Security Lead
ABOUT XP HEALTH:
At XP Health, we're on a mission to revolutionize vision care through cutting-edge technology, including augmented reality, while ensuring a delightful and seamless user experience. We aim to make high-quality eye care accessible to everyone. Today, we are honored to serve over 3,000 clients, including several Fortune 500 logos and notable Silicon Valley companies. With passionate founders and a team that boasts deep expertise in the field, XP Health has driven efficient, best-in-class growth to date, and is hungry for more.
We invite you to become part of our dynamic and diverse team, where unique perspectives meet unparalleled growth opportunities. With over $50M in funding raised, including our Series B round in early 2024, we’re positioned for exciting new challenges and impactful contributions to the healthcare landscape.
The Opportunity
As the Security Lead, you will be at the forefront of ensuring the company meets critical compliance standards, including SOC 2, HIPAA, and HiTrust. You will take full ownership of the compliance function, working directly with leadership to manage audits, implement IT security protocols, and oversee training programs. This is an exciting opportunity to join a fast-growing healthcare B2B company that serves large clients and undergoes rigorous annual audits to maintain trust and security.
You’ll be instrumental in shaping the company’s security posture as we scale, deepening our compliance and expanding our programs to meet the increasing complexity of our operations. This role offers the chance to impact the company’s growth while building a scalable and robust security framework, with opportunities for leadership and strategic influence in the coming years.
Key Responsibilities
- Lead the execution of annual audits for SOC 2, HIPAA, and HiTrust, ensuring the company meets and exceeds compliance requirements.
- Develop, manage, and track annual compliance training programs for all employees.
- Oversee IT security tasks, including provisioning laptops, setting up compliant firewalls, and maintaining VPNs in line with industry best practices.
- Conduct quarterly security and compliance review meetings to identify risks, escalate issues, and drive necessary changes to maintain security posture.
- Manage client-facing calls for security due diligence and provide audit evidence to external auditors.
- Monitor and improve SLAs for addressing data breaches or compliance gaps, ensuring timely resolution of critical issues.
- Collaborate with leadership to continuously improve compliance initiatives and scale security programs as the company grows.
Requirements
- 5+ years of experience managing compliance programs for SOC 2, HiTrust, or similar frameworks at companies with 80+ employees.
- Proven track record of handling HIPAA, SOC 2, and HiTrust audits from start to finish, including providing evidence to auditors and managing security training.
- Strong IT skills, including experience with laptop provisioning, firewall setup, and VPN maintenance, with a focus on security.
- Demonstrated ability to manage and improve compliance processes, including tracking training programs, running penetration tests, and ensuring adherence to security protocols.
- Strong program management and organizational skills, with experience coordinating cross-functional stakeholders and managing quarterly security reviews.
- Excellent communication and client-facing skills, with the ability to present security protocols and audit findings to both internal teams and external auditors.
CA Pay Range
$150,000 - $170,000 USD
Compensation & Benefits
We offer a competitive compensation package that includes salary, equity options, paid time off, bonuses, a 401K plan, and comprehensive benefits. We believe in taking care of our team members so they can focus on their work and personal development.
Diversity & Inclusion Commitment
At XP Health, we are committed to fostering a diverse and inclusive workplace that reflects the communities we serve. We believe that a variety of perspectives and experiences contribute to innovation and success. We welcome applicants from all backgrounds, including racial and ethnic minorities, individuals with disabilities, veterans, and members of the LGBTQ+ community.
Our goal is to create an environment where everyone feels valued, respected, and empowered to contribute their unique talents. We encourage all individuals who are passionate about our mission to make vision care more affordable, accessible, and convenient to apply, and join us in building a more inclusive future together.
Come join our fast-growing team to disrupt and recreate a better vision care experience from the ground up!
Apply for this job
*
indicates a required field