Job RadarAll jobs
Active Remote Denver, Colorado; Remote Posted · 30.09.2026 Greenhouse (US)

Head of Information Security/Compliance

Frontera

Frontera is reimagining how children with autism and other behavioral health needs get the care they deserve. We bring together world-class clinicians, technologists, and autism specialists to build cutting-edge AI tools that help care teams work smarter and spend more time with the children and families who need them most. Our platform is HIPAA-compliant and designed for the real-world needs of behavioral health teams • from psychologists to ABA therapists. By combining evidence-based care with powerful technology, we’re expanding access to high-quality services for families everywhere. Our Mission Frontera exists to close the care gap: every child, no matter where they live, should be able to access effective behavioral healthcare.Role Overview Frontera is hiring a Head of Information Security/Compliance to own our cloud security posture and compliance program as we scale. This isn't a compliance-generalist seat that partners with engineering from the outside • we need someone with real cloud security depth who can operate inside our AWS infrastructure, hold SOC 2 audits, and be the senior security voice both internally and in front of customers and boards. As we sell into healthcare and enterprise, this role is central to Frontera being trusted with sensitive data at scale. What You'll Own Compliance program ownership Own Frontera's HIPAA program across both Frontera Health and FronteraCare, and serve as the designated HIPAA Security and Privacy Officer. Own the SOC 2 program end to end, including audit scope, observation periods, the auditor relationship, evidence collection in our compliance platform, and tracking remediation to closure. Run the annual HIPAA risk assessment and keep a living risk register that leadership reviews regularly. Internal policies and standards Build Frontera's internal policy framework across both entities, covering acceptable use, access control, data classification and handling, device and endpoint use, AI tool use, vendor onboarding, incident response, and data retention and deletion. Write role-specific procedures for FronteraCare clinic staff, so front-line teams know exactly what to do in common situations like texting families, using personal devices, or trying a new app. Set up a clear, fast way for employees to request new tools, so staff don't feel they have to go around security to get their work done. Keep policies current as the business changes, including new products, new AI vendors, and new clinic locations. Run annual reviews and have leadership sign off on changes. Make sure each policy maps to HIPAA and SOC 2 requirements, so one set of policies serves both audits and nothing is duplicated. Define workforce accountability, including policy acknowledgment, training requirements, and a fair, consistent process when policies aren't followed. Work with HR, Legal, and IT Operations on the parts they own. Risk, incidents, and vendors Lead incident response on the compliance side, including breach risk assessments, reportability decisions, and notifications to regulators and affected parties. Own vendor risk management, including security reviews of new tools, BAA coverage, and documented data deletion when vendors are offboarded. Set data governance standards for AI vendors, covering data residency, retention, zero-data-retention requirements, and the conditions for using de-identified data in model training. Oversee privacy and consent for clinic-facing products, including in-clinic video, working with Product and Clinical. Security culture and FronteraCare operations Build security and privacy practices that clinic staff actually follow, through training and simple guidance. Prevent and catch shadow IT, especially tools that handle PHI (protected health information) without a BAA. Run security awareness training and phishing simulations, and track completion across both entities. Act as the go-to person for employees with security or privacy questions, so asking is easier than working around the rules. Customers and the business Lead security and compliance reviews with customers and prospects, including questionnaires, BAA negotiations, and live calls. Bring in Engineering for deep technical questions. Own our public trust center and the process for sharing the SOC 2 report. Report on security and compliance posture to the executive team, and to the board when asked. Partnership with Engineering Set security requirements for cloud infrastructure, access control, and device management. Engineering and IT implement and run those controls. Review security architecture decisions, penetration test results, and vulnerability findings, and track them against the risk register. Join product planning early so that HIPAA and SOC 2 requirements shape the design rather than being added after launch. Team and structure Manage the transition from outside security support to an in-house function, and decide when to wind that support down. Recommend how the security and compliance function should grow as FronteraCare scales, including whether to add headcount or use outside support. Qualifications 8-12 years of security/compliance experience, including hands-on work running SOC 2 audits against AWS cloud infrastructure — not managed a team that did, or partnered with engineering from a compliance-manager seat Hands-on IAM architecture experience Cloud security certification(s) Has sat on security reviews directly with prospects or customers, and can speak to how those conversations went Enterprise fluency — comfortable being the senior security presence in front of customers, partners, and boards Preferred Healthcare or regulated-industry background Fractional CISO experience at a digital health company, especially if you're looking to move in-house Security leadership at a Series B-D health tech company An engineering background that grew into compliance ownership, with strong infrastructure or platform depth We have determined a salary range for this position that takes into account several factors including experience, knowledge, education, skills, and abilities. Please note that the salary information is a general guideline and the exact salary will be determined based on the individual’s qualifications and experience, with consideration given to the factors listed above. All full-time employee benefits include a stake in shared success through stock options, health benefits, 401(k) plan, and 4 weeks of PTO per year. This role is based in Denver, CO or remote within the US. Expected Salary Range: $175,000 to $220,000Why Frontera? Opportunity to be at the forefront of innovation in pediatric healthcare. Work on challenging and impactful projects that leverage cutting-edge technologies. Collaborate with a talented and passionate team in a fast-paced and dynamic environment. Make a real difference in the lives of children and families in rural communities. Competitive salary and benefits package. Our Denver Office & Perks Dog-friendly office. Catered lunch from local Denver restaurants five days a week, plus occasional breakfasts and dinners. Robust snack program and great coffee options (including cappuccino machine and cold brew cans). Regular team events and low-key socials. Up to $150/month commuter stipend, discounted nearby parking, and a discounted Colorado Athletic Club membership. Thoughtfully designed space for focus, collaboration, and connection. Competitive health benefits, stock options, 401(k), and generous PTO. Join us in building the future of behavioral healthcare!
This job was verified from Greenhouse (US). Applications are completed on the original source.
Apply on the original listing ↗
Something wrong with this job?