Practice Better

Practice Better

Senior Manager, Infosec, IT & Compliance

Remote - Canada · Senior · Full-time

Work authorization required$165k-$180kDetected 5 days ago
AWSCloud PlatformsCybersecurityIncident ResponseComplianceProduct ManagementProduct StrategyNegotiationVendor ManagementProcurementCustomer SuccessHIPAAEHR/EMRLeadershipCommunicationPlain LanguageCISSP

About the role

  • We are looking for a Senior Manager, Information Security, IT, and Compliance to join our growing team.
  • As a Business Associate to thousands of healthcare practitioners globally, Practice Better operates in a complex regulatory environment spanning HIPAA, GDPR/UK GDPR, and many more existing and emerging state privacy laws.
  • You understand that compliance is not a checkbox exercise - it's a business enabler that protects our customers, and earns their trust.

Responsibilities

  • You'll drive day-to-day execution of our compliance program - supporting vendor BAA/DPA negotiations and the implementation of multi-jurisdictional privacy frameworks, maturing our security posture and anticipating regulatory gaps.
  • You'll also manage IT operations, including user provisioning/deprovisioning, device management, SaaS vendor rationalization, and identity & access management.
  • Manage multi-jurisdictional compliance execution - Support implementation of HIPAA/HITECH, GDPR/UK GDPR, and many more existing and emerging privacy laws and coordinate with legal counsel on complex regulatory matters.
  • Drive vendor risk management and BAA/DPA lifecycle - Negotiate and finalize Business Associate Agreements and Data Processing Agreements with subprocessors, ensuring breach notification timelines meet calendar-day standards, data deletion commitments are defined, and subprocessor transparency obligations are satisfied.
  • Mature security posture and operational resilience - Partner with Engineering to implement security controls that support SOC 2 Type II and ISO 27001 readiness, lead incident response planning and mature monitoring/alerting.
  • Embed privacy-by-design across product and engineering - Collaborate with Product and Engineering leadership to assess PHI exposure in new features, define data minimization strategies, and guide architecture decisions that reduce compliance risk.
  • Drive Identity & Access Management (IAM) strategy - Own identity provider configuration and access control policies, implementing least-privilege access principles, periodic access reviews, and role-based access control (RBAC) frameworks.
  • Manage endpoint security and device management - Define and enforce endpoint security standards (MDM, disk encryption, antivirus, patching).
  • Own SaaS vendor rationalization and procurement hygiene - Conduct regular vendor intelligence audits to identify tool overlaps, license waste and procurement gaps. Partner with Finance on SaaS spend optimization.

Requirements

  • Deep expertise in HIPAA/HITECH compliance, including Business Associate obligations, breach notification requirements, and Covered Entity vs.
  • Strong working knowledge of GDPR/UK GDPR and cross-border data transfer mechanisms
  • Proven ability to negotiate and finalize vendor BAAs and DPAs, with a strong understanding of must-have vs. nice-to-have contractual terms
  • Experience implementing security frameworks (SOC 2, ISO 27001, or equivalent) and managing third-party audits or certifications
  • Bias for action and pragmatic risk management - you know when to escalate to legal counsel and when to make judgment calls independently
  • 6+ years of relevant experience in information security, IT operations, privacy, and compliance roles, with at least 2+ years in healthcare SaaS or regulated industry
  • Deep expertise in HIPAA/HITECH compliance, including Business Associate obligations, breach notification requirements, and Covered Entity vs. Business Associate determination frameworks
  • Hands-on experience leading IT operations for remote-first organizations, including identity & access management, device provisioning, and SaaS vendor management
  • Prior experience building or scaling InfoSec, IT, and compliance functions from scratch in high-growth SaaS companies
  • Technical grounding in SaaS architecture, APIs, data flows, infrastructure (cloud environments like AWS), and identity providers (Google Workspace, Okta, Microsoft 365)
  • Exceptional communication skills - you can translate legal jargon into plain language for practitioners, write concise vendor negotiation emails, and present compliance strategies to executive leadership with clarity and confidence
  • Comfortable operating in a fast-moving, high-growth environment where priorities shift and ambiguity is the norm
  • Organizational context - The role would manage both the security/compliance function AND day-to-day IT operations, reporting directly to the VP of Engineering
  • Bonus Points
  • Professional certifications (CIPP/US, CIPP/E, CIPM, CISSP, CISM, or equivalent)

Compensation

  • $165,000 - $180,000/yr CAD
  • We take a holistic approach to compensation, combining salary, benefits, and flexibility.
  • The range above reflects our expected compensation for this role, based on current market data.
  • All compensation ranges are reviewed regularly and may evolve over time to reflect changes in the market.
  • We offer a robust benefits package for full-time, permanent employees, including health, dental, and vision coverage from day 1, as well as RRSP matching, generous paid parental leave, and annual learning stipends.

Benefits

  • Comprehensive Benefits
  • We offer a robust benefits package for full-time, permanent employees, including health, dental, and vision coverage from day 1, as well as RRSP matching, generous paid parental leave, and annual learning stipends.
  • Wellness and Growth
  • Unlimited vacation, built on trust, clear expectations, and real support for taking
  • Ready to make a real impact on global health and wellness care?
  • Practice Better is an all-in-one platform helping health and wellness practitioners run their businesses, care for their clients, and scale their impact.
  • Founded by practitioners in 2016, we're now the leading EHR and practice management platform in the wellness industry, trusted by tens of thousands of practitioners across 70+ countries.

Company info

  • Note: Practice Better is a remote-first company with team members across North America.

Visa & Work Authorization

  • Practice Better is unable to support sponsorship for work permits or visas at this time.

This listing is sourced directly from Practice Better's careers page and normalized into a canonical job model.