F logo

Head of Information Security/Compliance

Frontera HealthDenver, Colorado

$175,000 - $220,000 / year

Automate your job search with Sonara.

Submit 10x as many applications with less effort than one manual application.1

Reclaim your time by letting our AI handle the grunt work of job searching.

We continuously scan millions of openings to find your top matches.

pay-wall

Overview

Schedule
Full-time
Career level
Executive
Remote
Remote
Compensation
$175,000-$220,000/year
Benefits
Health Insurance
Paid Vacation
401k Matching/Retirement Savings

Job Description

Frontera is reimagining how children with autism and other behavioral health needs get the care they deserve. We bring together world-class clinicians, technologists, and autism specialists to build cutting-edge AI tools that help care teams work smarter and spend more time with the children and families who need them most.

Our platform is HIPAA-compliant and designed for the real-world needs of behavioral health teams - from psychologists to ABA therapists. By combining evidence-based care with powerful technology, we’re expanding access to high-quality services for families everywhere.

Our Mission

Frontera exists to close the care gap: every child, no matter where they live, should be able to access effective behavioral healthcare.

Role Overview

Frontera is hiring a Head of Information Security/Compliance to own our cloud security posture and compliance program as we scale. This isn't a compliance-generalist seat that partners with engineering from the outside - we need someone with real cloud security depth who can operate inside our AWS infrastructure, hold SOC 2 audits, and be the senior security voice both internally and in front of customers and boards. As we sell into healthcare and enterprise, this role is central to Frontera being trusted with sensitive data at scale.

What You'll Own

  • Compliance program ownership
    • Own Frontera's HIPAA program across both Frontera Health and FronteraCare, and serve as the designated HIPAA Security and Privacy Officer.
    • Own the SOC 2 program end to end, including audit scope, observation periods, the auditor relationship, evidence collection in our compliance platform, and tracking remediation to closure.
    • Run the annual HIPAA risk assessment and keep a living risk register that leadership reviews regularly.
    Internal policies and standards
    • Build Frontera's internal policy framework across both entities, covering acceptable use, access control, data classification and handling, device and endpoint use, AI tool use, vendor onboarding, incident response, and data retention and deletion.
    • Write role-specific procedures for FronteraCare clinic staff, so front-line teams know exactly what to do in common situations like texting families, using personal devices, or trying a new app.
    • Set up a clear, fast way for employees to request new tools, so staff don't feel they have to go around security to get their work done.
    • Keep policies current as the business changes, including new products, new AI vendors, and new clinic locations. Run annual reviews and have leadership sign off on changes.
    • Make sure each policy maps to HIPAA and SOC 2 requirements, so one set of policies serves both audits and nothing is duplicated.
    • Define workforce accountability, including policy acknowledgment, training requirements, and a fair, consistent process when policies aren't followed. Work with HR, Legal, and IT Operations on the parts they own.
    Risk, incidents, and vendors
    • Lead incident response on the compliance side, including breach risk assessments, reportability decisions, and notifications to regulators and affected parties.
    • Own vendor risk management, including security reviews of new tools, BAA coverage, and documented data deletion when vendors are offboarded.
    • Set data governance standards for AI vendors, covering data residency, retention, zero-data-retention requirements, and the conditions for using de-identified data in model training.
    • Oversee privacy and consent for clinic-facing products, including in-clinic video, working with Product and Clinical.
    Security culture and FronteraCare operations
    • Build security and privacy practices that clinic staff actually follow, through training and simple guidance.
    • Prevent and catch shadow IT, especially tools that handle PHI (protected health information) without a BAA.
    • Run security awareness training and phishing simulations, and track completion across both entities.
    • Act as the go-to person for employees with security or privacy questions, so asking is easier than working around the rules.
    Customers and the business
    • Lead security and compliance reviews with customers and prospects, including questionnaires, BAA negotiations, and live calls. Bring in Engineering for deep technical questions.
    • Own our public trust center and the process for sharing the SOC 2 report.
    • Report on security and compliance posture to the executive team, and to the board when asked.
    Partnership with Engineering
    • Set security requirements for cloud infrastructure, access control, and device management. Engineering and IT implement and run those controls.
    • Review security architecture decisions, penetration test results, and vulnerability findings, and track them against the risk register.
    • Join product planning early so that HIPAA and SOC 2 requirements shape the design rather than being added after launch.
    Team and structure
    • Manage the transition from outside security support to an in-house function, and decide when to wind that support down.
    • Recommend how the security and compliance function should grow as FronteraCare scales, including whether to add headcount or use outside support.

