Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Security Compliance and Risk Manager image - Rise Careers
Job details

Security Compliance and Risk Manager

At Bluesight, our mission is to create groundbreaking solutions that increase efficiency, safety and visibility for health systems, hospital pharmacy, and pharmaceutical manufacturers.  We empower our customers to deliver the right medicine to the right patient at the right time, every time.  We are a high growth healthcare information technology company with a start-up 'vibe' but over 2,000 customers using our proven solutions.



Bluesight is seeking to add an IT Compliance and Risk Manager to our team!  The IT Compliance and Risk Manager will provide risk oversight and direct hands-on completion of deliverables related to our security posture and compliance.   The Risk Manager will lead our efforts in protecting sensitive healthcare data, securing our cloud infrastructure, and ensuring regulatory compliance. The ideal candidate will possess strong managerial abilities, deep expertise in cloud security (particularly AWS), and a background in SaaS/internet technologies. A vital responsibility of the role will be ensuring the strategic view is developed and executed with consideration for the risks involved while proactively managing IT and data risks in the organization.


Representative Responsibilities and Duties:
  • Perform compliance monitoring, analysis, tracking, and reporting
  • Oversee, direct, and complete security audits
  • Complete security risk assessments
  • Lead Bluesights' annual SOC2 Type 2 renewal certification
  • Support execution of the enterprise-wide risk assessment framework as it pertains to Risks, Controls, and overall Governance activities
  • Develop and manage the Bluesight Security Program, including technical security assessments, vulnerability management, and penetration testing
  • Ensure the confidentiality, integrity, and availability of our cloud-based systems and data through strong collaboration with our engineering and IT teams.
  • Maintain, implement, and improve upon security strategies
  • Assists in defining and maintaining security policies, standards, and guidelines.
  • Evaluate and implement security technologies, including endpoint detection, firewalls, and other security tools.
  • Collaborates with vendors and internal teams to deploy and integrate security solutions.
  • Conducts security assessments, including vulnerability assessments and penetration testing.
  • Manage overall Security Risks to company systems, data and operations.
  • Conduct an Annual Security & Privacy Risk Analysis
  • Manage and maintain the Risk Register
  • Work with executive leadership on prioritization and remediation
  • Lead the implementation of controls and mitigation strategies
  • Develop and maintain security incident response and investigation efforts
  • Manage Security monitoring platforms
  • Manage Security Incident Response
  • Monitor and analyze
  • Provide recommendations to remediate identified security vulnerabilities.
  • Participates in tabletop exercises and simulations to enhance incident response capabilities.
  • Contribute to the development and delivery of security awareness training for employees.
  • Provide guidance on security best practices and awareness.
  • Collaborates closely with the Engineering, DevOps, and IT teams to understand operational challenges and contribute to solutions.
  • Maintain comprehensive documentation related to security architecture, assessments, and technology implementations.
  • Ensures documentation is aligned with organizational standards.
  • Ensure that appropriate steps are taken to implement information security requirements for IT systems throughout their life cycle, from the requirements definition phase through disposal.
  • Develop and present, highly technical information and presentations to non-technical audiences at all levels of the organization.


Required Qualifications:
  • 3-6 years of strong information security experience and technical security experience 
  • Minimum of 10 years of IT and IT compliance experience
  • Strong experience with security and privacy compliance frameworks.
  • Demonstrated success in managing external audits and internal assessments.
  • Extensive experience using and securing AWS cloud environments
  • Extensive experience with Application Security on internet-facing systems
  • Strong understanding of SaaS and internet technologies.
  • Strong management and mentoring skills
  • Prior experience in healthcare technology or other regulated industries is highly desirable.
  • Proven track record of securing AWS workloads, managing risk, conducting audits, and implementing security best practices.
  • Industry certifications such as AWS Certified Security Specialty are preferred.
  • BS in Computer Science, Information Systems, or related field preferred
  • Must be able to demonstrate integration of regulations and processes such as SOC2, ISO, HIPAA, and Hi-Trust
  • Strong project management and organizational skills; ability to manage multiple initiatives simultaneously.
  • Must have exceptional writing capabilities on technical and process security controls
  • Must be able to articulate risk mitigation and answer IT Security questions in a professional manner


$130,000 - $160,000 a year
This is the standard base pay range for this role. In addition to a base salary, this position is also eligible for an amazing benefits package. The actual amount of salary offered will vary depending on the position level, experience, performance, and location. This position is fully remote and open to applicants in the continental United States.

