
Manager, Technology Risk
Hinge Health
Posted 2026-06-11
USD 198,000 - USD 250,000 per year
Tech & Engg
Job Description
Ovii's Interpretation of the Role
The Technology Risk Manager is a senior individual contributor who owns Hinge Health’s technology risk posture across security, infrastructure, and IT. The role drives risk identification, remediation, and regulatory compliance (SOX, HIPAA) while partnering with engineering, security, and audit teams.
Role Snapshot
- Technology risk ownership
- SOX & HIPAA compliance
- Cross‑functional remediation leadership
- Executive risk reporting
- Regulatory governance
- Collaboration with security & engineering
Must-Have Requirements
- SOX IT General Controls
- HIPAA compliance
- Technology risk management (risk register, remediation tracking)
- Vulnerability management
- Access management, change management, computer operations controls
- Executive communication and reporting
- technology risk
- SOX ITGC
- regulated environments
Nice-to-Have Signals
- CISA or CISSP certification
- Prior Big 4 audit or advisory experience
- Familiarity with cloud security frameworks
- Big 4 audit experience
- CISA/CISSP certifications
- CISA
- CISSP
Work Setup
- Location: San Francisco, USA
- Work mode: HYBRID
- Remote scope: UNSPECIFIED
- Travel: Occasional off‑site/on‑site events
- Employment type: Full-Time
Eligibility Gates
- Visa sponsorship: unknown
Not Specified in JD
- Visa sponsorship
- Salary range
- Remote eligibility
- Education requirement
- Security clearance
- Travel frequency
What You'll Likely Work On
- Maintain and continuously refine the Technology Risk Register with clear ratings, owners, and mitigation plans.
- Track remediation progress across engineering and IT teams, escalating and unblocking to meet agreed SLAs.
- Serve as the primary interface for internal and external auditors on SOX ITGC testing, documentation, and evidence collection.
- Coordinate remediation of SOX ITGC findings, ensuring high‑quality corrective actions and timely closure.
- Partner with Security, Accounting, Legal/Compliance, and IT to support HIPAA and other healthcare regulatory requirements.
- Collaborate with Application Security, SRE, and Infrastructure teams to aggregate, prioritize, and track code vulnerabilities and infrastructure risks.
- Analyze vulnerability trends to focus remediation on highest‑impact items and drive consistent documentation of risk decisions.
- Design and maintain risk and control dashboards and produce executive‑ready reports that translate technical risk into clear business language.
Good Fit If You Have
- Proven ability to influence senior engineering and IT stakeholders.
- Experience leading cross‑functional risk or compliance programs in regulated environments.
- Exceptional written and verbal communication, translating technical risk for executives.
Skills
- SOX IT General Controls
- HIPAA compliance
- Vulnerability management
- Risk register maintenance
- Regulatory reporting
- Stakeholder influence
- Access & change management
- Cloud security fundamentals
- Audit liaison
- Executive communication