Lead privacy and security impact assessments for partner-facing business applications.
Design and improve the Partner Data Privacy & Security Impact Assessment process.
Evaluate risks throughout the data lifecycle and recommend mitigation strategies.
Del Oro Consulting is a staffing and consulting firm that connects professionals with contract opportunities. They are a mid-sized organization focused on delivering specialized talent solutions in a collaborative environment.
Lead complex privacy consulting projects from intake to final delivery, including drafting policies and conducting regulatory research.
Provide mentorship and feedback to Privacy Consultants, ensuring high-quality deliverables and consistent standards.
Maintain up-to-date knowledge of Canadian privacy legislation and support business development through proposals and client meetings.
PrivacyWorks Consulting specializes in providing information privacy, Freedom of Information, and security solutions to organizations across Canada and the US. The company has a growing team across Canada with experts averaging 15-20 years of experience, fostering a collaborative and fast-paced culture.
Lead and evolve information security, IT operations, and compliance programs to protect sensitive data and support growth.
Manage compliance initiatives across HIPAA, GDPR, PIPEDA, and other regulatory frameworks.
Drive security maturity, including SOC 2 and ISO 27001 readiness, and vendor risk management.
Partner company is a healthcare technology organization focused on improving healthcare outcomes. The company is remote-first and growing, with a mission-driven culture.
Advise internal business teams on compliance with privacy laws and regulations, including CCPA, HIPAA, and GDPR.
Draft, review, and negotiate privacy-related agreements and data processing addenda.
Develop and implement privacy policies, conduct impact assessments, and guide incident response.
EVERSANA provides commercialization services to the life sciences industry, helping bring innovative therapies to market. With over 7,000 employees, they serve more than 650 clients and are certified as a Great Place to Work globally.
Coordinate MZLA’s privacy and compliance program work, including planning, recurring reviews, risk tracking, documentation, and leadership reporting.
Translate privacy, security, and compliance requirements into practical processes that fit how MZLA works.
Coordinate vendor and tool reviews with legal, engineering, product, support, finance, operations, and other stakeholders.
Thunderbird is a trusted open-source email application used by over 20 million people. MZLA, the team behind Thunderbird, is a small but growing company of 60+ employees across seven countries, focused on building privacy-respecting communication and productivity tools.
Coordinates and administers privacy and compliance programs to ensure adherence to regulatory requirements.
Partners with internal teams to interpret requirements, implement compliant solutions, and monitor activities.
Develops policies, tracks corrective actions, and supports audits to maintain program effectiveness.
Capital Blue Cross is a health insurance company that improves the health and well-being of members and communities. It is an independent licensee of the Blue Cross Blue Shield Association and has been voted a 'Best Place to Work in PA' by employees.
Act as a trusted advisor to business leaders, bridging security risks and business priorities.
Lead security assessments, risk reviews, and remediation planning for new products and enterprise changes.
Maintain clear visibility of security risk, control health, metrics, and dashboards, escalating when needed.
Experian is a global data and technology company, powering opportunities for people and businesses around the world. With a team of 25,200 people in 32 countries, they foster an inclusive, purpose-driven culture and have been recognized as a World's Best Workplace in 2025.
Lead client engagements focused on cybersecurity strategy, privacy compliance, and security maturity improvements.
Provide virtual CISO advisory services, including cybersecurity roadmaps, risk mitigation, and incident response planning.
Develop and support privacy compliance programs aligned with frameworks such as CCPA/CPRA, GDPR, and ISO 27701.
Our partner is a cybersecurity and privacy advisory firm that helps organizations navigate complex regulatory and security challenges. They offer a flexible remote environment with diverse client engagements and a focus on continuous improvement.
Lead the design and governance of control frameworks and risk workflows within the GRC platform, ensuring alignment with compliance requirements like HIPAA, HITRUST, and NIST.
Oversee risk assessments, control testing, and vendor evaluations to identify and mitigate security risks.
Manage policy lifecycle, audit coordination, and reporting on control effectiveness and risk indicators.
USAP is a healthcare organization focused on providing anesthesia services and patient safety. It is a growing company with a culture of security, compliance, and collaboration.
Manage Omada’s HIPAA privacy program, including policy development, incident investigations, and breach response.
Drive privacy-by-design across digital products, embedding privacy into development and clinical operations.
Provide expert guidance on consumer privacy compliance, AI governance, and interoperability frameworks.
Omada Health is reverse engineering the way healthcare is delivered in America, putting the space between doctor visits at the center of care. They have served more than two million members since launch across 2,000+ employers, health plans, and health systems, and have been certified as a Great Place to Work.
