Startups

Security Compliance Program Manager

CentralReach · Holmdel, New Jersey · On-site

← All jobs
About CentralReach

ABA and Multidisciplinary Software Solutions for Autism & IDD Care. End-to-end software that supports the efficient delivery of care. Backed by Insight.

About the role

The Security Compliance Program Manager will own and drive CentralReach’s overall compliance program, working directly with the Chief Compliance Officer and Chief Information Security Officer. Beyond day-to-day maintenance and special projects, this role brings program ownership: translating regulatory and security standards into action plans, building KPIs and reporting cadences for leadership, developing metrics, monitoring, and incident response capabilities in partnership with Information Security and...

What they're looking for

  • Experience working with auditors through internal and external security and compliance audits
  • Working knowledge of security and compliance frameworks (e.g., NIST 800-53, SOC 2, HIPAA, ISO 27001) and the ability to translate them into operational action plans
  • Experience developing KPIs, metrics, and reporting cadences for program and executive leadership
  • Familiarity with security monitoring, alerting, and incident response concepts
  • Experience with Business Continuity and Disaster Recovery planning
  • Process improvement and automation mindset, including experience evaluating and implementing GRC or compliance management tools
More about this role

CentralReach is a leading provider of autism and IDD care software for Applied Behavior Analysis (ABA), multidisciplinary therapy, and special education. Trusted by more than 200,000 users, we enable therapy providers, educators, and employers to scale the way they deliver ABA and related therapies with innovative technology, market-leading industry expertise, and world-class customer satisfaction.

The Security Compliance Program Manager will own and drive CentralReach’s overall compliance program, working directly with the Chief Compliance Officer and Chief Information Security Officer. Beyond day-to-day maintenance and special projects, this role brings program ownership: translating regulatory and security standards into action plans, building KPIs and reporting cadences for leadership, developing metrics, monitoring, and incident response capabilities in partnership with Information Security and Infrastructure teams, and continually evolving the program’s processes and tooling.

  • Lead and Manage Third-Party and Internal Audits

SOC 2 Type 2

HIPAA Attestation

Privacy Audit

Security Audits

  • Compliance Program Strategy & Implementation

Translate requirements from regulatory and...

Read the full posting on CentralReach's site ↗

Legal & Compliance

Build your edge while you search

Free tools for founders and investors, plus VC Unfiltered, our take on startups, venture and the people who build them.