Jobs and Careers
VO

Director of Security Privacy Compliance 100% Remote

Vori Health
United StatesRemotefull_timeVerifiedPosted 6 Jun 2025
💰 $200,000/yr($180,000/yr$200,000/yr)

About the role

Who We Are: 

Vori Health is an award-winning, nationwide, virtual-first, musculoskeletal medical practice focused on evidence-based care that treats the whole person. Using a unique care model to help patients find the best path forward, Vori Health connects patients to a trained care team that includes a nonoperative physical medicine physician, a health coach navigator, and a physical therapist who manage the initial patient assessment and then work to coordinate all aspects of care. We are on a mission to empower humanity to lead a healthier life. 

Reporting to the Chief Technology Officer, you will work closely with other members of the information technology team, as well as cross-functional stakeholders.  

As the Director of Security, Privacy, and Compliance, you’ll be responsible for designing, implementing, and optimizing the security and compliance infrastructure that supports our virtual-first clinical care model. You will lead Vori Health’s information protection strategy across patient data, clinical workflows, and vendor ecosystems, ensuring regulatory readiness and operational resilience. This role will lead, operationalize and maintain security controls to protect patient data and maintain SOC2, HIPAA, GDPR and HITRUST compliance.  You will lead Vori Health’s information protection strategy across patient data, clinical workflows, and third-party ecosystems, ensuring regulatory readiness, operational resilience, and patient trust. 

This position involves strategic decision-making, system implementations, and the adoption and testing of new processes and procedures which improve the security and robustness of Vori Health’s infrastructure and associated IT systems. You will oversee key outside vendors, working to identify and safeguard Vori Health from intrusion, security threats, security weaknesses, software bugs and exploits. You will be responsible for Vori Health’s data, systems, patients, customer, and user security. 

 

What You’ll Do: 

  • Security & Compliance Leadership 

    • Lead the development and execution of security and privacy programs that ensure HIPAA, HITECH, NIST, GDPR, SOC2, HITRUST, and emerging frameworks (e.g., CCPA/CPRA, 21st Century Cures Act) compliance. 

    • Develop, implement, and maintain security policies, procedures, and governance documentation. 

    • Serve as the primary point of contact for all internal and external audits, including regulatory and client assessments. 

    • Conduct risk assessments, security audits and penetration tests to identify vulnerabilities and develop remediation plans

  • Privacy Management 

    • Oversee the enterprise privacy program including PHI protections, breach notifications, consent management, and OCR compliance. 
    • Act as liaison with legal and clinical leadership for interpretation and application of data privacy requirements. 

  • Third-Party Risk & Vendor Security

    • Own vendor security assessments, third-party due diligence, and contract negotiation support.

    •  Maintain a centralized vendor risk registry and monitor compliance on an ongoing basis. 

  • Secure Architecture & Development Practices 

    • Collaborate with engineering teams to ensure adoption of secure development practices (DevSecOps). 

    • Leverage frameworks such as NIST, OWASP, and ISO for secure coding, CI/CD pipelines, and system design. 

  • Risk Management & Incident Response 

    • Conduct regular risk assessments, vulnerability scans, penetration tests, and threat modeling. 

    • Develop and lead security incident response processes, including forensic investigations and breach communications. 

  • Training & Enablement 

    • Develop and deliver ongoing employee security and privacy training programs. 

    • Promote a security-first culture across clinical, product, and operational teams. 

  • Customer & Partner Engagement 

    • Support the completion of RFPs, due diligence requests, and customer security questionnaires. 

    • Participate in customer and partner meetings to articulate our security and compliance posture. 

    • Build and maintain relationships with regulatory bodies, auditors, and other stakeholders to ensure compliance with relevant regulations and standards 

  • Strategy, Reporting & Budgeting 

    • Provide security KPIs, dashboards, and executive briefings to leadership. 

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Vori Health

View company profile →