
Manager, Technology Risk
Hinge Health
Posted 2026-06-11
USD 191,200 - USD 286,800 per year
Tech & Engg
Job Description
Ovii's Interpretation of the Role
The Technology Risk Manager drives Hinge Health’s security and compliance posture, owning the risk register, remediation workflow, and regulatory governance across engineering and IT. The role translates technical vulnerabilities into business risk, produces executive‑ready reports, and partners with auditors, security, legal, and operations teams.
Role Snapshot
- Own technology risk register
- Drive remediation across engineering & IT
- Lead SOX & HIPAA compliance programs
- Partner with security, legal, and audit teams
- Produce executive risk reports
- Analyze vulnerability trends
Must-Have Requirements
- SOX IT General Controls
- HIPAA compliance experience
- Technology risk experience (2+ years)
- technology risk
- SOX ITGC
- HIPAA compliance
Nice-to-Have Signals
- CISA certification
- CISSP certification
- Big 4 audit experience
- CISA/CISSP certification
- Big 4 audit background
- CISA
- CISSP
Work Setup
- Location: San Francisco, USA
- Work mode: HYBRID
- Travel: Occasional off‑site/on‑site events
- Employment type: Full-Time
Not Specified in JD
- Visa sponsorship
- Salary range
- Remote eligibility
- Education requirement
- Certifications
- Travel
- Security clearance
- Coding test
What You'll Likely Work On
- Maintain and continuously refine the Technology Risk Register with clear ratings, owners, and mitigation plans.
- Track and drive remediation progress across engineering and IT teams, escalating and unblocking to meet SLAs.
- Serve as primary interface for internal and external auditors on SOX ITGC testing, documentation, and evidence collection.
- Coordinate remediation of SOX ITGC findings, ensuring high‑quality corrective actions and timely closure.
- Partner with Security, Accounting, Legal/Compliance, and IT to support HIPAA and other healthcare regulatory requirements.
- Aggregate, prioritize, and track code vulnerabilities, penetration‑testing findings, and infrastructure risks across the SDLC.
- Analyze vulnerability trends to focus teams on highest‑impact remediation work.
- Design dashboards and produce executive‑ready reports that translate technical risk into clear business language.
Good Fit If You Have
- Exceptional written and verbal communication; can distill complex technical risk into concise executive narratives.
- Proven ability to influence senior engineering and IT stakeholders.
- Comfort working with PHI‑handling or similarly sensitive data environments.
- Track record leading cross‑functional risk or compliance programs with high visibility.
Skills
- SOX IT General Controls
- HIPAA compliance
- Risk register management
- Vulnerability assessment
- Stakeholder influence
- Regulatory reporting
- Cloud security fundamentals
- Access & change management