This position is a remote position and open to applicants in the continental United States.


Why Bluesight?

Bluesight’s culture is built on innovation and teamwork. There’s room to grow and opportunities to take initiative. You will partner with sharp, motivated teammates looking to disrupt a massive industry—and have fun doing it.  We truly believe that where you work and what you do matters.  Join us as we revolutionize the hospital pharmacy landscape!

-Competitive salary

-Time off when you need it – unlimited vacation days!

-Generous insurance coverage

-401k program with a company match

-Fun, collaborative culture!


EOE AA M/F/VET/Disability


All qualified applicants will receive consideration for employment and will not be discriminated against on the basis of race, religion, color, national origin, sex, protected veteran status, disability, or any other basis protected by federal, state or local laws.

Bluesight Glassdoor Company Review
4.4 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
Bluesight DE&I Review
3.6 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
CEO of Bluesight
Bluesight CEO photo
Kevin MacDonald
Approve of CEO

Average salary estimate

$145000 / YEARLY (est.)
min
max
$130000K
$160000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Security Compliance and Risk Manager, Bluesight

Join Bluesight as our new Security Compliance and Risk Manager, where you’ll play a crucial role in safeguarding sensitive healthcare data and ensuring our IT security remains top-notch! At Bluesight, we’re all about developing innovative solutions that enhance safety and visibility within health systems and improve patient outcomes. This position is an exciting opportunity for someone with a strong background in information security and cloud technologies, particularly AWS. As the Security Compliance and Risk Manager, you'll oversee compliance monitoring, conduct security audits, and lead risk assessments while collaborating closely with our engineering and IT teams. We’re looking for a strategic thinker who can execute robust security strategies and manage our Security Program, including vulnerability management and penetration testing. Your responsibilities will also include developing security policies and conducting annual risk analyses to protect our cloud-based systems and data. If you have experience working in healthcare technology or regulated industries and a passion for managing risk, this will be an exciting avenue for you to showcase those skills! Not only do we offer a competitive salary, but you’ll also enjoy an incredible benefits package that includes unlimited vacation days and a fun, collaborative culture. We can’t wait for you to join us in revolutionizing the hospital pharmacy landscape!

Frequently Asked Questions (FAQs) for Security Compliance and Risk Manager Role at Bluesight
What are the key responsibilities of a Security Compliance and Risk Manager at Bluesight?

At Bluesight, the Security Compliance and Risk Manager is responsible for overseeing compliance monitoring, conducting security audits, performing security risk assessments, and leading the annual SOC2 Type 2 renewal certification. This role also focuses on maintaining the Security Program, developing security policies, managing overall security risks, and providing guidance on security best practices.

Join Rise to see the full answer
What qualifications are required for the Security Compliance and Risk Manager position at Bluesight?

The ideal candidate for the Security Compliance and Risk Manager role at Bluesight should have 3-6 years of strong information security experience and a minimum of 10 years of IT and compliance experience. Familiarity with AWS cloud environments, security compliance frameworks, and a background in healthcare technology is highly desirable.

Join Rise to see the full answer
How important is cloud security knowledge for a Security Compliance and Risk Manager at Bluesight?

Cloud security knowledge is crucial for a Security Compliance and Risk Manager at Bluesight, as this role heavily involves securing our cloud infrastructure and ensuring data confidentiality. Candidates are expected to have extensive experience in AWS security practices and a solid understanding of SaaS and internet technologies.

Join Rise to see the full answer
What does the application process look like for the Security Compliance and Risk Manager role at Bluesight?

The application process for the Security Compliance and Risk Manager position at Bluesight typically includes submitting your resume, completing a preliminary phone interview, and a series of detailed interviews with team members and executives. Candidates should be prepared to discuss their relevant experience, particularly around security practices and risk management.

Join Rise to see the full answer
What makes Bluesight a great place to work for a Security Compliance and Risk Manager?

Bluesight stands out as a fantastic workplace for a Security Compliance and Risk Manager due to its innovative culture, collaborative environment, and the opportunity to make a real impact on healthcare technology. With competitive salaries, unlimited vacation days, and a supportive team, Bluesight is committed to your personal and professional growth.

