2

Remote Hitrust Jobs in Santa Clara, CA (NOW HIRING)

... remote-work ePHI handling. * Own the security incident response process, including detection ... HITRUST * Demonstrated ability to independently run a security program in a lean environment.

... remote-work ePHI handling. * Own the security incident response process, including detection ... HITRUST * Demonstrated ability to independently run a security program in a lean environment.

New

Remote Hitrust information

See Santa Clara, CA salary details

$18

$32

$44

How much do remote hitrust jobs pay per hour?

As of Sep 1, 2026, the average hourly pay for remote hitrust in Santa Clara, CA is $32.50, according to ZipRecruiter salary data. Most workers in this role earn between $25.38 and $38.94 per hour, depending on experience, location, and employer.

What is a remote HITRUST professional?

A Remote HITRUST professional is someone who specializes in helping organizations achieve and maintain HITRUST certification, often while working from a remote location. HITRUST (Health Information Trust Alliance) certification is a widely recognized standard for managing data protection and compliance, particularly in the healthcare sector. These professionals guide companies through the complex process of meeting HITRUST requirements, conducting assessments, and ensuring ongoing compliance. Their work typically involves risk assessments, policy development, and collaboration with various teams, all facilitated through digital communication tools.

What are the key skills and qualifications needed to thrive as a remote HITRUST professional?

To thrive as a Remote HITRUST Compliance Specialist, you need a deep understanding of information security, risk management, and regulatory compliance, often supported by relevant degrees and HITRUST or cybersecurity certifications. Familiarity with frameworks like HITRUST CSF, GRC (Governance, Risk, and Compliance) tools, and audit management systems is typically required. Strong analytical thinking, attention to detail, and clear communication are crucial soft skills for interpreting requirements and guiding organizations through compliance processes. These skills ensure accurate risk assessments, effective compliance strategies, and successful HITRUST certification in a remote work environment.

What are some common challenges faced by professionals working in a remote HITRUST compliance role?

Professionals in remote HITRUST compliance roles often encounter challenges such as effectively coordinating with cross-functional teams spread across different locations and time zones. They must ensure clear communication and collaboration to gather required documentation and evidence for HITRUST assessments. Additionally, staying up to date with changing HITRUST standards and maintaining secure data practices while working remotely can be demanding. However, strong organizational skills and proactive use of collaboration tools can help overcome these challenges.

What is the difference between Remote Hitrust vs Remote HIPAA Compliance Specialist?

AspectRemote HitrustRemote HIPAA Compliance Specialist
CertificationsHITRUST CSF Certification, HIPAA knowledgeHIPAA certifications, sometimes HITRUST familiarity
Work EnvironmentRemote, healthcare and cybersecurity sectorsRemote, healthcare organizations
Industry UsageHealthcare, cybersecurity, complianceHealthcare, compliance roles

Remote Hitrust professionals focus on implementing and managing HITRUST CSF frameworks, often requiring cybersecurity and compliance certifications. Remote HIPAA Compliance Specialists primarily ensure healthcare organizations meet HIPAA standards, with certifications centered on HIPAA regulations. Both roles are remote and serve the healthcare industry, but Hitrust roles tend to involve broader cybersecurity frameworks, while HIPAA specialists focus specifically on privacy and security rules.

What are popular job titles related to Remote Hitrust jobs in Santa Clara, CA?

For Remote Hitrust jobs in Santa Clara, CA, the most frequently searched job titles are:

What job categories do people searching Remote Hitrust jobs in Santa Clara, CA look for?

The top searched job categories for Remote Hitrust jobs in Santa Clara, CA are:

What cities near Santa Clara, CA are hiring for Remote Hitrust jobs?

Cities near Santa Clara, CA with the most Remote Hitrust job openings:

Infographic showing various Remote Hitrust job openings in Santa Clara, CA as of August 2026, with employment types broken down into 86% Full Time, 10% Part Time, and 4% Contract. Highlights an 62% Physical, 5% Hybrid, and 33% Remote job distribution, with an average salary of $67,603 per year, or $32.5 per hour.

