At Revere Health, we believe there is a better path to healing and healthcare maintenance, and we’re working on this mission—one patient at a time. We’re a national leader in a movement called value-base care which aims to improve treatment outcomes and keep costs down. Our internal culture is one that promotes respect and consistently recognizes the impact that individual employees have on the mission of the organization. Position Summary The Information Risk & Compliance Specialist supports privacy, security, and information-risk management in a healthcare environment by helping assess control effectiveness, track remediation, support incident investigations, and coordinate compliance activities across technical and business stakeholders. This role is best suited for a candidate with practical experience in healthcare compliance, information risk, privacy, or security operations who is comfortable working with technical teams, interpreting findings, and driving issues to resolution. The successful candidate will bring structure, accountability, and steady progress to a growing information risk management program. Essential Job Functions Compliance and Information Risk Coordination: • Maintain the compliance and information risk calendar, including key obligations, due dates, owners, evidence needs, and follow-up actions. • Track the risk register and related issue logs, ensuring items remain current, actionable, and appropriately escalated. • Work with control owners to validate status, document remediation progress, and drive closure of compliance gaps. • Identify overdue items, missing ownership, and barriers to completion, and help move issues toward resolution. Privacy Incident Investigation Support: • Receive, log, and organize privacy incident reports in a timely manner. • Gather facts, timelines, system details, and supporting documentation needed for investigation and decision-making. • Coordinate follow-up with IT Security, HIM, and business owners as needed. • Track investigation milestones, status updates, and corrective actions through closure. • Prepare working notes and summaries for Privacy Officer review. • Escalate potentially high-risk matters promptly. Control, Audit, and Assessment Support: • Support internal and external audits, assessments, and compliance questionnaires. • Coordinate evidence requests and maintain audit-ready documentation. • Validate supporting evidence for controls, findings, observations, and corrective actions. • Track remediation status through completion and confirm closure documentation is complete. • Help prepare concise updates on compliance posture, open issues, and recurring risk themes. Policy and Documentation Support: • Assist with policy, standard, procedure, and control documentation. • Help keep documentation current, clear, and aligned with operational practice. • Support version control, review cycles, and approval tracking. • Review documentation for consistency between written requirements and actual workflows. Third-Party and Vendor Risk Support: • Assist with vendor intake, risk tiering, and due diligence workflows. • Coordinate security and privacy questionnaires, follow-up requests, and remediation tracking. • Maintain visibility into vendor-related privacy and compliance risk. • Help ensure third-party obligations are documented, monitored, and followed through. Cross-Functional Coordination: • Work directly with IT Security, IT Infrastructure, HIM, Legal, Procurement, Compliance, and business units. • Facilitate follow-up on outstanding actions and unresolved issues. • Communicate clearly with both technical and non-technical stakeholders. • Support timely coordination between operational owners and control owners. Reporting and Metrics: • Maintain status reports, dashboards, and action trackers. • Provide concise updates on open issues, risks, incidents, and remediation. • Use data to highlight trends, aging items, repeat findings, and recurring problem areas. • Help leadership understand where technical and compliance gaps are appearing and what is needed to close them. Other Duties as Assigned: • Perform other duties and special projects as assigned. Required Qualifications • Bachelor’s degree or equivalent experience in information systems, information security, healthcare administration, compliance, or a related discipline. • Three or more years of experience in healthcare information risk, privacy, compliance, security operations, audit support, or a closely related GRC role. • Experience working with technical and operational stakeholders to identify, track, and close security or compliance gaps. • Working knowledge of HIPAA Privacy and Security requirements. • Familiarity with risk assessments, control validation, audit evidence, and remediation tracking. • Ability to understand technical findings, assess their operational impact, and communicate them clearly to varied audiences. • Strong written and verbal communication skills. • Strong critical thinking, organization, and follow-through. • Ability to handle confidential information with sound judgment and discretion. • Experience working in a regulated healthcare environment. • Ability to travel periodically (Intrastate) to assess risk and compliance at remote clinics. Preferred Qualifications • Direct experience in healthcare information security, privacy, or information risk. • Hands-on exposure to IAM, vulnerability management, endpoint security, log review, or similar enterprise security processes. • Experience supporting privacy incidents, security incidents, or breach evaluations. • Experience with GRC tools or compliance tracking platforms. • Experience with Microsoft 365, Azure, or similar enterprise technology environments. • Familiarity with PCI DSS, NIST CSF, FISMA, HITRUST, or similar frameworks. • Experience supporting audit readiness or control testing in a healthcare or regulated environment. • Familiarity with HIM workflows, clinical operations, or healthcare business processes. Hours 9:00 AM to 5:00 PM (flexible) Monday - Friday Infrequent evening/weekend hours Eligible for hybrid work after 90 days (up to 3 days/week remote) Core Competencies • Results oriented and focused on closure. • Uses critical thinking to identify gaps and prioritize action. • Works well across IT, HIM, and business teams. • Takes ownership and follows through reliably. • Communicates clearly and concisely. • Adapts well in a changing environment and helps bring structure to ambiguity. Working Model • This role should operate as a hands-on coordinator and problem solver. • The successful candidate will be comfortable working in a dynamic environment where process maturity is still developing. • The role is well suited to someone who is energized by the opportunity to build structure, reduce risk, and improve consistency over time.
Contracts Director - Juniper Re
Baldwin
Senior Litigation Attorney (Portland Metro)
Amfam
Associate
Constangy Brooks Smith & Prophete LLP
PI Paralegal
Edgar Snyder & Associates, LLC
Director, Contracts
Elligo Health Research Inc
Risk Manager
RideNow Powersports