Information Security Officer

Remote
CompanyMedvidi
LocationRemote USA
CategorySecurity
DepartmentLegal
Seniority-
WorkplaceRemote
Posted2026-09-14
Viacomeet

Description

MEDvidi is a multi-state telehealth practice delivering behavioral health and psychiatric services through a licensed Professional Corporation structure. As our organization and provider workforce continue to grow, protecting highly sensitive behavioral-health information and maintaining a strong, operational HIPAA security program are critical to our continued success.

We are seeking an experienced Information Security Officer (ISO) to own and operate MEDvidi's HIPAA Security Program.

About the Role

The Information Security Officer will have end-to-end ownership of MEDvidi's information security program, with particular responsibility for safeguarding electronic protected health information (ePHI).

You will inherit a completed Security Risk Analysis and be responsible for turning identified risks and recommendations into a sustainable operating program. This includes remediation execution, ongoing risk management, technical and administrative safeguards, vendor security, incident response, security policies, and security compliance.

This is a hands-on ownership role for someone comfortable independently running a security program in a lean, fast-moving healthcare environment.

  • 6+ years of information security experience.
  • 2+ years of experience in healthcare or another regulated ePHI/PII environment.
  • Demonstrated hands-on ownership of a HIPAA security program or equivalent regulated security program ; advisory-only experience is not sufficient.
  • Strong working knowledge of the HIPAA Security Rule .
  • Working knowledge of at least one relevant security/control framework, such as:
  • NIST Cybersecurity Framework (CSF) 2.0
  • NIST SP 800-66r2
  • HITRUST
  • Demonstrated ability to independently run a security program in a lean environment.
  • Strong risk-based prioritization, practical control implementation, and security documentation skills.

Preferred Qualifications

  • CISSP, HCISPP, CISM, or equivalent certification.
  • Experience securing telehealth platforms or other healthcare technology environments.
  • Cloud security experience with AWS, Azure, and/or GCP.
  • Experience leading security incident response.
  • Experience working with fractional or external security resources, penetration testers, and independent security advisors.
  • Familiarity with evolving HIPAA Security Rule requirements.

What Success Looks Like

During your first year, you will be expected to establish a mature, well-documented, and operational security program. Key outcomes include:

  • Closing Security Risk Analysis remediation items or placing them on documented, formally accepted remediation schedules.
  • Maintaining a security policy suite mapped to applicable HIPAA safeguards, with clear owners, review cadences, and evidence.
  • Testing the incident response plan through a tabletop exercise.
  • Maintaining workforce security training completion of at least 95% .
  • Completing security reviews for critical vendors handling ePHI.
  • Coordinating an annual penetration test and ensuring findings are incorporated into the remediation program.

Why Join MEDvidi?

This is an opportunity to take genuine ownership of information security within a growing multi-state behavioral healthcare organization. Rather than serving solely as an advisor, you will have the mandate to build, operate, improve, and demonstrate the effectiveness of the security program while working closely with Compliance, Privacy, IT, and organizational leadership.

If you are an experienced healthcare security professional who enjoys translating regulatory requirements and risk assessments into practical, sustainable security operations, we would like to hear from you.

Equal Opportunity Employer Statement

MEDvidi is an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees and contractors. All qualified applicants will receive consideration without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.