Get the latest updates on AI-powered hiring, career growth, and technical deep-dives delivered to your inbox.
hinge-health
The Technology Risk Manager is a senior individual contributor responsible for driving Hinge Health’s technology risk posture across security, infrastructure, and IT. You’ll act as the primary owner for technology risk across multiple teams rather than as a pure advisor.
The role has broad exposure to Security , IT, Engineering leadership, and you’re expected to confidently surface risks, drive clear risk evaluations, and collaborate with partners to land practical remediation decisions.
You’ll work closely with Application Security, Engineering , Security, and IT to translate technical vulnerabilities into business risk, maintain the Technology Risk Register, and ensure high-quality, timely remediation in a PHI-handling and heavily regulated environment.
What You’ll Do Maintain and continuously refine the Technology Risk Register, documenting cyber, operational, and regulatory risks with clear ratings, owners, and mitigation plans.
Track and drive remediation progress across engineering and IT teams, escalating and unblocking as needed to ensure risk treatment plans meet agreed SLAs. Regulatory Compliance & Governance (SOX & HIPAA). Serve as a primary interface for internal and external auditors on SOX IT General Controls (ITGC) and related technology control testing, documentation, and evidence collection.
Coordinate and track remediation of SOX ITGC findings, ensuring clear ownership, high-quality corrective actions, and timely closure to prevent control deficiencies and material weaknesses. Partner with Security, Accounting, Legal/Compliance, and IT to ensure risk and control practices support HIPAA and other healthcare regulatory requirements.
Partner with Application Security, SRE, and Infrastructure teams to aggregate, prioritize, and track code vulnerabilities, penetration-testing findings, and infrastructure risks across the SDLC. Analyze vulnerability trends (by system, control, and data sensitivity) to help teams focus on the highest-impact remediation work.
Drive consistent, high-quality documentation of risk decisions, mitigations, and compensating controls. Design and maintain risk and control dashboards that provide senior leadership with clear insight into security posture, compliance status, and remediation velocity.
Produce recurring executive-ready reports and narratives that translate complex technical risk into clear, non-technical language for decision-makers and risk committees. Recommend and refine KPIs/KRIs that measure technology risk, SOX ITGC health, and vulnerability reduction over time.
Inclusive healthcare and benefits: On top of comprehensive medical, dental, and vision coverage, we offer employees and their family members help with gender-affirming care, tools for family and fertility planning, and travel reimbursements if healthcare isn’t available where you live.
Planning for the future: Start saving for the future with our traditional or Roth 401k retirement plan options which include a 2% company match. Modern life stipends: Manage your own learning and development Grow with us through discounted company stock through our ESPP with easy payroll deductions.
Culture & Engagement Hinge Health is an equal opportunity employer and prohibits discrimination and harassment of any kind. We make employment decisions without regards to race, color, religion, sex, sexual orientation, gender identity, national origin, age, veteran status, disability status, pregnancy, or any other basis protected by federal, state or local law.
We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. We provide reasonable accommodations for candidates with disabilities. If you feel you need assistance or an accommodation due to a disability, let us know by reaching out to your recruiter.
By submitting your application you are acknowledging we are using your personal data as outlined in the personnel and candidate privacy policy. Beware of Phishing Attempts: We've noticed an increase in phishing where fraudsters impersonate employees and send fake job offers to steal sensitive information. We'll never ask for financial details during the hiring process and only use "@ hingehealth.com " emails.
If you receive a suspicious offer, stop communication and report it to the US FBI Internet Crime Complaint Center. To verify an email from our recruiting team, forward it to security@hingehealth.com .
Matched to your profile
We surface this role because it matches profiles like yours, not because we vet the employer. Always confirm the pay, location, and remote details on hinge-health's official site before you apply.