Jobs and Careers
KY

Senior Manager, Infosec Compliance

Kyruus Health
Remote - United States, United StatesRemotefull_timeVerifiedPosted 11 Jul 2025
💰 $186,000/yr($165,000/yr$186,000/yr)

About the role

At Kyruus Health, our mission is to connect people to the right care, in pursuit of our vision: a better healthcare system- one that's transparent and accessible- where everyone gets the care they need. Our values are at the heart of everything we do:
We care deeply – We do the right thing even if it’s the harder thing. We are fiercely driven – We harness our curiosity to pursue continuous improvement and create simple solutions to complex problems.We lead with respect – We celebrate the individual traits that make each of us unique and seek out diverse voices to listen and learn.We are accountable – We do what we promise for each other and our customers.
Here’s what that would mean for you in the Senior Manager, InfoSec Compliance role. Care: You care about our patients, our customers, our employees and our company. You want to do everything you can to keep them and their data safe. Driven: You want to build the best Information Security program possible. Respect: You respect the other departments at Kyruus Health. Security should be an enabler of their success. Accountable: You value our compliance certifications and look to improve with each assessment cycle.
This pivotal role will own leading Kyruus Health's enterprise-wide information security compliance and risk management strategy, reporting directly to the Senior Director, Information Security. The position requires a proven leader to oversee crucial certification efforts (SOC 2 Type II, HITRUST) and implement robust controls across our four unique cloud infrastructure environments. Responsibilities include strategic risk assessment, policy governance, driving continuous improvement, and actively managing team performance through coaching and strategic delegation of day-to-day compliance activities. This role is key to protecting sensitive data, maintaining customer trust, and ensuring our security posture enables business growth.

What you will do in a Senior Manager, InfoSec Compliance role at Kyruus Health:

  •  People Leadership: Lead a high-performing team responsible for delivering on complex, business-critical compliance initiatives. Provide coaching, mentorship, and career development to support both execution excellence and long-term growth.
  • Strategic Delegation: Strategically delegate day-to-day compliance activities and project tasks to team members, ensuring efficient execution and optimal resource utilization.
  • InfoSec Compliance Strategy: Lead and champion the Kyruus Health strategy for certification and audit work as it relates to SOC 2 Type II, HITRUST
  • Control Architecture & Implementation: Oversee the design and implementation of controls aligned to HITRUST CSF, NIST, SOC 2, and FedRAMP frameworks. Drive control maturity through cross-functional execution, audit readiness, and continuous improvement.
  • Risk Assessments: Lead information security risk assessments, document control deficiencies, and develop recommendations for improvement.
  •  Risk Management: Design and implement continuously monitor for information security risks by maintaining an information security risk register.
  • Business as Usual: Delegate day-to-today compliance activities (third party vendor reviews, access reviews, documentation review requests, etc.).
  • Gap Assessments: Lead periodic security and compliance gap assessments on new and existing systems, processes, and technologies.
  • Control Failures: Document and report control failures and gaps to stakeholders and provide guidance to improve alignment with compliance initiatives.
  • Policy Management and Governance: Develop, implement, and maintain information security governance artifacts such as policy, standards, and procedures to manage, support, and improve the organization’s information security program.
  • Customer Support: Triage and respond to client intake requests related to data privacy and security, as well as attend calls to discuss risks or issues with customers.
  • Security Training: Develop and deliver information security training and awareness artifacts to develop and maintain a security-aware organizational culture.
  • Collaboration: Lead collaboration between the security team and other departments, such as IT, legal, and executive management. Communicate complex security concepts and issues in a clear and actionable manner to non-technical stakeholders.
  • Continuous Improvement: Identify opportunities for process improvements and enhancements in security operations. Lead initiatives to upgrade or replace outdated sys

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Kyruus Health

View company profile →