Take ownership of building and scaling comprehensive security, privacy, and compliance programs that protect customer data.
Lead compliance initiatives such as SOC 2 Type 2 audits and evaluate additional frameworks like ISO 27001 and HIPAA.
Build scalable automated security processes by replacing manual tasks with scripts, APIs, and AI-powered solutions.
Our partner is a technology company focused on building secure, scalable systems. They operate with a remote, collaborative culture emphasizing ownership, transparency, and continuous improvement, with around 50–300 employees.
Lead the risk and compliance function, building frameworks to protect data and meet regulatory standards.
Collaborate cross-functionally to identify and mitigate operational, IT, and privacy risks.
Manage audits, incident response, and training to promote a strong culture of data security.
BIS Safety Software is a SaaS company that builds software to help organizations manage safety training, learning, and compliance. The company has been growing since 2006 and offers a collaborative culture with an Employee Stock Ownership Plan, valuing humility and ownership.
Manage internal audits and support external compliance assessments across business functions.
Perform gap analyses and track remediation actions for compliance frameworks.
Maintain and improve compliance documentation, policies, and risk registers.
Our partner is a growing SaaS organization serving global industries. It fosters a collaborative and inclusive culture with a focus on employee development and well-being.
You will own end-to-end compliance audits (SOC 1, SOC 2, HITRUST) and manage compliance automation platforms.
You will run the vulnerability management program and remediate security findings across AWS.
You will support security incident response, fraud investigations, and third-party risk assessments.
We are transforming post-acute care as the leading digital ordering platform for medical equipment and supplies. We connect major health systems, health plans, and suppliers to help patients get life-saving products at home, with a network of 300,000+ clinicians and 3,000+ supplier locations across all 50 states.
Serve as an IS&T Program Expert and Accreditor, evaluating security and technology systems across the federation and conducting PCI DSS compliance activities.
Conduct risk assessments and technical analyses to identify non-compliance with NIST CSF and HIPAA Security, and manage corrective actions.
Communicate professionally with technical and non-technical stakeholders to ensure timely project management and education on compliance requirements.
Planned Parenthood is the nation's leading provider and advocate of high-quality, affordable sexual and reproductive health care, and the largest provider of sex education. PPFA is a 501(c)(3) supporting independently incorporated affiliates that operate non-profit health centers across the U.S., with a culture of fostering belonging and learning.
Lead the governance, risk, and compliance function across security policies, standards, risk management, audits, and third-party risk.
Own audit readiness and ongoing compliance programs across frameworks such as SOC 2, ISO 27001, GovRAMP, PCI DSS, HIPAA, NIST CSF, and more.
Manage third-party and supply chain risk management, including vendor security reviews, due diligence, and remediation tracking.
Accela provides government software solutions to improve efficiency, increase citizen engagement, and enable thriving communities. They have been an industry leader for nearly 20 years and are committed to diversity, equity, and inclusion.
Consult onsite and remotely with customers to collect and analyze data related to policies, infrastructure, and compliance requirements.
Perform gap analyses of current environments and recommend remediation steps.
Assist with sales and marketing activities as a subject matter expert and prepare industry presentations.
CampusGuard provides information security and privacy consulting and compliance services for campus-based organizations. It is a full-service firm leveraging industry standards to deliver world-class security and compliance services.
Lead customer security reviews, RFPs, RFIs, and questionnaires to keep deals moving.
Own SOC 2 Type II program management and the customer-facing trust portal.
Author security policies and manage AI compliance frameworks.
Sparkrock helps social benefit organizations like nonprofits, school boards, and government agencies reach their full potential through technology. They are a best-in-class, 100% remote organization with a focus on culture and growth, serving over 150,000 users.
Coordinate vendor security assessments and track remediation activities.
Maintain accurate documentation and workflow updates within ServiceNow.
Support daily operational activities for an enterprise Third-Party Risk Management program.
Del Oro Consulting is a consulting firm that delivers third-party risk management and cybersecurity governance services. The company offers a remote work culture and provides benefits including medical, dental, vision, and 401(k) matching.
Own and continuously improve the company's compliance program across SOC 2, GDPR, ISO 27001, and other frameworks.
Lead external audits, develop security policies, and partner with engineering teams to implement controls.
Manage third-party risk, respond to customer security questionnaires, and build compliance metrics for executive reporting.
10a Labs is the safety and threat-intelligence layer trusted by frontier AI labs, AI unicorns, Fortune 10 companies, and leading global technology platforms. They are a high-growth technology company with a collaborative culture, operating in a fast-moving environment.