Senior Privacy and Security Analyst

  • $105k-$145k
  • Remote - Worldwide

Remote

Cybersecurity

Senior

Job description

ABOUT THE ROLE:

Rightway Healthcare is seeking a detail-oriented and driven Privacy & Security Analyst to work closely with the Head of Security, Security GRC Manager, and Privacy Officer. This role will focus on strengthening our privacy and security assurance capabilities at scale. Rightway seeks a candidate who is experienced in privacy within regulated, high-growth environments and is eager to further develop their security governance, risk, and compliance (GRC) expertise.

WHAT YOU’LL DO:

Privacy and Data Protection Compliance

  • Contribute to the design and execution of the company’s privacy roadmap, including the rollout of new policies, tooling, and operational workflows.
  • Design, implement, and oversee processes, procedures, and operational workflows for managing and fulfilling data subject access requests (DSARs) and privacy-related inquiries.
  • Support the execution and documentation of privacy impact assessments (PIAs) and data protection impact assessments (DPIAs).
  • Initiate and expand GRC tooling to provide privacy control coverage and control health monitoring.

Timebound Privacy & Security Activities

  • Document and track completion of control activities and escalate issues where needed.
  • Assist with internal and external audits, ensuring timely and complete evidence collection and review.
  • Maintain and continuously improve a centralized repository of commonly requested security documentation and artifacts (e.g., SOC 2, SIG, CAIQ).
  • Support the implementation and operationalization of AI risk and governance controls in alignment with ISO/IEC 42001 and emerging regulatory guidance. Monitor AI systems for compliance with ethical and legal standards.

Third Party Privacy and Security Risk Management

  • Conduct initial and periodic vendor risk assessments, ensuring that third parties meet Rightway’s privacy, security, and other compliance standards.
  • Track and follow up on remediation plans and risk treatment for vendor.,
  • Support automation and optimization of the vendor risk assessment lifecycle.

Customer Assurance

  • Collaborate with Security GRC Manager to respond to customer privacy and security RFPs, questionnaires and assessments.
  • Partner with legal on language of BAAs and Data Protection Agreements.

WHO YOU ARE:

  • Minimum of 3 years in a heavily Privacy oriented role in a regulated environment.
  • Maintains a Certified Information Privacy Professional (CIPP) or similar certification.
  • Familiarity with security/privacy compliance frameworks and regulation (e.g., SOC 2, ISO 27001, NIST, HIPAA, HITRUST NY DFS).
  • Experienced with third party risk management broadly and from a privacy perspective.
  • Experience responding to customer due diligence inquires e.g. Questionnaires.
  • Strong organizational skills and the ability to manage multiple tasks and deadlines simultaneously.
  • Passionate advocate for Privacy Programs, believing that these are not merely check box activities, but vital tools that significantly improve privacy posture and protect the organization.
  • Interest in emerging technologies and willingness to develop subject matter expertise in AI risk and compliance.

SALARY (BEFORE BONUS POTENTIAL):

$105,000-$145,000/yr

Offer amounts for both remote and in office roles are influenced by geographic location.

CYBERSECURITY AWARENESS NOTICE

In response to ongoing and industry-wide fraudulent recruitment activities (i.e., job scams), Rightway wants to inform potential candidates that we will only contact them from the @rightwayhealthcare.com email domain. We will never ask for bank details or deposits of any kind as a condition of employment.

ABOUT RIGHTWAY:

Rightway is on a mission to harmonize healthcare for everyone, everywhere. Our products guide patients to the best care and medications by inserting clinicians and pharmacists into a patient’s care journey through a modern, mobile app. Rightway is a front door to healthcare, giving patients the tools they need along with on-demand access to Rightway health guides, human experts that answer their questions and manage the frustrating parts of healthcare for them.

Since its founding in 2017, Rightway has raised over $130mm from investors including Khosla Ventures, Thrive Capital, and Tiger Global at a valuation of $1 billion. We’re headquartered in New York City, with a satellite office in Denver. Our clients rely on us to transform the healthcare experience, improve outcomes for their teams, and decrease their healthcare costs.

