Security Audit and Compliance Manager
DatavantAbout the role
Datavant is a data logistics company for healthcare whose products and solutions enable organizations to move and connect data securely. We are a data logistics company for healthcare whose products and solutions enable organizations to move and connect data securely. Datavant has a network of networks consisting of thousands of organizations, more than 70,000 hospitals and clinics, 70% of the 100 largest health systems, and an ecosystem of 500+ real-world data partners.
By joining Datavant today, you’re stepping onto a highly collaborative, remote-first team that is passionate about creating transformative change in healthcare. We hire for three traits: we want people who are smart, nice, and get things done. We invest in our people and believe in hiring for high-potential and humble individuals who can rapidly grow their responsibilities as the company scales. Datavant is a distributed, remote-first team, and we empower Datavanters to shape their working environment in a way that suits their needs.
As a leader within the larger Information Security organization, your mission is to help lead your portion of GRC to the next level of evolution at Datavant, using a dual focus on delivering high-quality service for our stakeholders, as well as “automating away all the boring stuff” about your team’s jobs. You have deep expertise in developing, managing, and executing commercial and federal compliance audits like FedRAMP, SOC2, and HITRUST. You are an experienced industry professional with the keen ability to understand IT security processes, controls, and communicate across a variety of audiences. You will join our team in leading the security audit and compliance program.
You will:
- Lead a team of security and compliance professionals, delivering on our assurance and audit activities with a focus on innovative automated processes
- Manage the Datavant portfolio of compliance attestations, assessments, and audits including SOC2, FedRAMP, HITRUST, HIPAA, PCI DSS, ISO27001, etc.
- Manage a wide range of compliance and control efforts relating to information security; coordinate remediation efforts throughout the organization, analyze risks, and implement mitigation actions
- Create a comprehensive program utilizing unified control frameworks and monitoring of controls to ensure alignment with control frameworks such as NIST CSF, CIS, etc.
- Oversee issue, gap and remediation plans, compensating and mitigating control activities and retesting; scale and standardize the deviation process.
- Set and reinforce strategic direction, execute audit and compliance roadmaps, monitor progress, coordinate improvement efforts internally and externally, and assess process-improvement effectiveness
- Create standard operating processes for managing changes to the control environment, managing audits, and guiding control owners in readiness.
- Coach your team, holding them accountable for delivery excellence, continuous improvement, and provide clarity and mentorship on how they will get to the next steps in their careers
- Establish a baseline and publish a monthly NPS for all functions you manage
- Challenge the team to devise meaningful ways to measure their success and blockers in each of their functions; then, publish those and use them to make iterative improvements to your program
What you will bring to the table:
- 5+ years experience in security, compliance, audits, control assessments, or risk management based on security and privacy frameworks, such as SOC 2, ISO 27001, HIPAA, PCI, HITRUST, NIST 800-53, FedRAMP, etc.
- Minimum 3 years successfully leading GRC team or audit function
- Excellent communicator and mentor with ability to articulate complex compliance and security concepts to diverse audiences
- Detail-oriented and able to handle multiple priorities in a fast-paced environment
Bonus points if:
- One or more industry-recognized security, cloud, or audit professional certifications (e.g., CISA, CISM, CISSP, CCSP, etc.)
- IT security and audit experience in the healthcare industry
We are committed to building a diverse team of Datavanters who are all responsible for stewarding a high-performance culture in which all Datavanters belong and thrive. We are proud to be an Equal Employment Opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, sex, sexual orientation, gender identity, religion, national origin, disability, veteran status, or other legally protected status.
Our compensation philosophy is to be externally competitive, internally fair, and not win or lose on compensation. Salary ranges for this position are developed with the support of benchmarks and industry
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s