Founded in 2008 and headquartered in NYC, Rethink First is a pioneer and market leader in behavioral and mental health technology. Developed by nationally recognized experts in the field, Rethink’s award-winning online solutions feature comprehensive video-based training and education programs and sophisticated behavior intervention planning tool for individuals and caregivers. Rethink’s offerings include individualized assessments, online skills-based activities, access to remote clinician-led consultations and more.
The Rethink First platform is used by Fortune 500 companies, school districts, government agencies, public and private behavioral health providers, and families caring for individuals with developmental disabilities worldwide.
The Information Security and Compliance Manager is a critical role to RethinkFirst. We are seeking a self-starter, individual contributor to work across technical, legal, and business stakeholders to ensure that systems across Rethink are aligned with current information security standards. This role will report to the Director, DevSecOps and provide policies, guidance and strategic direction to the entire technology group.
Primary Responsibilities:- Work independently to manage the company’s information security program, including policies, standards and procedures.
- Provide security awareness, education, and training based on industry best practices and internal policies.
- Direct Vulnerability Management - scanning for vulnerabilities and contributing to remediation efforts. Follow up on Pentest results.
- Monitor compliance with security standards and execute information security risk assessment, including SOC2, HiTrust.
- Provide security and compliance frameworks.
- Monitor and drive compliance efforts corporate-wide.
- Maintain awareness of trends in the latest cloud technologies, security regulations, and operational requirements, and advise across the business.
- Work with internal departments in the organization to reduce risk and with external clients to explain security posture.
- Coordinate compliance/privacy/process audits with external vendors, manage and address findings and act as a SME to guide the process internally.
- Participate in vendor security review process - both for internal vendors and external prospects.
- Participating in prospect security-related review process. Including completing information security questionnaires for Sales RFP's, participating on sales calls for security due diligence.
- Provide threat analysis of emerging vulnerabilities.
- Knowledge of WAF’s and IDS solutions.
- Participate in Risk Management and mitigation efforts.
- Participate in SDLC software hardening.
- Disseminate corporate security and compliance training.
- Work with outside vendors to manage security monitoring.
- Manage SIEM alerts and tuning.
- Lead efforts forensic efforts in the resolution of security incidents. Must perform network, application, and log correlation, analysis, and alerts.
Requirements- Experience implementing and managing compliance with HIPPA, SOC2 & HiTrust; Familiarity with applicable legal / regulatory requirements for HIPAA, GDPR.
- Excellent communication and interpersonal skills, with the ability to collaborate effectively with technical and non-technical stakeholders.
- In-depth knowledge of Data Loss Prevention.
- In-depth HIPPA Compliance experience is required.
- Knowledge of Azure cloud.
- Bachelor's degree in Information Security, Computer Science, or a related field is required (Master's degree preferred).
- Knowledge of NIST (National Institute of Standards and Technology) cybersecurity framework is preferred.
Benefits
- 401k plus company match
- Competitive medical, dental, and vision benefits
- 11 paid holidays
- Access to RethinkCare and ability to gift to 5 friends and family members
Location: Remote opportunities are available to candidates who reside in the following states: AL, AZ, CT, FL, GA, IL, IN, KY, LA, MA, MD, MI, MO, NC, NH, NJ, NV, OH, PA, TX, VA, WA, WI
Our commitment to an inclusive workplace:
RethinkFirst is an equal opportunity employer and is committed to providing a workplace free from harassment and discrimination. We celebrate the unique differences of our employees because that is what drives curiosity, innovation, and the success of our business. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, gender identity or expression, age, marital status, veteran status, disability status, pregnancy, parental status, genetic information, political affiliation, or any other status protected by the laws or regulations in the locations where we operate. Accommodations are available for applicants with disabilities.
JazzHR Privacy Policy
JazzHR Terms of Use
California Privacy Notice
#remote