Live opening · Posted 3 days ago

VP, Information Security

MatrixCare · United States (Remote)
Linkedin Yes
JobBeeper subscribers received an alert for this role.

At a glance

The key details from the original listing.

Posted 3 days ago
CompanyMatrixCare
LocationUnited States (Remote)
Work modeYes
SkillsAWS
SourceLinkedin
ListedPosted 3 days ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
13 min from Linkedin publishing this role to us finding it
10 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
61,658 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

Highlights
Location Remote, US
Start Date Nov 2, 2026
Work Location Allows Remote Work
Skills
HealthTech
HIPPA
HITECH
HITRUST
ISO27001
SOC2
NIST
AWS
Description
About MatrixCare
MatrixCare provides software solutions to more than 15,000 providers supporting skilled nursing, senior living and long-term care, life plan communities, and home health and hospice care. A multi-year winner of the Best in KLAS award, MatrixCare is trusted by thousands of facility-based and home-based care organizations to improve provider efficiencies and promote a better quality of life for the people they serve. For more information, visit www.matrixcare.com.
About The Role
The Vice President of Information Security will lead the information security program for MatrixCare and its affiliate companies and own the confidentiality, integrity, and availability of the systems and data our customers trust us with. Our software supports skilled nursing, home health, hospice, senior living, and life plan communities, so protected health information sits at the center of nearly everything we build. Protecting it is a patient safety obligation as much as a technical one.
This leader sets security strategy, owns our regulatory and contractual obligations including the HIPAA Security Rule and SOC 2, runs incident response, and represents MatrixCare's security posture to customers, auditors, and executive leadership. The team is small by design and leveraged through a managed security partner, so the job is about building capability and judgment rather than headcount.
The VP, Information Security will work closely with the Chief Technology Officer for security execution across MatrixCare’s technology and product environments, including delivery against priorities, remediation commitments, and security outcomes established by the CTO in coordination with the General Counsel, with the CTO having a substantive role in setting objectives and evaluating performance.
This is a hands-on leadership role. We are looking for someone who moves comfortably between a Board and executive level risk conversation and a deep technical review with engineers, and who raises the security bar across the organization through partnership and practical tooling rather than mandate.
What You'll Do
Own the information security strategy and annual roadmap, aligned to business objectives, customer commitments, and regulatory obligations.
Build and maintain the security policy set, standards, and procedures, and keep them current, enforceable, and mapped to the frameworks we are measured against.
Own the enterprise security risk register. Run recurring risk assessments, quantify exposure in business terms, and drive remediation to closure with named owners and dates.
Own the HIPAA Security Rule program, including the security risk analysis, the risk management plan, and the supporting documentation that has to hold up under scrutiny.
Maintain SOC 2 Type II attestation, including control design, evidence collection, auditor management, and remediation of exceptions. Advise on additional frameworks such as HITRUST and NIST Cybersecurity Framework alignment based on customer demand and cost, not certification for its own sake.
Own detection, monitoring, and response across cloud and corporate environments, delivered largely through a managed security partner whose scope, quality, and cost you manage.
Own the incident response plan and serve as incident commander for major events, including the technical investigation and supporting Legal and Privacy in HIPAA breach assessments and notification determinations, and coordination with affected customers.
Run vulnerability management and the penetration testing program end to end, with risk-based prioritization, published remediation service levels, and transparent reporting against them.
Own identity and access management, including identity governance, privileged access, secrets management, periodic access reviews, and authentication standards for workforce and customer-facing access.
Embed security into the software development lifecycle so it raises quality rather than slowing delivery, covering pipeline scanning, the gating policy, the exception process, and threat modeling for changes that touch protected health information.
Define security and privacy requirements for AI capabilities and partner with Legal and Privacy on applicable privacy and data governance requirements, including data boundaries, model and agent access control, human oversight, and audit logging.
Own data protection across the estate: classification, encryption at rest and in transit, key management, and rules governing use of production data in non-production environments.
Run third-party security assessment and ongoing monitoring for suppliers and business associates, sized to the risk each one actually presents.
Own customer security reviews, questionnaires, and audit support, reduce the cycle time they consume, and serve as the security voice in strategic customer and prospect conversations.
Own security awareness and phishing simulation, and partner with Legal, Privacy, and Compliance on HIPAA awareness training, measured on behavior change rather than completion rates.
Recruit, coach, and retain a small, high-caliber team across United States and India based operations, and manage the security budget and tooling portfolio with an eye toward consolidation.
Maintain direct accountability to the Chief Technology Officer for execution of agreed security priorities, remediation commitments, architecture standards, and security outcomes across product, cloud, infrastructure, and corporate technology environments.
What You'll Bring
Required Qualifications
10+ years in information security, including 4+ years leading a security team or function with full program accountability.
Direct experience leading security in healthcare, health technology, or a comparably regulated environment where protected health information or equivalently sensitive data is handled at scale.
Ownership of a security compliance program, including responsibility for audit outcomes and direct engagement with external auditors and assessors.
Experience building security capability where it did not previously exist: authoring policy, standing up process, and implementing tooling without an established program to inherit.
Working command of the HIPAA Security Rule, HITECH, breach notification requirements, and SOC 2 Trust Services Criteria, with practical exposure to at least one of HITRUST, ISO 27001, or the NIST Cybersecurity Framework.
Cloud security depth in Amazon Web Services, including identity and access management, key management, network controls, logging, and posture management.
Application security depth, including secure development lifecycle practice, pipeline scanning, threat modeling, and driving penetration test findings to verified closure.
Identity and access management depth, including identity governance, privileged access, single sign on, and multifactor authentication.
Security operations experience across detection, security information and event management, endpoint detection and response, and real incident response, including the decisions you made under pressure and what you changed afterward.
Experience managing a managed security service provider while retaining internal policy authority and technical judgment.
Experience presenting security posture and risk to executive leadership and to customers, translating technical exposure into business consequence.
Experience managing a security budget and selecting, negotiating with, and managing security vendors.
Post-acute care, electronic health records, or another clinical software domain is a plus, as is experience in a software product company rather than a provider or payer environment.
Bachelor's degree in computer science, information systems, cybersecurity, or a related field; equivalent practical experience is welcome.
Preferred Qualifications
Practical experience securing AI or machine learning capability in a regulated environment, including data governance, model access control, and human oversight.
Experience in a private equity backed or high-growth environment, and with globally distributed teams including operations in India.
CISSP, CISM, or comparable certification preferred; equivalent depth of hands on program ownership will also be considered.
What Success Looks Like
SOC 2 Type II is maintained without qualification, and the HIPAA security risk analysis stays current and defensible.
Critical and high severity findings decline measurably, with mean time to remediate held within published service levels and every major incident closed with documented root cause and corrective action.
Security gates operate on changed code across priority products, all critical vendors are assessed and monitored on schedule, and customer security review cycle time is reduced.
The team is retained and engaged, roles are filled on plan, and the program is delivered within approved budget.
Why Join MatrixCare?
At MatrixCare, we are committed to fostering a culture where teammates can grow their careers and make an impact on the healthcare industry. We offer opportunit

Work arrangement
Yes

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App