Security Operations & Compliance Engineer
Job Description
Security Operations & Compliance Engineer Pay Competitive Location Exeter/New Hampshire Employment type Full-Time Job Description Req#: 468693 *This position is fully remote and/or hybrid depending on candidate location, candidate must be based in the US, with full work authorization. Position Summary: This role is responsible for understanding, evaluating, and assessing complex systems, security controls and standards for Enterprise IT and products. In addition, this role will ensure that the company is compliant with regulatory IT requirements, product security & IT security best practices, policies and standards. Primary Responsibilities:
Oversee the IT policy framework - develop, update, and maintain IT policies, procedures, and standards; oversee adherence to IT processes; own the IT training program to create and oversee IT training curricula for the company. Oversee IT compliance and IT document life cycle, ensure compliance with IT documentation standards. Work with the Application team and business stakeholders to develop user and functional requirement specifications. Work with product teams to ensure best security practices are implemented in products and services. Perform information security assessments, compliance gap analysis, risk assessments, develop policies and procedures, in a variety of business use cases with respect to the following: HIPAA Security Industry Rule HITRUST framework SOX Compliance GDPR Compliance SOC 2 Type I and II Compliance Coordinate audit-related activities with external auditors in these areas, as well as SOX. Participate in the SOX audit process and assume ownership of the SOX IT General Controls. Perform existing IT security and compliance controls and assist the business in performing the same; participate and support FDA inspections. Monitors, evaluates and maintains information security controls for applications and systems. Assists internal systems users with information security issues in a timely and professional manner. Enforces security policies and procedures by conducting audits, monitoring and analyzing potential security violations. Coordinate and oversee third-party penetration testing. Monitor security systems to identify security events and respond to, investigate, and mitigate those events.
Position Requirements:
Must have relevant experience with software and networks in the Health Care industry. Must have 5+ years of experience working in IT of a regulated industry. SOX, PCI compliance and GDPR knowledge required. Strong understanding of Client / Server architecture, Cloud platforms (GCP) and network concepts. Minimum 3 years of progressively responsible experience performing Windows system administration duties in a critical production environment, preferably healthcare. Strong analytical, organizational, critical thinking, and problem-solving skills. Comfortable in working cross-functionally with all levels of a corporate structure. Knowledge of SOX, HIPAA, SOC2 and HITRUST applied to IT, ERP systems, and systems implementations. Excellent customer service and interpersonal skills (this role will require you to interact with business stakeholders, QA, and external auditors).
About the company Vapotherm Inc. is a publicly held corporation based in Exeter, New Hampshire that was founded in 1999 as a medical device manufacturer after creating the first heated and humidified high flow therapy nasal cannula system. Notice Talentify is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status. Talentify provides reasonable accommodations to qualified applicants with disabilities, including disabled veterans. Request assistance at [email protected] or 407-000-0000. Federal law requires every new hire to complete Form I-9 and present proof of identity and U.S. work eligibility. An Automated Employment Decision Tool (AEDT) will score your job-related skills and responses. Bias-audit & data-use details: www.talentify.io/bias-audit-report . NYC applicants may request an alternative process or accommodation at [email protected] or 407-000-0000. #J-18808-Ljbffr