AffirmedRx, PBC - Information Security Manager
Requirements
• Bachelor’s degree in Computer Science, Information Security, Information Technology, or a related field, or equivalent experience • 4–7 years in information security or security engineering • Hands-on experience with the Microsoft security stack (Entra ID / Active Directory, Microsoft 365, Azure) • Experience supporting compliance frameworks such as SOC 2, HITRUST, URAC, or HIPAA • Demonstrated experience with IAM and SSO, SIEM operations, and data governance / eDiscovery (Purview or equivalent) • Experience with vendor security assessments and third-party risk • Healthcare, PBM, or other regulated-industry experience preferred • CISSP, CISM, or CompTIA Security+ (preferred) • Microsoft SC-200, SC-300, or AZ-500 (preferred) • HITRUST CCSFP (preferred) • Solid technical background with the ability to explain security concepts to a non-technical audience • Strong written and verbal communication • Customer-service orientation with a problem-solving attitude • Ability to work independently and prioritize across competing demands • Fully remote; must have reliable internet and a suitable home work environment • Occasional unscheduled overtime may be required to support incident response or audit deadlines • Willingness and ability to travel (10%-20%) • What you get: • To impact industry change in the pharmacy benefits management space, while delivering the highest quality patient outcomes • To work in a culture where people thrive because when OUR team thrives, OUR business thrives • Competitive compensation, including health, dental, vision and other benefits • Note: • AffirmedRx is committed to providing equal employment opportunities to all employees and applicants for employment. Remote employees are expected to maintain a professional work environment free of distractions to ensure optimal performance and collaboration.
Responsibilities
• Identity & Access Management: • Administer Microsoft Entra ID / Active Directory, including users, groups, conditional access, and MFA • Design, implement, and maintain single sign-on (SSO) integrations across the application portfolio (SAML / OIDC) • Run periodic user access reviews and account audits; document findings and drive remediation of access exceptions • Manage provisioning and deprovisioning; enforce least privilege and role-based access control • Security Operations & Monitoring: • Operate and tune the SIEM (such as Microsoft Sentinel); review logs, alerts, and reports across endpoints, servers, network, and cloud • Triage and investigate alerts; participate in incident response (identify, contain, eradicate, recover, and document lessons learned) • Maintain and improve detection coverage in support of a defense-in-depth strategy • Compliance, Audit & Certification: • Maintain SOC 2 and URAC: own evidence collection, control mapping, and coordination with auditors • Lead and support the path to HITRUST CSF certification, including gap assessment, control implementation, evidence gathering, and validated-assessment readiness • Track remediation items, control owners, and audit timelines • Application & Data Security: • Provide security oversight across the application portfolio • Document application and data flows, integrations, and trust boundaries • Support secure configuration, vulnerability remediation, and application access governance • Data Governance & eDiscovery: • Administer Microsoft Purview: data loss prevention (DLP), data classification and labeling, and retention • Execute eDiscovery, content and email search, and legal holds in support of legal and compliance requests • Vendor & Security Tooling Management: • Evaluate, select, and recommend security products and enhancements to existing controls • Conduct and respond to vendor security assessments and support third-party risk review • Manage security tooling vendors: product selection, quote review, renewals, configuration, and invoice oversight • Support & Operations: • Respond to security and provision tickets in a timely, well-documented manner • Create and maintain security documentation: policies, standards, baselines, procedures, and runbooks
Apply in one click
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT