Back to jobs

Security Compliance Program Manager

Holmdel, New Jersey

CentralReach is a leading provider of autism and IDD care software for Applied Behavior Analysis (ABA), multidisciplinary therapy, and special education. Trusted by more than 200,000 users, we enable therapy providers, educators, and employers to scale the way they deliver ABA and related therapies with innovative technology, market-leading industry expertise, and world-class customer satisfaction. 

The Security Compliance Program Manager will own and drive CentralReach’s overall compliance program, working directly with the Chief Compliance Officer and Chief Information Security Officer. Beyond day-to-day maintenance and special projects, this role brings program ownership: translating regulatory and security standards into action plans, building KPIs and reporting cadences for leadership, developing metrics, monitoring, and incident response capabilities in partnership with Information Security and Infrastructure teams, and continually evolving the program’s processes and tooling.  

Key Accountabilities: 

  • Lead and Manage Third-Party and Internal Audits 
    • SOC 2 Type 2 
    • HIPAA Attestation 
    • Privacy Audit  
    • Security Audits 
  • Compliance Program Strategy & Implementation 
    • Translate requirements from regulatory and security frameworks (e.g., NIST 800-53, SOC 2, HIPAA) into concrete action items for cross-functional teams 
    • Track progress and communicate compliance rollout status with the teams doing the work 
  • Program Reporting & Communication 
    • Develop KPIs and dashboards to measure compliance program maturity, and report on them regularly to the Chief Compliance Officer and leadership 
    • Partner with Information Security and IT leadership to continually evolve the compliance program 
  • Metrics, Monitoring & Incident Response 
    • Partner with Security and Infrastructure teams to support automated identification, alerting, and response for compliance-relevant risks and incidents 
    • Maintain the compliance/security Incident Response Plan 
    • Support on-call and escalation planning for compliance and security incidents 
  • Compliance Process Development & Tooling 
    • Create, implement, and automate recurring compliance processes, such as account and access reviews and employee onboarding/offboarding checks 
    • Identify and evaluate GRC (governance, risk, and compliance) and compliance management tools to support the program 

Projects: 

  • Build out the compliance program KPI framework and reporting cadence for leadership 
  • Manage Security and Compliance policy updates. 
  • Lead and manage required internal audits 
  • Oversee Vendor Management 
  • Implement security and compliance program 

Desired Skills and Experience: 

  • Experience working with auditors through internal and external security and compliance audits 
  • Working knowledge of security and compliance frameworks (e.g., NIST 800-53, SOC 2, HIPAA, ISO 27001) and the ability to translate them into operational action plans 
  • Experience developing KPIs, metrics, and reporting cadences for program and executive leadership 
  • Familiarity with security monitoring, alerting, and incident response concepts 
  • Experience with Business Continuity and Disaster Recovery planning 
  • Process improvement and automation mindset, including experience evaluating and implementing GRC or compliance management tools 
  • Strong cross-functional collaboration and stakeholder management, including with Information Security, Infrastructure, and Legal teams 
  • Proven ability to manage multiple compliance initiatives simultaneously (e.g., audit cycles, risk assessments, policy rollouts) with competing timelines and cross-functional dependencies 
  • Excellent written and verbal communication skills, with demonstrated ability to translate complex regulatory or legal requirements into clear, actionable guidance for non-compliance audiences. 
  • Detail-oriented approach to documenting audit findings, risk assessments, or corrective action plans, with follow-through on tracking items to closure. 
  • Analytical mindset with a track record of identifying root causes of process or control gaps and recommending sustainable fixes rather than short-term patches. 

Base Salary Range

$100,000 - $120,000 USD

Backed by Roper Technologies, Inc. (Nasdaq: ROP), CentralReach is entering an exciting phase of growth, innovation, and scale.  

Recognized as one of the best places to work over 10 times by organizations such as Inc, Built In, and NJBIZ, our culture is centered around impact, inclusion, and flexibility. As a hybrid company with collaborative offices in Ft. Lauderdale, FL; Holmdel, NJ; and Verona, Italy, we foster a workplace where top talent can thrive and make a real difference in the lives of those we serve.

We offer competitive compensation, comprehensive health benefits, generous PTO, 401(k) matching, and paid parental leave to our full-time employees. Our team members also enjoy hybrid work schedules, career development support, wellness programs, and opportunities to give back through CR Cares™, our community engagement initiative.

Be part of a market leader driving the future of care. Explore opportunities at centralreach.com/careers.  

Protecting your information is important to us.  Please take a moment to review our Notice of Privacy Practices for Job Applicants. Applicant-Privacy-Notice-110725 to understand how we collect, use, store, and protect your personal information during the recruitment process. 

Apply for this job

*

indicates a required field

Phone
Resume/CV

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Please choose the technologies you are familiar with: *
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in CentralReach’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

We use Greenhouse’s AI-powered Talent Matching tool to compare your application against our job requirements.

Learn more