Requirements 7+ years in security, with 3+ years in a regulated environment (HIPAA, finance, or government), must be evidenced in bullets, not just worked at a healthcare company.
Operational HITRUST or SOC2 experience - managed/maintained an ongoing program, not just audit participation or a one-time certification push.
Structured risk quantification to non-technical leadership (documented cost vs risk recommendations, not just identified risks).
Built or significantly improved security infrastructure in a cloud-native workplace (GCP, AWS, or Azure).
Track record evaluating and managing external security vendors/consultants (scoping, risk assessment, delivery accountability).
Direct hands-on AI/LLM security work - assessing risk in an AI product, governing internal LLM tool usage, or building controls for LLM systems.
Evidenced cost vs risk judgment - a recommended against decision or documented tradeoff, not just risk-averse defaults.
Comfortable as a solo IC with no team to delegate to - recent hands-on security work,
not pure people-management.
Should
Have SOC2 Type II operational experience specifically CISSP / CISM / CCSP or equivalent certification.
EHR integration security familiarity - HL7 FHIR, Epic/Athena patterns.
Agentic AI systems experience - built with agents (tool-calling, multi-step workflows) or assessed their security posture.
High growth startup experience (Series A-C).
Direct enterprise customer-facing security work (questionnaires, CISO/trust reviews).
Could Have
Healthcare domain depth beyond the regulated-environment requirement (RCM, clinical workflows)- a plus, not a gate.
Security awareness/training program design experience.
GCP specifically (matches Arintra's stack, but AWS/Azure equally acceptable per JD).