Join Rise to see the full answer
Common Interview Questions for Security Compliance and Risk Manager
Can you describe your experience with cloud security, particularly in AWS?

When answering this question, emphasize specific projects where you've secured AWS workloads. Discuss any security measures you've implemented and how they contributed to the overall risk management strategy. Be sure to mention any relevant certifications you might hold.

Join Rise to see the full answer
How do you conduct a security risk assessment, and what methodologies do you use?

Outline a structured approach to conducting security risk assessments by describing methodologies like NIST, OCTAVE, or FAIR. Provide examples of how you’ve identified risks, assessed their impact, and developed mitigation strategies.

Join Rise to see the full answer
What are the key components of a successful security compliance program?

Highlight essential components such as policy creation, compliance monitoring, employee training, and incident response plans. Discuss how each part contributes to maintaining regulatory compliance and securing sensitive data.

Join Rise to see the full answer
How do you ensure that security policies are effectively communicated and implemented across the organization?

Focus on the importance of collaboration with various teams to ensure policies are clear and accessible. Mention how you might utilize training programs and regular updates to keep everyone informed and engaged in security practices.

Join Rise to see the full answer
What experience do you have in managing external audits?

Share your experience in preparing for and managing audits, discussing how you’ve facilitated communication and documentation between your company and auditors. Highlight any successful outcomes from past audits you managed.

Join Rise to see the full answer
How would you approach incident response planning?

Discuss the critical steps in incident response planning, such as creating an incident response team, developing a communication strategy, and simulating real-world scenarios. Stress the importance of regular updates and training sessions.

Join Rise to see the full answer
What is the significance of SOC2 audits in your work?

Explain the role of SOC2 audits in establishing trust with your clients and stakeholders. Detail how you prepare for these audits and the ways in which they contribute to improving the security posture of the organization.

Join Rise to see the full answer
Can you elaborate on your experience with vulnerability management?

Provide insights into the tools and processes you use for vulnerability management. Mention your experiences in identifying, prioritizing, and remediating vulnerabilities, as well as the importance of continuous monitoring.

Join Rise to see the full answer
What strategies do you employ for employee security awareness training?

Highlight the importance of fostering a security-driven culture and explain how you design training programs that engage employees. Mention incorporating real scenarios and regular refreshers to keep security awareness top-of-mind.

Join Rise to see the full answer
How do you manage multiple security initiatives simultaneously?

Discuss your project management skills and the tools you use to prioritize tasks effectively. Talk about the importance of clear communication and collaboration across teams to ensure the successful execution of multiple initiatives.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 2 days ago
Customer-Centric
Mission Driven
Inclusive & Diverse
Work/Life Harmony

Join Bluesight as an Event and Marketing Coordinator and play a vital role in creating impactful event experiences for the healthcare industry.

Posted 13 days ago

Enhance your skills as a Java Developer intern at Fiserv, a leader in the fintech industry, through a comprehensive summer internship program.

Photo of the Rise User
American Express Remote Phoenix, Arizona, United States
Posted 5 hours ago
Inclusive & Diverse
Empathetic
Collaboration over Competition
Growth & Learning
Transparent & Candid
Medical Insurance
Dental Insurance
Mental Health Resources
Life insurance
Disability Insurance
Child Care stipend
Employee Resource Groups
Learning & Development

Join American Express as an Agile Champion to drive technical excellence and innovative payment solutions across teams.

Join Cal State Fullerton as an Information Technology Consultant, delivering critical technical support and training to enhance educational experiences.

Photo of the Rise User

Join Ozarks Technical Community College as an IT Business Analyst, where you'll play a key role in aligning technology solutions with business needs.

Posted 14 days ago

EFG is looking for a passionate Senior Security Engineer to enhance their information security across innovative gaming technologies.

Photo of the Rise User
Amgen Remote Portugal - Lisbon
Posted 12 days ago

Join Amgen as a Scrum Master and lead Agile teams to deliver impactful digital solutions in healthcare innovation.

ngc Hybrid United States-Maryland-Hollywood
Posted 7 days ago

Join Northrop Grumman as a Windows Systems Administrator and contribute to innovative systems in a dynamic environment.

Join Straight Edge Technology as an experienced Level 3 System Administrator and help build and maintain a secure and efficient IT infrastructure.

