Padmi
100ms logo
100ms

AI agents · healthcare automation

Security and Compliance Lead – AI Agents (Healthcare)

Bangalore · Onsite₹5M–₹8M/yrPosted 5 months ago
SecuritySenior
Apply at 100ms

Opens the source posting on jobs.lever.co

Source description

About the role

View original

Regulatory Compliance & Privacy Design, implement, and maintain a comprehensive HIPAA compliance programme covering the Privacy Rule, Security Rule, and Breach Notification Rule. Serve as the designated Privacy Officer and/or Security Officer for the organisation. Develop and enforce Business Associate Agreements (BAAs) with all vendors and partners handling PHI. Conduct periodic Security Risk Assessments (SRA) and maintain a risk register with clear remediation timelines. Monitor evolving U.S. healthcare regulations (HITECH, state privacy laws, CMS interoperability rules, 21st Century Cures Act) and update policies accordingly. Lead external audit readiness for SOC 2 Type II, HITRUST CSF, and customer-required security assessments. Security Architecture & Engineering Define and enforce 100ms’s security architecture across cloud infrastructure (AWS / GCP / Azure), application layer, AI agent pipelines, and U.S.-based data storage. Implement IAM policies, encryption standards (at rest and in transit), and network segmentation controls. Own vulnerability management: scanning, triage, SLA-driven patching, and penetration testing schedules. Establish and manage a Security Incident Response Plan (SIRP), including tabletop exercises and on-call rotation. Evaluate and deploy security tooling (SIEM, EDR, DLP, CSPM) appropriate for a startup—balancing rigour with speed. Ensure security of LLM-based agent workflows, including prompt injection defences, data leakage prevention, and PHI handling in AI pipelines. Governance, Risk & Trust Build 100ms’s security documentation library: policies, standards, procedures, and evidence repositories using GRC frameworks like (Sprinto, Vanta, Drata, Secureframe). Set up and manage continuous compliance monitoring and automated evidence collection via Sprinto for SOC 2 and HIPAA audit readiness. Own the vendor risk management programme, including third-party security reviews and ongoing monitoring. Respond to customer security questionnaires, RFPs, and due-diligence requests alongside Sales and Customer Success. Drive security awareness training across the organisation, including onboarding programmes and phishing simulations. Track security KPIs and present a quarterly compliance posture report to the leadership team. Cross-Functional Partnership Embed secure-by-design principles into the SDLC: threat modelling, secure code reviews, and dependency scanning. Collaborate with Engineering on DevSecOps practices—CI/CD pipeline security, secrets management, and infrastructure-as-code hardening. Partner with Legal on data processing agreements, breach notification protocols, and regulatory filings. Support customer-facing teams in addressing compliance concerns and positioning security as a sales differentiator with U.S. healthcare buyers.

More at 100ms

Related open roles

View all roles