articulating control implementation, and describing considerations for applying security and compliance concepts to a technical environment.
  • Field and address requests for team support in collaboration with internal and external stakeholders.

Datavant focuses on health data technology, enabling the secure exchange of patient information while preserving privacy. Its main product is software that de-identifies patient health data and links records from different sources, allowing for cohesive data use without revealing personal information. Clients include hospitals, research institutions, and pharmaceutical companies, who rely on Datavant's technology for secure data access essential for research and public health initiatives. The company operates on a subscription-based model, aiming to be a key player in health data technology by providing vital tools for secure data sharing.

Company Size

5,001-10,000

Company Stage

Series B

Total Funding

$80.5M

Headquarters

San Francisco, California

Founded

2017

Simplify Jobs

Simplify's Take

What believers are saying

  • Increased demand for de-identified data solutions boosts Datavant's market potential.
  • Partnerships with AWS enhance data processing capabilities and scalability.
  • The rise of value-based care models increases demand for integrated data solutions.

What critics are saying

  • Phishing attacks have exposed sensitive data, affecting 11,000 children.
  • Rapid expansion in Galway may strain resources and lead to integration challenges.
  • Aggressive M&A strategy could lead to integration risks and cultural clashes.

What makes Datavant unique

  • Datavant specializes in de-identifying and linking patient health data securely.
  • The company has a vast network of over 70,000 hospitals and clinics.
  • Datavant's SaaS model provides customizable solutions for diverse healthcare needs.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Competitive Salaries & Rewards

Generous Parental & Family Leave

Ability to work anywhere in the US and Canada

Meaningful equity

Competitive Benefits – Full Family Coverage

WFH Stipend & Monthly Credit

Commitment to Learning & Development

Unlimited PTO

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

1%

2 year growth

0%
TechCentral
Apr 28th, 2025
Datavant hires VP of operations and site lead for global R&D centre in Galway

Health data platform Datavant has appointed Deirdre Giblin as VP of operations and site lead for its new global R&D centre in Galway.

Hit Consultant
Apr 10th, 2025
OMNY Health First EHR on Datavant Connect for Faster RWD Insights

To address this gap, OMNY Health has partnered with Datavant and Amazon Web Services (AWS) to leverage its expansive EHR dataset through AWS Clean Rooms.

Silicon Republic
Mar 31st, 2025
Datavant announces R&D centre in Galway with 125 new jobs

Datavant announces R&D centre in Galway with 125 new jobs.

HR Today
Mar 26th, 2025
Cathy Hoenig Appointed as Director, People Operations Project Management Office at Datavant

United States, March 2025 - Cathy Hoenig has joined Datavant as Director, People Operations Project Management Office.

Stock Titan
Mar 10th, 2025
31 Million Patient Journeys, One Mission

By incorporating OneMedNet's patient tokens into Datavant's network of over 300 real-world data partners, researchers can efficiently discover and access targeted Real-World Data for specific patient populations.

INACTIVE