Remote
3 weeks ago

Job Overview

Job Type
FullTime
Pay
$190K – $230K

Job description

Salary:
USD 190,000 - 230,000 per year
Location:
Remote, United States
Work arrangement:
Remote

Role Summary

Job Title: Senior Director, Security & Compliance

About Prompt

Prompt is revolutionizing healthcare by delivering highly automated and modern software to rehab therapy businesses, their teams, and the patients they serve. As one of the fastest-growing companies in healthcare SaaS and the new standard in healthcare technology, we are committed to building a team that thrives in our fast-paced, innovative environment.

As Prompt continues to scale, maintaining the trust of our customers, partners, and the patients they serve is critical. We are seeking a Senior Director, Security & Compliance to lead and mature the security and compliance programs that support our continued growth.

The Senior Director, Security & Compliance serves as the company’s Compliance Officer and designated HIPAA Security Officer and is accountable for the company’s enterprise compliance and information security programs.

This role owns the governance, control environment, certification and audit programs, security risk management, policy framework, and cross-functional operating model required to maintain compliance with HIPAA/HITECH, SOC 2, and other applicable regulatory, contractual, and certification requirements.

The Senior Director will partner closely with Legal, Engineering, DevOps, IT, Product, People, Finance, and other business functions to translate requirements into clear controls, accountable owners, remediation plans, and sustainable operating processes. This is a hands-on leadership role for someone who wants to build and mature the program while leveraging strong technical resources across the organization.

Responsibilities

  • Serve as the company’s Compliance Officer and designated HIPAA Security Officer, leading the company’s compliance and information security programs.
  • Own HIPAA/HITECH compliance, including the Security Risk Analysis, risk-management plan, and ongoing oversight of required safeguards.
  • Be accountable for SOC 2 Type II and other compliance certifications, attestations, and assurance programs, including audit readiness, auditor relationships, remediation, and evidence sufficiency.
  • Own the company’s compliance and information-security policy framework, including policy development, review, approval, exceptions, and ongoing governance.
  • Establish clear ownership for controls across the organization and ensure deficiencies, risks, and remediation plans are identified, tracked, and appropriately escalated.
  • Partner with Engineering, DevOps, architecture, and IT leaders to evaluate security approaches and ensure technical controls appropriately address compliance and risk requirements.
  • Own the security incident-response framework and partner with Legal, Privacy, technical teams, and executive leadership on incident assessment, response, and remediation.
  • Lead the security and compliance aspects of third-party risk management, enterprise customer diligence, audits, RFPs/RFIs, and security escalations.
  • Partner with Product, AI, Engineering, Legal, and other stakeholders to establish appropriate governance for emerging technologies and the use of sensitive data.
  • Continuously improve the company’s compliance and security operating model so that requirements are clear, ownership is durable, and controls operate effectively in practice.

Requirements

  • 8+ years of experience in compliance, information security, risk management, or related disciplines, including meaningful leadership responsibility.
  • Deep practical knowledge of HIPAA/HITECH and healthcare compliance requirements, ideally within a covered entity or business associate environment.
  • Demonstrated experience leading SOC 2 Type II or comparable certification and assurance programs.
  • Experience building or materially improving compliance governance, control environments, policy frameworks, audit readiness, and cross-functional accountability.
  • Strong working knowledge of cloud security, application security, IAM, vulnerability management, endpoint security, secure SDLC practices, and modern SaaS architecture.
  • Ability to engage credibly with technical leaders, evaluate proposed approaches, identify material risk, and translate technical issues into business, compliance, and customer impact.
  • Strong executive judgment and communication skills, with the ability to work effectively across Legal, Engineering, Product, IT, People, Finance, auditors, customers, and executive leadership.
  • Demonstrated ability to drive accountability across functions without relying solely on direct reporting relationships.
  • Relevant certifications such as CISSP, CISM, CRISC, CISA, CHC, or similar are preferred but not required where equivalent experience is demonstrated.

We’re looking for a hands-on security and compliance leader who can build a durable program, not simply oversee an established one. The right person will bring deep healthcare compliance expertise, strong risk judgment, and enough technical fluency to work effectively with experienced Engineering, DevOps, architecture, and IT partners.

