About Medicom
Medicom is a leading enterprise imaging software company that solves longstanding interoperability challenges for clinicians, staff, patients, and researchers. Its core platform, Connect, supports diverse enterprise imaging interoperability use cases. These include access to prior and unread imaging studies, point-of-care workflows, patient access to images, orders and results workflows for teleradiology, telestroke and trauma, and cross-institution sharing of digital imaging. Medicom's Network is adopted by over 1,000 US healthcare institutions and backed by leading venture capital firms, such as UPMC Enterprises. Data and insights from the Medicom Connect network drive Medicom's Intellect offering, which helps clinicians and researchers advance patient care and develop new therapies.
About the role
Medicom is seeking an Information Security Program Manager to join our Compliance team and lead the company’s information security and regulatory compliance programs. As a healthcare data company, Medicom must meet the highest standards for data protection while supporting rapid product development and growth.
In this role, you will own Medicom’s internal compliance programs and partner closely with Engineering and cross-functional leaders to ensure security and compliance are embedded into our products, systems, and processes. You will play a critical role in maintaining HIPAA compliance while preparing the organization for additional frameworks such as SOC 2, GDPR, and FedRAMP.
What you'll do
- Own and lead Medicom’s internal compliance and security programs, ensuring ongoing adherence to HIPAA, HITRUST, GDPR, SOC 2, and other evolving regulatory frameworks and standards.
- Partner closely with the Engineering team to incorporate security and compliance requirements into product design, feature development, and system architecture.
- Develop, maintain, and clearly communicate to internal and external stakeholders Medicom’s information security program, including controls, risk areas, and known limitations.
- Lead preparation for new compliance certifications and readiness efforts (e.g., SOC 2 Type 2, GDPR certification, FedRAMP readiness).
- Serve as the primary coordinator for the Confidentiality & Security Team (CST), including agenda setting, monthly meetings, and executive-level reporting.
- Manage all aspects of SOC 2 audits, including coordination with third-party auditors and internal stakeholders.
- Act as a trusted internal advisor, providing guidance, education, and support on compliance and security-related topics across the organization.
- Monitor changes in relevant laws, regulations, and industry standards, recommending and implementing updates to internal policies and processes.
Qualifications
- 8+ years of experience in compliance, information security, privacy, or risk management, preferably within healthcare, health tech, or SaaS environments.
- CISSP (Certified Information Systems Security Professional) certification strongly preferred or other advanced technical security certifications (e.g. Information Systems Security Architecture Professional, Information Systems Security Engineering Professional)
- Strong working knowledge of industry frameworks and federal, regional, and state regulations such as HIPAA, SOC 2, CCPA, and GDPR; experience with FedRAMP is a plus.
- Proven ability to interpret complex regulatory requirements and translate them into practical, actionable guidance.
- Experience leading external audits, certifications, or regulatory assessments.
- Excellent documentation, organizational, and program management skills.
- Strong written and verbal communication skills, with the ability to align cross-functional stakeholders.
- Comfortable working independently and proactively in a fast-paced, growing organization.
Equal Opportunity Employer Statement
Medicom Technologies is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.
Reasonable Accommodation Notice
If you require a reasonable accommodation in the application process, please contact [email protected] to discuss your needs.
Salary
Starting at $130k
Top Skills
Similar Jobs
What you need to know about the Colorado Tech Scene
Key Facts About Colorado Tech
- Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
- Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
- Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
- Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
- Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute



