Demo

Director of Information Security

Groups Recover Together
Burlington, MA Full Time
POSTED ON 1/21/2025
AVAILABLE BEFORE 3/21/2025
Director of Information Security
Location : Name Linked Remote - US
ID 2025-6362 Job Locations US-Remote | US-MA-Burlington Category Technology Type Regular Full-Time
Overview

Groups Recover Together was founded in 2014 to make treatment for opioid addiction respectful, accessible and affordable. We empower our members to regain control of their lives through a combination of community support, outpatient weekly group therapy and medication to manage withdrawal using buprenorphine and naltrexone. Today we serve ~1X,000 members weekly via virtual care and a network of offices across 15 states and growing.

We embrace innovation in our vision of tech enabled care delivery and are developing a cutting edge care delivery and member experience platform.

Responsibilities

The Director of Information Security will lead all security efforts within our IT organization, ensuring that the company's systems, data, and operations meet rigorous security and compliance standards. This role requires a strategic leader with deep expertise in healthcare compliance and a thorough understanding of state and federal privacy regulations including, but not limited to, HIPAA, HITECH, and 42 CFR Part 2. . You'll be responsible for shaping and executing security policies, overseeing risk management, and leading initiatives to protect against security threats in a complex, highly regulated environment. This position will report directly to the VP of Technology.

Key Responsibilities:
    Develop and Lead Security Strategy: Define and implement a comprehensive security strategy that aligns with regulatory requirements, including HIPAA, and supports the organization's business goals.
  • Governance and Compliance: Establish and maintain policies, procedures, and protocols to ensure compliance with healthcare regulations (HIPAA, HITECH), data protection laws, and industry best practices. Sit on the Compliance Committee and report on the status of the information security program and key initiatives.
  • Risk Assessment and Management: Lead security risk assessments, vulnerability testing, and remediation efforts across all systems, ensuring early identification and mitigation of potential threats.
  • Incident Response: Design and maintain incident response procedures. Act as the primary leader in case of a security breach, coordinating containment, investigation, and reporting efforts. Perform regular disaster recovery/business continuity tests to ensure organizational readiness.
  • Security Awareness: Develop and implement security training programs for all employees to foster a security-first culture and promote best practices.
  • Collaboration with IT and Product Teams: Work closely with IT, Product, and Development teams to integrate security requirements into system design, development, and deployment processes.
  • Third-Party and Vendor Management: Evaluate and manage security risks associated with third-party vendors, tools, and partnerships. Conduct regular audits of vendor compliance with security requirements.
  • Team Leadership and Development: Build, mentor, and lead a high-performing security team. Foster a collaborative, innovative, and supportive team environment.
Qualifications
Required Skills and Experience:
  • Education: Bachelor's degree in Information Security, Computer Science, or a related field. Advanced degrees or relevant certifications (e.g., CISSP, CISM, CHPS, CISA) are a plus.
  • Experience: 8 years of experience in IT security, with at least 3 years in a leadership role in a healthcare or highly regulated industry. Experience in a venture-backed environment is advantageous.
  • HIPAA Expertise: In-depth knowledge of HIPAA and HITECH regulations and compliance requirements is mandatory.
  • Technical Proficiency: Familiarity with network security, cloud infrastructure (e.g., Azure, AWS), and security best practices for on-premise, hybrid, and cloud-based systems. Strong understanding of cybersecurity threats, risks, and best practices, including cloud and on-premises security.
  • Regulatory Knowledge: Solid understanding of healthcare regulatory environments and standards, including NIST, HITRUST, SOC 2, and PCI-DSS compliance.
  • Risk Assessments: Experience in conducting risk assessments and audits.
  • Communication and Leadership: Proven ability to communicate complex security topics to technical and non-technical audiences. Strong leadership and interpersonal skills, with experience building and developing high-performing teams.
Connect With Us!
Not ready to apply? Connect with us for general consideration.

 

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Director of Information Security?

Sign up to receive alerts about other jobs on the Director of Information Security career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$194,072 - $240,547
Income Estimation: 
$220,784 - $286,649
Income Estimation: 
$194,072 - $240,547
Income Estimation: 
$220,784 - $286,649
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$220,784 - $286,649
Income Estimation: 
$270,069 - $359,305
Income Estimation: 
$152,549 - $188,894
Income Estimation: 
$194,072 - $240,547
Income Estimation: 
$135,994 - $168,063
Income Estimation: 
$161,209 - $233,553
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Groups Recover Together

Groups Recover Together
Hired Organization Address Charleston, WV Full Time
Member Access Staff Provider - KY / WV Location : Name Linked Kentucky - Remote 2025-6384 Job Locations US-KY-Remote | U...
Groups Recover Together
Hired Organization Address London, KY Full Time
Substance Use Counselor Schedule: Monday through Thursday (10-hour work-days) 9a-7p Salary: $49,000 - $65,000 Groups Rec...
Groups Recover Together
Hired Organization Address Keene, NH Full Time
Salary Range: $43,000.00 / yr to $46,000.00 / yr Schedule: Monday through Thursday, 9:00am to 7:00pm This role requires ...
Groups Recover Together
Hired Organization Address Louisville, KY Full Time
Member Access Staff Provider - KY/WV Location : Name Linked Kentucky - Remote ID 2025-6384 Job Locations US-KY-Remote | ...

Not the job you're looking for? Here are some other Director of Information Security jobs in the Burlington, MA area that may be a better fit.

Director of Information Security

Orbis, Burlington, MA

Director, Information Security

Analog Devices, Inc., Wilmington, MA

AI Assistant is available now!

Feel free to start your new journey!