Qualifications

  • 8-12 years of security/compliance experience, including hands-on work running SOC 2 audits against AWS cloud infrastructure — not managed a team that did, or partnered with engineering from a compliance-manager seat
  • Hands-on IAM architecture experience
  • Cloud security certification(s)
  • Has sat on security reviews directly with prospects or customers, and can speak to how those conversations went
  • Enterprise fluency — comfortable being the senior security presence in front of customers, partners, and boards

Preferred

  • Healthcare or regulated-industry background
  • Fractional CISO experience at a digital health company, especially if you're looking to move in-house
  • Security leadership at a Series B-D health tech company
  • An engineering background that grew into compliance ownership, with strong infrastructure or platform depth

We have determined a salary range for this position that takes into account several factors including experience, knowledge, education, skills, and abilities. Please note that the salary information is a general guideline and the exact salary will be determined based on the individual’s qualifications and experience, with consideration given to the factors listed above. All full-time employee benefits include a stake in shared success through stock options, health benefits, 401(k) plan, and 4 weeks of PTO per year.

This role is based in Denver, CO or remote within the US.

Expected Salary Range: $175,000 to $220,000

Why Frontera?

  • Opportunity to be at the forefront of innovation in pediatric healthcare.
  • Work on challenging and impactful projects that leverage cutting-edge technologies.
  • Collaborate with a talented and passionate team in a fast-paced and dynamic environment.
  • Make a real difference in the lives of children and families in rural communities.
  • Competitive salary and benefits package.
Our Denver Office & Perks
  • Dog-friendly office.
  • Catered lunch from local Denver restaurants five days a week, plus occasional breakfasts and dinners.
  • Robust snack program and great coffee options (including cappuccino machine and cold brew cans).
  • Regular team events and low-key socials.
  • Up to $150/month commuter stipend, discounted nearby parking, and a discounted Colorado Athletic Club membership.
  • Thoughtfully designed space for focus, collaboration, and connection.
  • Competitive health benefits, stock options, 401(k), and generous PTO.

Join us in building the future of behavioral healthcare!

Automate your job search with Sonara.

Submit 10x as many applications with less effort than one manual application.

pay-wall

FAQs About Head of Information Security/Compliance Jobs at Frontera Health

What is the work location for this position at Frontera Health?
This job at Frontera Health is located in Denver, Colorado, according to the details provided by the employer. Some roles may also include multiple work locations depending on the requirement.
What pay range can candidates expect for this role at Frontera Health?
Candidates can expect a pay range of $175,000 and $220,000 per year.
What employment applies to this position at Frontera Health?
Frontera Health lists this role as a Full-time position.
What experience level is required for this role at Frontera Health?
Frontera Health is looking for a candidate with "Executive" experience level.
Does Frontera Health allow remote work for this role?
Yes, this position at Frontera Health supports remote work, giving candidates the flexibility to work outside the primary office location.
What benefits are offered by Frontera Health for this role?
Frontera Health offers following benefits: Health Insurance, Paid Vacation, 401k Matching/Retirement Savings, and Health & Wellness Programs for this position. Actual benefits may vary depending on the employer's policies and employment terms.
What is the process to apply for this position at Frontera Health?
You can apply for this role at Frontera Health either through Sonara's automated application system, which helps you submit applications 10X faster with minimal effort, or by applying manually using the direct link on the job page.