Xenter

Xenter

Governance, Risk & Compliance Lead

Draper, UT · Full-time

Sponsorship not specifiedDetected 7 days ago
AWSAzureCloud PlatformsData ScienceIncident ResponseComplianceAuditingPrivacy LawHIPAAFDA RegulatoryMedical DevicesLeadershipCommunicationInternal AuditCISSP

About the role

  • At Xenter, you'll join an entrepreneurial team where innovation moves quickly, ideas become reality, and every employee has the opportunity to help shape technologies with the potential to change healthcare worldwide.
  • This is a hands-on role first and a leadership role second.
  • In year one you will personally write policies, run risk assessments, gather evidence, and sit across the table from auditors.

Responsibilities

  • Own the certification roadmap - define and execute the path to HITRUST CSF, ISO/IEC 27001, SOC 2 Type II, and ISO/IEC 42001, including readiness assessments, gap remediation, and external audit management.
  • Design scalable controls - favor controls that enable velocity rather than create friction, scale with company growth, and reduce audit burden through automation and evidence reuse.
  • Write and operationalize policies - author the policy library, select and administer compliance automation tooling, and drive continuous control monitoring and evidence collection.
  • Lead privacy - own HIPAA compliance, GDPR, CCPA and other state privacy law obligations for our consumer app, data mapping, and privacy impact assessments.
  • Build the human layer - run security awareness training, incident response exercises, and business continuity and disaster recovery planning and testing.

Benefits

  • Be the face of trust to hospitals - lead responses to hospital security reviews, customer security questionnaires, MDS2 forms, and BAA negotiations; make it easy for health systems to say yes to Xenter.
  • Scale the team - define the GRC hiring plan, recruit and mentor analysts and managers, and report program health, risk posture, and certification progress to executive leadership.
  • Healthcare or medical device industry experience strongly preferred, including HIPAA, FDA cybersecurity guidance (e.g., Section 524B premarket requirements), and the realities of hospital IT security review.

Company info

  • Clear, confident communication with executives, auditors, engineers, and hospital CISOs alike.

This listing is sourced directly from Xenter's careers page and normalized into a canonical job model.