Information Security Officer (ISO) Job at Blooming Health, Remote

RUpLTkJHeFEwWjBrejAzNVd3andsNU9B
  • Blooming Health
  • Remote

Job Description

Job Description: Information Security Officer (ISO)

About Us

Blooming Health ( is on a mission to transform social care for older adults and underserved populations. We partner with community organizations, government agencies, and healthcare stakeholders to build a digital tissue in the community for automating access to social care and advancing health equity. As we scale, we're looking for an ambitious and resourceful Implementation and Project Manager to drive complex implementation projects in State and Local Governments, and Healthcare segments.

Overview

  • We are seeking an experienced Information Security Officer (ISO) to oversee IT, security, and compliance for our organization. The ISO will be responsible for developing and implementing a comprehensive security strategy, managing a team of IT & Cyber Security & GRC personnel, and collaborating with business and engineering teams to ensure all security, regulatory, and compliance requirements are met.
    Must have experience helping a startup/smaller company achieve compliance

Key Responsibilities

1. Security Strategy & Program Management

  • Develop, implement, and maintain an organization-wide information-security roadmap that supports business goals and budgets.

  • Drive all activities needed to achieve and sustain HITRUST R2 certification; map controls to SOC 2, NIST 800-53, ISO 27001, GDPR, and HIPAA.

  • Establish a continuous-improvement cycle for security policies, procedures, and standards; track emerging threats and regulatory changes.

2. IT Administration & Infrastructure Ownership

  • Device-Life-Cycle Management: own procurement, imaging, MDM enrollment, patching, asset tracking, and secure decommissioning for laptops, servers, and mobile devices.

  • Endpoint & SaaS Deployment: select and roll out collaboration, identity, and productivity tooling (Okta, Google Workspace, O-365, JAMF, Intune, etc.).

  • Network & Cloud Operations: oversee firewalls, VPNs, Wi-Fi, VPC design, and backups; ensure high availability, capacity planning, and performance monitoring.

  • Build-vs-Buy / MSSP Decision-Making: evaluate when to partner with a managed security service provider vs. operating controls in-house; own vendor due-diligence, contracts, and ongoing KPI reviews.

  • Help-Desk & ITSM Governance: set SLAs for ticket triage, change management, and problem management; publish metrics and drive service-quality improvements.

3. Team Leadership & Management

  • Hire, coach, and retain a blended team of IT administrators, security engineers, and GRC analysts.

  • Set OKRs, run weekly stand-ups, and coordinate on-call rotations for both IT and security operations.

4. Monitoring, Detection & Incident Response

  • Operate and tune SIEM/EDR, vulnerability scanners, and cloud-security posture-management tools; ensure 24×7 monitoring coverage.

  • Lead incident response—from triage through root-cause analysis and post-mortem—coordinating with engineering, legal, and communications teams.

5. Risk Management & Compliance

  • Perform periodic enterprise risk assessments; maintain a living risk register with owners, treatment plans, and residual-risk metrics.

  • Ensure timely completion of audits (HITRUST, SOC 2, HIPAA, PCI, etc.) and track remediation through closure.

  • Maintain evidence repositories, policy repositories, and contract inventories to streamline internal and external audits.

6. Collaboration & Executive Reporting

  • Embed security and privacy requirements into product roadmaps, CI/CD pipelines, and vendor onboarding workflows.

  • Present quarterly security scorecards, incident trends, and IT service KPIs to the executive team and, when required, the board of directors.

  • Serve as primary liaison with cloud providers, MSSPs, and regulatory bodies; negotiate security addenda and SLAs.

Qualifications

  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or a related field (Master's degree preferred).
  • A minimum of 7–10 years of experience in information security, with at least 3 years in a managerial or leadership role.
  • Strong understanding of security frameworks and standards such as NIST, ISO 27001, GDPR, and HIPAA.
  • Proven experience in managing and mentoring technical teams.
  • Excellent communication, collaboration, and analytical skills.
  • Relevant certifications (e.g., CISSP, CISM, CISA) are highly desirable.

Skills

  • Expert in IT systems management and tools (ITSM, IdPs, MDMs etc.)
  • Expert in cybersecurity management (SIEM, EDR/VDR, Endpoint management)
  • Strategic planning and risk management
  • Incident response and forensic analysis
  • IT infrastructure and network security expertise
  • Strong leadership and team management
  • Excellent written and verbal communication

Job Tags

Remote job, Full time, Contract work, Local area,

Similar Jobs

NL Health Services

Regional Registered Nurse II Job at NL Health Services

 ...St. Brendans Community Health Centre, St. Brendans Regional Registered Nurse II Central Zone - HCS Home Com Ns - New Wes Valley...  ...delivered in a variety of settings including the home, school, clinic and other community settings. Services include health promotion... 

Alabaster City Schools

Custodian - CVES - Apply 2/5/2025 - 6/13/2025 Job at Alabaster City Schools

 ...Multiple Positions ALABASTER CITY SCHOOLS JOB DESCRIPTION JOB TITLE: CUSTODIAN QUALIFICATIONS: 1. Good general health. 2. Demonstrated aptitude for assigned responsibilities. 3. Such alternatives to the above qualification as the Board of Education... 

THIRD COAST EMPLOYEE SERVICES, LLC

Pipeline Technician Job at THIRD COAST EMPLOYEE SERVICES, LLC

 ...deep water producing regions in the Gulf of Mexico, with on and offshore assets including natural gas gathering and transmission pipelines, NGL and crude oil pipelines, gas processing plants, and a deep water floating production system. Our infrastructure services some... 

University of Maryland, Baltimore County

Acupuncturist (General Associate) | University of Maryland, Baltimore County Job at University of Maryland, Baltimore County

 ...students, staff and faculty at UMBC. Responsibilities: Our team is in search of a licensed acupuncturist to provide outpatient acupuncture therapy to UMBCs campus population. Job Responsibilities: Performs acupuncture therapy to patients according to the... 

Criterion Executive Search

Commercial Lines Account Managers Pelham Job at Criterion Executive Search

 ...Must have Applied/TAM experience.Type of Accounts: Generalist, Service Oriented, Suppliers, Real Estate.Carriers: Chubb, Travelers, AIG, excess market w specialty lines, a lot of carriers.*In the Bergan County NJ office, Commercial Lines Account Manager opening for...