Information Security Officer

Security EngineerSecurity EngineerFull TimeRemoteTeam 2-10

Location

United States

Posted

8 days ago

Salary

Not specified

No structured requirement data.

Job Description

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more.

Role Description

This role involves serving as Bloom's Information Security Officer, focusing on building security into the foundation of the organization.

  • Own the security program end-to-end: designing and implementing controls, architecting systems to prevent breaches, and driving a culture of proactive risk management.
  • Use data and metrics to measure effectiveness, identify gaps, and demonstrate continuous improvement.
  • Build and lead a proactive security program with a prevention-first mindset.
  • Evaluate, refine, and enforce security policies, standards, and procedures.
  • Conduct regular risk assessments and threat modeling.
  • Lead tabletop exercises, penetration testing, and red team activities.
  • Build, operate, and monitor the security program, ensuring effective education of stakeholders.
  • Serve as the primary owner for HIPAA, HITRUST, and SOC 2 Type II compliance oversight.
  • Maintain knowledge of NIST standards and emerging healthcare security regulations.
  • Translate regulatory requirements into engineering specifications and operational procedures.
  • Partner with Engineering, IT, and DevOps to embed security controls into infrastructure.
  • Define and track key security metrics and KPIs.
  • Develop and deliver security awareness training.

Qualifications

  • Bachelor’s degree in information systems, Computer Science, Engineering, or a related technical field, or a minimum of four (4) years of experience in lieu of degree.
  • 7+ years of progressive experience in information security, with at least 3 years in a security program leadership role.
  • Previous experience guiding an organization through successful assessments in SOC 2 and/or HITRUST R2.

Requirements

  • Deep expertise in healthcare security and privacy regulations, particularly HIPAA Security Rule requirements.
  • Hands-on experience achieving and maintaining HITRUST CSF certification and SOC 2 Type II attestation.
  • Strong working knowledge of NIST frameworks and FedRAMP.
  • Proven track record implementing technical security controls and managing a comprehensive security program.
  • Experience with cloud security (AWS, Azure, or GCP) and modern DevSecOps practices.
  • Demonstrated ability to use metrics and data analysis to drive security program improvements.
  • Excellent communication skills—able to translate technical risk into business terms for executives and board members.
  • Relevant certifications: CISSP, CISM, HCISPP, HITRUST CCSFP, or equivalent.
  • Experience in a high-growth healthcare technology or digital health environment.
  • First-hand experience building security programs or security-first architectures.
  • Experience with GRC platforms and security automation tools.

Benefits

  • Competitive compensation.
  • Comprehensive health coverage.
  • Long-term growth opportunities.
  • Remote work environment.
  • BeBloom™, a proprietary employee training and engagement program.

Core Values

  • Put People First: Uphold and promote a people-first culture within the organization.
  • Be Stronger Together: Embrace a team player mentality.
  • Do What’s Right: Adhere to high ethical standards.
  • Embrace a Growth Mindset: Embrace a culture of continuous learning.
  • Drive Solutions: Demonstrate ingenuity and skill by sharing ideas and solutions.

Job Requirements

  • Bachelor’s degree in information systems, Computer Science, Engineering, or a related technical field, or a minimum of four (4) years of experience in lieu of degree.
  • 7+ years of progressive experience in information security, with at least 3 years in a security program leadership role.
  • Previous experience guiding an organization through successful assessments in SOC 2 and/or HITRUST R2.
  • Deep expertise in healthcare security and privacy regulations, particularly HIPAA Security Rule requirements.
  • Hands-on experience achieving and maintaining HITRUST CSF certification and SOC 2 Type II attestation.
  • Strong working knowledge of NIST frameworks and FedRAMP.
  • Proven track record implementing technical security controls and managing a comprehensive security program.
  • Experience with cloud security (AWS, Azure, or GCP) and modern DevSecOps practices.
  • Demonstrated ability to use metrics and data analysis to drive security program improvements.
  • Excellent communication skills—able to translate technical risk into business terms for executives and board members.
  • Relevant certifications: CISSP, CISM, HCISPP, HITRUST CCSFP, or equivalent.
  • Experience in a high-growth healthcare technology or digital health environment.
  • First-hand experience building security programs or security-first architectures.
  • Experience with GRC platforms and security automation tools.

Benefits

  • Competitive compensation.
  • Comprehensive health coverage.
  • Long-term growth opportunities.
  • Remote work environment.
  • BeBloom™, a proprietary employee training and engagement program.
  • Core Values
  • Put People First: Uphold and promote a people-first culture within the organization.
  • Be Stronger Together: Embrace a team player mentality.
  • Do What’s Right: Adhere to high ethical standards.
  • Embrace a Growth Mindset: Embrace a culture of continuous learning.
  • Drive Solutions: Demonstrate ingenuity and skill by sharing ideas and solutions.

Related Categories

Related Job Pages

More Security Engineer Jobs

Security Engineer8 days ago
Full TimeRemoteTeam 5,001-10,000Since 2000H1B No Sponsor

The teacher is responsible for delivering specific course content in an online environment, providing instruction, support, and guidance while focusing on individual student needs. This includes monitoring progress via the learning management system and actively working with students and parents to plan for post-secondary success.

United States

Enterprise Security Architect

Navitus Health Solutions, LLC

Navitus - Putting People First in Pharmacy - Navitus was founded as an alternative to traditional pharmacy benefit manager (PBM) models. We are committed to removing cost from the drug supply chain to make medications more affordable for the people who need them. At Navitus, our team members work in an environment that celebrates diversity, fosters creativity and encourages growth.

Security Engineer8 days ago
Full TimeRemoteTeam 1,001-5,000

The Enterprise Security Architect participates in designing, constructing, maintaining, and enhancing the IT Security and infrastructure landscape, collaborating with stakeholders to define requirements and recommend solutions. This role involves administering security tools and architecting long-term and short-term solutions to improve the overall security posture.

United States
$120K - $150K / year

Lead Cyber Security Architect/Engineer

Solstice Advanced Materials

Solstice Advanced Materials is a leading global specialty materials company that advances science for smarter outcomes. Solstice offers high-performance solutions that enable critical industries and applications, including refrigerants, semiconductor manufacturing, data center cooling, nuclear power, protective fibers, healthcare packaging and more. Recognized for developing next-generation materials through some of the industry's most renowned brands such as Solstice®, Genetron®, Aclar®, Spectra®, Fluka™, and Hydranal™. Partnering with over 3,000 customers across more than 120 countries and territories. Supported by a robust portfolio of over 5,700 patents. Approximately 4,000 employees worldwide drive innovation in materials science.

Security Engineer8 days ago
Full TimeRemoteTeam 1,001-5,000

The Lead Cybersecurity Architect/Engineer will act as the technical lead for the Security Operations Center, guiding analysts during complex investigations and major incidents. Key duties include designing and implementing threat detections, leading incident response activities, and developing detection engineering practices aligned with adversary behaviors.

United States
$183K - $250K / year
Security Engineer8 days ago
Full TimeRemoteTeam 201-500H1B No Sponsor

Sales Executive driving growth for Offensive Security Services Consulting portfolio

CloudCyber SecuritySDLC
District of Columbia + 6 moreAll locations: District of Columbia, North Carolina, Maryland, Pennsylvania, Virginia, Washington, West Virginia
$120K - $170K / year