Serve as named Information Security Officer and Privacy Officer for SOC 2 and HIPAA - own the policy manual (40+ documents), audit liaison relationship with A-LIGN, control mapping across overlapping ...

8 Align Jobs Hiring in California
Serve as named Information Security Officer and Privacy Officer for SOC 2 and HIPAA - own the policy manual (40+ documents), audit liaison relationship with A-LIGN, control mapping across overlapping ...
Senior Security Engineer, Digital Forensics (San Francisco)
San Francisco, CA · On-site
$150K - $250K/yr
Drive CMMC Level 2 certification to completion - scoping, SSP/POA&M ownership, evidence collection, and managing the C3PAO assessment (we're already evaluating firms like Schellman, A-LIGN, and CBIZ ...
Senior Security Engineer, Digital Forensics (San Francisco)
San Francisco, CA · On-site
$150K - $250K/yr
Drive CMMC Level 2 certification to completion - scoping, SSP/POA&M ownership, evidence collection, and managing the C3PAO assessment (we're already evaluating firms like Schellman, A-LIGN, and CBIZ ...
Head of Security
San Francisco, CA · On-site
$150K - $250K/yr
... A-LIGN, and CBIZ Pivot Point). Own our NIST SP 800-171 / DFARS 252.204-7012 posture and continuous compliance. Stand up and administer our ITAR/EAR export-control program - technical data segregation ...
Head of Security
San Francisco, CA · On-site
$150K - $250K/yr
... A-LIGN, and CBIZ Pivot Point). Own our NIST SP 800-171 / DFARS 252.204-7012 posture and continuous compliance. Stand up and administer our ITAR/EAR export-control program - technical data segregation ...
Head of Security
San Francisco, CA · On-site
$150K - $250K/yr
... A-LIGN, and CBIZ Pivot Point). • Own our NIST SP 800-171 / DFARS 252.204-7012 posture and continuous compliance. • Stand up and administer our ITAR/EAR export-control program - technical data ...
Head of Security
San Francisco, CA · On-site
$150K - $250K/yr
... A-LIGN, and CBIZ Pivot Point). • Own our NIST SP 800-171 / DFARS 252.204-7012 posture and continuous compliance. • Stand up and administer our ITAR/EAR export-control program - technical data ...
Head of Security
San Francisco, CA · On-site
$150 - $250/hr
Drive CMMC Level 2 certification to completion -- scoping, SSP/POA&M ownership, evidence collection, and managing the C3PAO assessment (we're already evaluating firms like Schellman, A-LIGN, and CBIZ ...
Head of Security
San Francisco, CA · On-site
$150 - $250/hr
Drive CMMC Level 2 certification to completion -- scoping, SSP/POA&M ownership, evidence collection, and managing the C3PAO assessment (we're already evaluating firms like Schellman, A-LIGN, and CBIZ ...
Head of Security
San Francisco, CA · On-site
$150 - $250/hr
Drive CMMC Level 2 certification to completion -- scoping, SSP/POA&M ownership, evidence collection, and managing the C3PAO assessment (we're already evaluating firms like Schellman, A-LIGN, and CBIZ ...
Head of Security
San Francisco, CA · On-site
$150 - $250/hr
Drive CMMC Level 2 certification to completion -- scoping, SSP/POA&M ownership, evidence collection, and managing the C3PAO assessment (we're already evaluating firms like Schellman, A-LIGN, and CBIZ ...
Head of IT & Security
San Francisco, CA · On-site
$160K - $200K/yr
Serve as named Information Security Officer and Privacy Officer for SOC 2 and HIPAA - own the policy manual (40+ documents), audit liaison relationship with A-LIGN, control mapping across overlapping ...
Head of IT & Security
San Francisco, CA · On-site
$160K - $200K/yr
Serve as named Information Security Officer and Privacy Officer for SOC 2 and HIPAA - own the policy manual (40+ documents), audit liaison relationship with A-LIGN, control mapping across overlapping ...
RN- Immunizing
Sun Valley, CA · On-site
$54 - $55.72/hr
... in a dynamic community healthcare setting Seek new ways to grow, collaborate with others and deliver better outcomes lign others around purpose to Product support and commitment • Actively ...
RN- Immunizing
Sun Valley, CA · On-site
$54 - $55.72/hr
... in a dynamic community healthcare setting Seek new ways to grow, collaborate with others and deliver better outcomes lign others around purpose to Product support and commitment • Actively ...
A-LIGN Jobs Information
What are popular cities in California for Align jobs?
What are the most popular jobs at Align?
What are the most popular categories at Align?
Job description
NexHealth is a technology company building infrastructure that's reshaping how patient data moves and how the HealthTech ecosystem connects. We're looking for a Security Lead to own our security governance, compliance, IT operations, vendor security, and incident response - establishing the function, embedding strong practices, and partnering closely with engineering, legal, and leadership.
This is a player-coach role with real hands-on expectation in year one. You'll drive the next phase of our security and compliance program, and build your team.
What You'll Do- Own NexHealth's security governance, compliance, and IT programs end-to-end.
- Serve as named Information Security Officer and Privacy Officer for SOC 2 and HIPAA - own the policy manual (40+ documents), audit liaison relationship with A-LIGN, control mapping across overlapping regimes, and evidence collection pipelines.
- Set security standards across application security, vulnerability management, cloud security (AWS), audit logging, and access controls - driving the technical program through Engineering via influence, not direct authority.
- Build, hire, and develop the IT and workforce security program: endpoints, identity, SaaS administration, phishing simulations, role-specific training modules, and facilities security.
- Own vendor security: intake, classification, assessment, BAA execution, ongoing oversight, and customer-facing trust artifacts including Trust Center and subprocessor disclosure.
- Lead incident response in Officer capacity; partner with outside counsel on breach determinations, own IR tracking, and run annual tabletop exercises.
- Own the risk register, risk acceptance decisions, privacy operations (DSARs, data subject rights, privacy complaints), BC/DR plan, and cyber insurance relationship.
- Hire a Staff-level IT IC within year one and grow the function from there.
- 8+ years of relevant security experience, including 3+ years in a security leadership role where you were materially building the program, not maintaining it.
- Has built (not inherited) a security program from a near-zero baseline at least once.
- Has owned a recurring external audit cycle end-to-end (e.g., SOC 2, ISO, PCI, HITRUST) - designed evidence collection, mapped controls, ran the auditor relationship, and made the next cycle materially easier than the last.
- Software engineering background. Can read a pull request, evaluate cloud configurations, and push back on Engineering with technical substance.
- Experience hiring and developing senior security or IT individual contributors.
Qualifications
- Hands-on experience with security tools and technologies such as SIEM, MDR, IDS/IPS, WAF, DLP, and vulnerability scanners.
- You've reshaped how a company engages with auditors, regulators, or customer security teams - moved questionnaires to Trust Centers, audits from manual to automated, or vendor reviews from one-off projects to continuous programs.
- You drive sustained operational change in functions you don't manage.
- You treat engineering velocity as a security input. Slow shipping creates security risk too.
- You can frame risk for a Board-level audience and for an engineering audience in the same week.
Behavioral Traits
- First-principles thinker.
- Writes. NexHealth runs on documents; verbal-first operators struggle here.
- Comfortable being the ranking voice on policy and risk.
About NexHealth
Sourced by ZipRecruiter
Industry
Software development
Company size
51 - 200 Employees
Headquarters location
San Francisco, CA, US