HOW WE LIVE OUR VALUES TO OUR TEAMMATES:

We’re seeking those with passion for healthcare and relentless devotion to our goal. We need team members that embody our following core values:

  1. We are human, first Our humanity binds us together. We bring the same empathetic approach to every individual we engage with, whether it be our members, our clients, or each other. We are all worthy of respect and understanding and we engage in our interactions with care and intention. We honor our stories. We listen to—and hear—each other, we celebrate our differences and similarities, we are present for each other, and we strive for mutual understanding.

  2. We redefine what is possible We always look beyond the obstacles in front of us to imagine new solutions. We approach our work with inspiration from other industries, other leaders, and other challenges. We use ingenuity and resourcefulness when faced with tough problems.

  3. We debate then commit We believe that a spirit of open discourse is part of a healthy culture. We understand and appreciate different perspectives and we challenge our assumptions. When working toward a decision or a new solution, we actively listen to one another, approach it with a “yes, and” mentality, and assume positive intent. Once a decision is made, we align and champion it as one team.

  4. We cultivate grit Changing healthcare doesn’t happen overnight. We reflect and learn from challenges and approach the future with a determination to strive for better. In the face of daunting situations, we value persistence. We embrace failure as a stepping stone to future success. On this journey, we seek to act with guts, resilience, initiative, and tenacity.

  5. We seek to delight Healthcare is complicated and personal. We work tirelessly to meet the goals of our clients while also delivering the best experience to our members. We recognize that no matter the role or team, we each play a crucial part in our members’ care and take that responsibility seriously. When faced with an obstacle, we are kind, respectful, and solution-oriented in our approach. We hold ourselves accountable to our clients and our members’ success.

Rightway is a healthcare company looking to improve healthcare outcomes for everyone, everywhere. With that in mind, we have to consider what is good for the health of our team, the company, and the communities we operate in. As such, Rightway has determined a mandatory COVID-19 vaccination policy for all employees, in combination with other safety precautions, is the best way forward.

Rightway is PROUDLY an Equal Opportunity Employer that believes in strength in the diversity of thought processes, beliefs, background and education and fosters an inclusive culture where differences are celebrated to drive the best business decisions possible. We do not discriminate on any basis covered by appropriate law. All employment is decided on the consideration of merit, qualifications, need and performance.

Share this job:
Please let Rightway know you found this job on Remote First Jobs 🙏

Benefits of using Remote First Jobs

Discover Hidden Jobs

Unique jobs you won't find on other job boards.

Advanced Filters

Filter by category, benefits, seniority, and more.

Priority Job Alerts

Get timely alerts for new job openings every day.

Manage Your Job Hunt

Save jobs you like and keep a simple list of your applications.

Search remote, work from home, 100% online jobs

We help you connect with top remote-first companies.

Search jobs

Hiring remote talent? Post a job

Frequently Asked Questions

What makes Remote First Jobs different from other job boards?

Unlike other job boards that only show jobs from companies that pay to post, we actively scan over 20,000 companies to find remote positions. This means you get access to thousands more jobs, including ones from companies that don't typically post on traditional job boards. Our platform is dedicated to fully remote positions, focusing on companies that have adopted remote work as their standard practice.

How often are new jobs added?

New jobs are constantly being added as our system checks company websites every day. We process thousands of jobs daily to ensure you have access to the most up-to-date remote job listings. Our algorithms scan over 20,000 different sources daily, adding jobs to the board the moment they appear.

Can I trust the job listings on Remote First Jobs?

Yes! We verify all job listings and companies to ensure they're legitimate. Our system automatically filters out spam, junk, and fake jobs to ensure you only see real remote opportunities.

Can I suggest companies to be added to your search?

Yes! We're always looking to expand our listings and appreciate suggestions from our community. If you know of companies offering remote positions that should be included in our search, please let us know. We actively work to increase our coverage of remote job opportunities.

How do I apply for jobs?

When you find a job you're interested in, simply click the 'Apply Now' button on the job listing. This will take you directly to the company's application page. We kindly ask you to mention that you found the position through Remote First Jobs when applying, as it helps us grow and improve our service 🙏

Apply now