Director of Cybersecurity & Compliance XpertDox, Inc Scottsdale, AZ Job Details Full-time $120,000 - $160,000 a year 3 hours ago Benefits Wellness program Stock options Relocation assistance Health insurance Unlimited paid time off Dental insurance Paid time off Parental leave Vision insurance 401(k) matching Life insurance Qualifications
AWS IAM SSO
Cloud identity and access management (IAM) DevSecOps Practices Authorization controls implementation IT user and group management Information security audit implementation Team leadership Encryption CISSP Governance, risk, and compliance (GRC) software
SOC 2 HIPAA
Health information compliance monitoring Public Cloud Data access controls implementation Vulnerability scanning IT control testing MFA Vulnerability management Cloud compliance
ISO 27001
Healthcare security compliance audits Access control management Web Application Security Testing CompTIA Security+ Information security auditing Cloud management Audit support Identity & access management
Full Job Description Director of Cybersecurity & Compliance Pay:
$120,000 to $160,000 per year
Location:
Scottsdale, AZ 85258
Type:
Full-time Entity:
XpertDox, Inc.
Department:
Information Security & Compliance On-site or remote: On-site, Monday through Friday Reports to: Chief Technology Officer About XpertDox XpertDox, Inc. is a physician-founded, venture-backed healthcare AI company headquartered in Scottsdale, Arizona, with a global delivery team in India. Our platform, XpertCoding, autonomously codes outpatient medical claims directly from clinical documentation using neural networks, machine learning, and natural language processing. Position Summary You will run security and compliance operations day to day at XpertDox. This is a hands-on role. XpertDox holds SOC 2 Type 2, ISO 27001, ISO 22301, and HIPAA attestations, with HITRUST certification underway, and you will execute and maintain that certification program. You will own the security questionnaires enterprise clients depend on, run identity and access management, and own application and web security across the platform. You own the execution that keeps our posture strong, audit-ready, and trusted by enterprise clients. Key Responsibilities In this role you will: Implement and maintain the controls behind SOC 2 Type 2, ISO 27001, ISO 22301, HIPAA, and HITRUST. Own evidence collection and continuous control monitoring, and prepare for and run third-party audits. Own completion of enterprise client security questionnaires, the answer library, and trust documentation, and provide the technical depth behind client security reviews. Own role-based access control, provisioning and deprovisioning, and periodic access reviews across cloud, on-premise, and remote access, including access from our global delivery team in India. Run MFA and single sign-on operations. Own application and web platform security, including secure development practices, code and dependency scanning, and secrets management. Drive remediation of security findings with engineering. Run vulnerability management and operate endpoint and cloud security controls. Coordinate penetration testing and track findings through remediation. Required Qualifications A relevant certification such as CISSP, CISM, CISA, GIAC, or Security+. Hands-on experience implementing and evidencing SOC 2 Type 2 and
ISO 27001
controls, ideally with GRC or continuous-monitoring tooling. 6+ years in cybersecurity and compliance, including hands-on ownership of security operations or a compliance program. Strong identity and access management experience (RBAC, SSO, MFA, and access reviews) across cloud and hybrid environments. Application and web security experience, including secure development practices, code and dependency scanning, and vulnerability remediation. Experience in healthcare, health-tech, or another PHI environment. Experience completing enterprise client security questionnaires and supporting audits. Team leadership or senior individual-contributor experience. Preferred Qualifications HITRUST control implementation experience. AWS security depth (IAM, KMS, security groups, and cloud security posture). Application security depth or secure-coding background. Experience working with distributed US and India teams. Location and Schedule This role is on-site at our Scottsdale, Arizona headquarters, Monday through Friday. It is not remote or hybrid. You must relocate to the Scottsdale area before your start date. Travel is minimal. Compensation Base salary of $120,000 to $160,000 per year, commensurate with experience. Incentive stock options. Relocation assistance, reimbursed against receipts. Benefits Health, dental, vision, and life insurance. 401(k) with matching. Unlimited PTO and parental leave. Wellness program, Friday lunch, and snacks.
To Apply Apply at https:
//careers.xpertdox.com/ XpertDox, Inc. is an equal opportunity employer.
Pay:
$120,000.00 - $160,000.00 per year
Benefits:
401(k) matching Dental insurance Health insurance Life insurance Paid time off Parental leave Relocation assistance