Information Security Officer

Medvidi

San Jose, CA • On-site, Remote

Full-time

Posted 4 days ago


Job description

Description
About MEDvidi
MEDvidi is a multi-state telehealth practice delivering behavioral health and psychiatric services through a licensed Professional Corporation structure. As our organization and provider workforce continue to grow, protecting highly sensitive behavioral-health information and maintaining a strong, operational HIPAA security program are critical to our continued success.
We are seeking an experienced Information Security Officer (ISO) to own and operate MEDvidi's HIPAA Security Program.
About the Role
The Information Security Officer will have end-to-end ownership of MEDvidi's information security program, with particular responsibility for safeguarding electronic protected health information (ePHI).
You will inherit a completed Security Risk Analysis and be responsible for turning identified risks and recommendations into a sustainable operating program. This includes remediation execution, ongoing risk management, technical and administrative safeguards, vendor security, incident response, security policies, and security compliance.
This is a hands-on ownership role for someone comfortable independently running a security program in a lean, fast-moving healthcare environment.
Responsibilities
Key Responsibilities
  • Serve as MEDvidi's designated HIPAA Security Official under 45 CFR § 164.308(a)(2).
  • Own the organization's security risk analysis and ongoing risk-management cycle, including maintaining the risk register and driving remediation items to closure.
  • Develop, operate, document, and maintain HIPAA administrative safeguards, including workforce security, access authorization, security awareness and training, incident procedures, and contingency planning.
  • Partner with IT to implement and maintain technical safeguards involving access controls, authentication, audit controls, data integrity, logging, and encryption of ePHI in transit and at rest.
  • Maintain security policies for MEDvidi's distributed workforce, including workstation security, device and media controls, and remote-work ePHI handling.
  • Own the security incident response process, including detection, containment, forensics coordination, documentation, and annual tabletop exercises.
  • Partner with the Privacy Officer on breach investigations and other areas where privacy and security requirements overlap.
  • Lead vendor and Business Associate security diligence, including security questionnaires, SOC 2/HITRUST reviews, subcontractor risk, and remediation of security findings.
  • Support security architecture and tooling decisions involving telehealth platforms, EHR access, endpoint management, logging, and SIEM coverage.
  • Review the security implications of AI tools and AI-assisted security and compliance processes used within the organization.
  • Manage and operate MEDvidi's GRC platform in partnership with Compliance leadership.
  • Monitor changes to the HIPAA Security Rule and help MEDvidi assess and implement new requirements as they become applicable.

Requirements
Required Qualifications
  • 6+ years of information security experience.
  • 2+ years of experience in healthcare or another regulated ePHI/PII environment.
  • Demonstrated hands-on ownership of a HIPAA security program or equivalent regulated security program; advisory-only experience is not sufficient.
  • Strong working knowledge of the HIPAA Security Rule.
  • Working knowledge of at least one relevant security/control framework, such as:
  • NIST Cybersecurity Framework (CSF) 2.0
  • NIST SP 800-66r2
  • HITRUST
  • Demonstrated ability to independently run a security program in a lean environment.
  • Strong risk-based prioritization, practical control implementation, and security documentation skills.

Preferred Qualifications
  • CISSP, HCISPP, CISM, or equivalent certification.
  • Experience securing telehealth platforms or other healthcare technology environments.
  • Cloud security experience with AWS, Azure, and/or GCP.
  • Experience leading security incident response.
  • Experience working with fractional or external security resources, penetration testers, and independent security advisors.
  • Familiarity with evolving HIPAA Security Rule requirements.

What Success Looks Like
During your first year, you will be expected to establish a mature, well-documented, and operational security program. Key outcomes include:
  • Closing Security Risk Analysis remediation items or placing them on documented, formally accepted remediation schedules.
  • Maintaining a security policy suite mapped to applicable HIPAA safeguards, with clear owners, review cadences, and evidence.
  • Testing the incident response plan through a tabletop exercise.
  • Maintaining workforce security training completion of at least 95%.
  • Completing security reviews for critical vendors handling ePHI.
  • Coordinating an annual penetration test and ensuring findings are incorporated into the remediation program.

Why Join MEDvidi?
This is an opportunity to take genuine ownership of information security within a growing multi-state behavioral healthcare organization. Rather than serving solely as an advisor, you will have the mandate to build, operate, improve, and demonstrate the effectiveness of the security program while working closely with Compliance, Privacy, IT, and organizational leadership.
If you are an experienced healthcare security professional who enjoys translating regulatory requirements and risk assessments into practical, sustainable security operations, we would like to hear from you.
Apply today to join MEDvidi as our Information Security Officer.