Medicom Group logo
Medicom Group

Tailored ,Flexible & Fast

Director of Legal, Risk & Compliance

DirectorDirectorFull TimeRemoteTeam 11-50Since 2009H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

9 days ago

Salary

Not specified

HIPAAHITRUSTSOC 2GDPRFed RAMPCISSPRisk ManagementComplianceContract ReviewAudit ManagementInformation SecurityHealthcare Regulations

Job Description

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more.

Role Description

Medicom is seeking a Director of Legal, Risk & Compliance (GRC) to lead the Company’s information security, regulatory compliance, and contractual risk management programs. As a healthcare data company, Medicom must meet the highest standards for data protection while supporting rapid product development and enterprise growth.

This role will own Medicom’s security and compliance frameworks (HIPAA, HITRUST, SOC 2, GDPR, FedRAMP readiness) while also serving as the primary reviewer of customer contractual obligations. The Director will partner closely with Engineering, Sales, Legal, and executive leadership to ensure security, compliance, and legal commitments are aligned and operationally achievable.

  • Own and lead Medicom’s information security and compliance programs, ensuring adherence to HIPAA, HITRUST, SOC 2, GDPR, and evolving regulatory standards.
  • Define, document, and continuously improve the company’s security control framework and risk management processes.
  • Leadership sponsor for SOC 2 audits and other certification efforts, coordinating with third-party auditors and internal stakeholders.
  • Prepare the organization for advanced frameworks and certifications, including FedRAMP readiness.
  • Serve as chair of the Confidentiality & Security Team (CST), including meeting leadership and agenda setting.
  • Review and assess customer MSAs, BAAs, and ISAs to ensure alignment with Medicom’s security controls and compliance posture.
  • Partner with Sales and Legal during enterprise negotiations to balance commercial objectives with risk mitigation.
  • Ensure ongoing compliance with contractual obligations, federal and state regulations, and customer procurement policies.
  • Coordinate with external counsel as appropriate regarding legal contracts and compliance matters.
  • Partner closely with Engineering to embed security and compliance requirements into product design and architecture.
  • Act as a trusted advisor across the organization on security, compliance, and risk-related matters.

Qualifications

  • 8–12+ years of experience in information security, governance, compliance, and legal within healthcare, health tech, or SaaS environments.
  • CISSP strongly preferred (or equivalent advanced security certification).
  • Deep working knowledge of HIPAA, SOC 2, HITRUST, GDPR, CCPA; FedRAMP experience strongly preferred.
  • Experience leading audits, certifications, and regulatory assessments.
  • Demonstrated experience reviewing and negotiating contractual language (MSAs, BAAs, DPAs, ISAs).
  • Strong communication skills and ability to influence cross-functional stakeholders.

Equal Opportunity Employer Statement

Medicom Technologies is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.

Reasonable Accommodation Notice

If you require a reasonable accommodation in the application process, please contact careers@medicom.us to discuss your needs.

Job Requirements

  • 8–12+ years of experience in information security, governance, compliance, and legal within healthcare, health tech, or SaaS environments.
  • CISSP strongly preferred (or equivalent advanced security certification).
  • Deep working knowledge of HIPAA, SOC 2, HITRUST, GDPR, CCPA; FedRAMP experience strongly preferred.
  • Experience leading audits, certifications, and regulatory assessments.
  • Demonstrated experience reviewing and negotiating contractual language (MSAs, BAAs, DPAs, ISAs).
  • Strong communication skills and ability to influence cross-functional stakeholders.
  • Equal Opportunity Employer Statement
  • Medicom Technologies is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.
  • Reasonable Accommodation Notice
  • If you require a reasonable accommodation in the application process, please contact careers@medicom.us to discuss your needs.

Related Categories

Related Job Pages

More Director Jobs

MeanPug Digital logo

Account Director

MeanPug Digital

Loyal Marketing for Ambitious Law Firms, we specialize in branding, web, CRM, software development, SEO, and digital ads

Director9 days ago
Full TimeRemoteTeam 11-50Since 2017

The Account Director is a senior leadership role responsible for overseeing a team of SEO Managers (Account Strategists) and ensuring the quality, consistency, and strategic integrity of work delivered across client accounts. This is not a purely hands...

SEOLocal SEOTechnical SEOGoogle Business ProfileCitation ManagementLink BuildingTeam LeadershipClient Strategy
United States
Full TimeRemote

This is a critical role in driving growth in our network of compounding pharmacies. The Director will play a pivotal role in managing a team of provider relations representatives and overseeing relationships with top providers across our pharmacy network. This role requires a str...

Sales LeadershipBusiness DevelopmentAccount ManagementKPI AnalysisTeam ManagementHealthcare Industry KnowledgeCompounding Pharmacy OperationsRegulatory ComplianceMarket AnalysisNegotiation
United States
Healthcare Information and Management Systems Society logo

Senior Director, Content, Engagement, & Reputation

Healthcare Information and Management Systems Society

At HIMSS, we are a catalyst for change in the health and wellness ecosystem. Guided by our vision to realize the full health potential of every human, everywhere, and our mission to reform the global health ecosystem through the power of information and technology, we embrace transformation as our “why” and technology as our “how.”

Director9 days ago
Full TimeRemoteTeam 201-500

This strategic leadership role is responsible for shaping, elevating, and integrating the global brand narrative across all audiences and channels, driving cohesive enterprise storytelling, overseeing communications, and stewarding the organization's global reputation. Key duties include leading global content strategy, managing internal and external communications, and strengthening audience engagement through data-informed methods.

CommunicationsPublic RelationsContent StrategyMedia RelationsExecutive CommunicationsInternal CommunicationsReputation ManagementEnterprise StorytellingCrisis ManagementAnalytics
United States
Full TimeRemoteTeam 10,001+

The Senior Director will lead U.S. federal government affairs initiatives to advocate for Danaher Diagnostics' tests and business units before policymakers and trade associations. Key duties include building trusted relationships with federal agencies, monitoring policy developments, and driving constructive solutions to advance patient access to diagnostics.

Government RelationsHealth PolicyStrategic PlanningStakeholder EngagementUS Federal Policy
United States
$200K - $225K / year