About the job
Join Our Mission:
HealthVerity is on the lookout for a meticulous and experienced Security Compliance Program Manager to elevate our Security team. This pivotal role focuses on ensuring our information systems align with essential compliance standards, including FedRAMP, HIPAA, and other healthcare regulations. You will collaborate with both Security team members and cross-functional departments to implement robust security controls, taking a risk-aware and cost-efficient approach while continuously monitoring and assessing these controls.
Your Responsibilities:
- Craft, document, and uphold FedRAMP-specific policies, procedures, and controls.
- Assist in maintaining FedRAMP compliance by developing System Security Plans (SSP), collecting evidence, and generating reports.
- Partner with internal teams to manage the continuous monitoring (ConMon) program, including vulnerability reporting, tracking Plans of Action and Milestones (POA&Ms), and creating ConMon artifacts.
- Work alongside internal teams to formulate and enforce policies that satisfy compliance obligations.
- Engage with third-party assessors to execute security evaluations and audits.
- Conduct risk assessments for third-party vendors.
- Lead security training programs and phishing awareness campaigns.
- Undertake periodic risk assessments and audits to verify adherence to applicable regulatory frameworks.
Who You Are:
- You prioritize security in all aspects of your work.
- You excel in guiding with empathy and simplifying complex security concepts for non-expert audiences.
- You possess exceptional communication, interpersonal, and leadership abilities.
- You are knowledgeable about HIPAA, NIST 800-53, and other security compliance frameworks.
- You have a track record of leading components of information security audits.
- You stay informed about security trends and threats, able to convey these topics clearly to non-security professionals.
- You have hands-on experience with cloud security architectures and best practices for AWS (or equivalent for GCP/Azure).
- You are proficient in scripting (Shell, Python) and favor automation for evidence collection.

