Ovii Job Board

Manager, Technology Risk

Hinge Health

San Francisco, US • Hybrid - San Francisco, US • Full-Time • 2+ years

Posted 2026-06-11 USD 198,000 - USD 250,000 per year Tech & Engg

Apply on employer site

Job Description

Ovii's Interpretation of the Role

The Technology Risk Manager is a senior individual contributor who owns Hinge Health’s technology risk posture across security, infrastructure, and IT. The role drives risk identification, remediation, and regulatory compliance (SOX, HIPAA) while partnering with engineering, security, and audit teams.

Role Snapshot

  • Technology risk ownership
  • SOX & HIPAA compliance
  • Cross‑functional remediation leadership
  • Executive risk reporting
  • Regulatory governance
  • Collaboration with security & engineering

Must-Have Requirements

  • SOX IT General Controls
  • HIPAA compliance
  • Technology risk management (risk register, remediation tracking)
  • Vulnerability management
  • Access management, change management, computer operations controls
  • Executive communication and reporting
  • technology risk
  • SOX ITGC
  • regulated environments

Nice-to-Have Signals

  • CISA or CISSP certification
  • Prior Big 4 audit or advisory experience
  • Familiarity with cloud security frameworks
  • Big 4 audit experience
  • CISA/CISSP certifications
  • CISA
  • CISSP

Work Setup

  • Location: San Francisco, USA
  • Work mode: HYBRID
  • Remote scope: UNSPECIFIED
  • Travel: Occasional off‑site/on‑site events
  • Employment type: Full-Time

Eligibility Gates

  • Visa sponsorship: unknown

Not Specified in JD

  • Visa sponsorship
  • Salary range
  • Remote eligibility
  • Education requirement
  • Security clearance
  • Travel frequency

What You'll Likely Work On

  • Maintain and continuously refine the Technology Risk Register with clear ratings, owners, and mitigation plans.
  • Track remediation progress across engineering and IT teams, escalating and unblocking to meet agreed SLAs.
  • Serve as the primary interface for internal and external auditors on SOX ITGC testing, documentation, and evidence collection.
  • Coordinate remediation of SOX ITGC findings, ensuring high‑quality corrective actions and timely closure.
  • Partner with Security, Accounting, Legal/Compliance, and IT to support HIPAA and other healthcare regulatory requirements.
  • Collaborate with Application Security, SRE, and Infrastructure teams to aggregate, prioritize, and track code vulnerabilities and infrastructure risks.
  • Analyze vulnerability trends to focus remediation on highest‑impact items and drive consistent documentation of risk decisions.
  • Design and maintain risk and control dashboards and produce executive‑ready reports that translate technical risk into clear business language.

Good Fit If You Have

  • Proven ability to influence senior engineering and IT stakeholders.
  • Experience leading cross‑functional risk or compliance programs in regulated environments.
  • Exceptional written and verbal communication, translating technical risk for executives.

Skills

  • SOX IT General Controls
  • HIPAA compliance
  • Vulnerability management
  • Risk register maintenance
  • Regulatory reporting
  • Stakeholder influence
  • Access & change management
  • Cloud security fundamentals
  • Audit liaison
  • Executive communication