Success in this role means creating a company-wide operating model where compliance and security requirements are well understood, controls have clear owners, risks are surfaced early, certifications are continuously supported, and security enables the business to move quickly and responsibly.

About the Company

Prompt is revolutionizing healthcare by delivering highly automated and modern software to rehab therapy businesses, the teams within, and the patients they serve. As the fastest-growing company in the space and the new standard in healthcare technology, we strive to attract top talent who share our vision and values.

Revolutionize rehab therapy practices with our leading healthcare software, designed to enhance patient care, increase practice revenue, and help reduce overhead and administrative costs through enhancing efficiencies of teams. As a rapidly expanding company, we’re inviting a Business Development Representative with a Physical Therapy background to propel our growth. This role is a bridge between cutting-edge technology and transformative technology that drives efficiencies and evolves the PT business, perfect for those eager to drive industry evolution.

Why work for Prompt?

Hybrid Work Model: Achieve the perfect work-life balance with our flexible hybrid schedule. Enjoy the camaraderie of the office at least 3 days a week where you will be working with Prompt’s leadership team.

Stunning Workspace: Our office just relocated to a brand new, state of the art luxury building on the waterfront in Hoboken, NJ overlooking NYC.The space is designed to inspire creativity and foster collaboration.

BIG Challenges: Here at Prompt, we are solving complex and unique problems that have plagued the healthcare industry since the dawn of time.

Additional Information

Why Work for Prompt?

  • Big Challenges: Here at Prompt, we are solving complex and unique problems that have plagued the healthcare industry since the dawn of time.
  • Talented People: Prompt didn't happen by chance, it's a team of incredibly talented and proven individuals who all made their mark before joining forces to build the greatest software on the planet for rehab therapists.
  • Healthy Approach: This isn't an investment bank. At Prompt you own your workload and the entire organization takes a liking to smart work (over hard work).
  • Positive Impact: Prompt helps outpatient rehab organizations treat more patients and deliver better care with less environmental waste. That means less surgery and less narcotic-based pain treatment, all while turning a paper-heavy industry digital.

Perks – What you can expect

  • Competitive salaries
  • Remote/hybrid environment
  • Potential equity compensation for outstanding performance
  • Flexible PTO
  • Company-wide sponsored lunches
  • Company paid disability and life insurance benefits
  • Company paid family and medical leave
  • Medical, dental, and vision insurance benefits
  • Discounted pet insurance
  • FSA/DCA and commuter benefits
  • 401k
  • Credits for online fitness classes/gym memberships
  • Recovery suite at HQ — includes a cold plunge, sauna, and shower

Here at Prompt, we are committed to fostering a fair and respectful work environment. As part of this commitment, it is our policy not to hire individuals from Prompt Customers unless they have obtained their current employer's explicit consent. We believe in upholding strong professional relationships and respecting the agreements and commitments our customers have with their employees. We appreciate your understanding and cooperation regarding this policy. If you have any questions or concerns, please don't hesitate to reach out to our People Department.

Prompt Therapy Solutions, Inc is an equal opportunity employer, indiscriminate of race, color, religion, ethnicity, ancestry, national origin, sex, gender, gender identity, sexual orientation, age, marital status, veteran status, disability, medical condition, or any other protected characteristic. We celebrate diversity and are committed to creating an inclusive environment for all employees.

Prompt Therapy Solutions, Inc is an E-Verify Employer.

Role:
Senior Director, Security & Compliance
Job Type:
FullTime

Company profile

Prompt, also known as Prompt Health or Prompt Therapy Solutions, provides an EMR and practice management platform for rehab therapy and chiropractic clinics, from single-provider practices and startups to large enterprise organizations. Its software automates scheduling, billing, documentation and patient communication, and the company cites data from over 1,000 practices showing 75% less documentation time. Prompt aims to help outpatient rehab organizations treat more patients and turn a paper-heavy industry digital, and its office is in Hoboken, New Jersey.

More jobs at Prompt

Similar Engineering jobs at other companies