Photo of the Rise User
Inclusive & Diverse
Empathetic
Collaboration over Competition
Growth & Learning
Transparent & Candid
Medical Insurance
Dental Insurance
Mental Health Resources
Life insurance
Disability Insurance
Child Care stipend
Employee Resource Groups
Learning & Development
Photo of the Rise User
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Transparent & Candid
Growth & Learning
Fast-Paced
Collaboration over Competition
Take Risks
Friends Outside of Work
Passion for Exploration
Customer-Centric
Reward & Recognition
Feedback Forward
Rapid Growth
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Paternity Leave
Fully Distributed
Flex-Friendly
Some Meals Provided
Snacks
Social Gatherings
Pet Friendly
Company Retreats
Dental Insurance
Life insurance
Health Savings Account (HSA)
Photo of the Rise User
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Transparent & Candid
Growth & Learning
Fast-Paced
Collaboration over Competition
Take Risks
Friends Outside of Work
Passion for Exploration
Customer-Centric
Reward & Recognition
Feedback Forward
Rapid Growth
Medical Insurance
Paid Time-Off
Maternity Leave
Mental Health Resources
Equity
Paternity Leave
Fully Distributed
Flex-Friendly
Some Meals Provided
Snacks
Social Gatherings
Pet Friendly
Company Retreats
Dental Insurance
Life insurance
Health Savings Account (HSA)

Transform the health system pharmacy supply chain through software, connecting hospitals and manufacturers from production through utilization of medications.

23 jobs
MATCH
Calculating your matching score...
BADGES
Badge ChangemakerBadge Flexible CultureBadge Future MakerBadge Work&Life BalanceBadge Rapid Growth
CULTURE VALUES
Customer-Centric
Mission Driven
Inclusive & Diverse
Work/Life Harmony
FUNDING
SENIORITY LEVEL REQUIREMENT
INDUSTRY
TEAM SIZE
No info
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
April 20, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
Someone from OH, Westerville just viewed Summer Internship - Public Health Data Science at Cotiviti
V
Someone from OH, Cincinnati just viewed Part-Time Executive/Personal Assistant at VirtuHire
Photo of the Rise User
Someone from OH, Chillicothe just viewed Area Manager at The Hemp Co by Curaleaf at Curaleaf
Photo of the Rise User
Someone from OH, Cincinnati just viewed VP, B2B/Integrated Marketing at TEGNA Inc.
Photo of the Rise User
Someone from OH, Cincinnati just viewed Director, Marketing and GTM Strategy at Aspen Dental
Photo of the Rise User
Someone from OH, Cincinnati just viewed Senior Vice President, JLLIPT Marketing at JLL
Photo of the Rise User
Someone from OH, Cincinnati just viewed Vice President of Marketing at Forum Health
Photo of the Rise User
Someone from OH, Cincinnati just viewed Vice President of Marketing at Beacon
Photo of the Rise User
Someone from OH, Cincinnati just viewed Director of Growth Marketing at Sundays for Dogs
P
Someone from OH, Cincinnati just viewed Vice President of Marketing at ProCaps Labs
Photo of the Rise User
Someone from OH, Cincinnati just viewed Vice President, Marketing at Inmagine
Photo of the Rise User
Someone from OH, Cincinnati just viewed VP of Marketing at IDIQ
Photo of the Rise User
Someone from OH, Cincinnati just viewed VP of Marketing at Vultron
Photo of the Rise User
Someone from OH, Cincinnati just viewed Marketing Manager (Remote - US) at Jobgether
F
Someone from OH, Cincinnati just viewed Head of Marketing at FoodHealth Company
Photo of the Rise User
Someone from OH, Cincinnati just viewed VP, Paid Marketing (Remote - US) at Jobgether
Photo of the Rise User
Someone from OH, Cincinnati just viewed Hospital Marketing at Datadog
Photo of the Rise User
Someone from OH, Cincinnati just viewed Vice President, Institutional Marketing at Tutor.com
Photo of the Rise User
Someone from OH, Cincinnati just viewed Director, Marketing Campaign Management at Humana
J
Someone from OH, Cleveland just viewed Sprinkler Service Technician IV at JCI
Photo of the Rise User
18 people applied to SOC Analyst I at CBIZ