Matcha
Artisight logo

Director of Information Security

Artisight

Apply

Healthcare Through the Lens of Possibility

$57M total funding raised· Backed by Labcorp Venture Fund, GFT Ventures, JCI Ventures, Mercato Partners
FULL TIMERemote · United States150 employeesPosted Sep 23
security architectureincident responsehealthcare regulatory compliancehipaasoc 2ai governancecloud securityidentity and access managementthird-party risk managementsecurity engineeringrisk assessmentaudit managementsecurity policy developmentexecutive communicationsecurity leadership

Remote startup roles in your inbox

Matcha reads all job descriptions to surface the handful that actually matter in a zero noise email. Simple by design.

Describe your next role, cut the noise

About Artisight

Artisight transforms hospital operations with its Smart Hospital Platform, helping health systems reduce costs, improve efficiency, and enhance patient care. Guided by deep clinical expertise and powered by NVIDIA GPUs, Artisight’s voice-activated sensors and computer vision technology enable real-time observation, virtual nursing, and automated documentation directly in the EHR. The platform integrates seamlessly with existing workflows to reduce staff burden, accelerate patient throughput, and improve safety. More than 400 hospitals across 30 health systems trust Artisight to deliver measurable results, including cutting patient falls by over 50%, reducing nurse turnover, and saving millions annually.

About the Role

The Director of Information Security owns Artisight's security program end to end: security engineering and architecture, incident response, healthcare regulatory compliance (HIPAA and related frameworks), AI governance, and third-party risk. Artisight's platform sits inside hospital environments, so this role carries direct responsibility for protecting patient data, clinical workflows, and the AI systems running on smart hospital infrastructure.

This is a hands-on leadership role. The Director will run a lean security function, work closely with Engineering and the CTO on architecture and tooling decisions, and represent security to executive leadership, hospital customers, and auditors.

This role is remote, based in the United States, and requires U.S. work authorization.

What You’ll Do 

  • Own security architecture review for new systems, integrations, and AI-driven features deployed into hospital environments, and maintain security standards for cloud infrastructure, endpoints, and network/edge security across Artisight's smart hospital hardware and software stack.
  • Own the relationship with our vCISO vendor, co-designing and operating the compliance and security programs.
  • Own the portfolio of third party security products, selecting vendors, ensuring proper implementation, and validating effectiveness.
  • Act as incident commander for security events, coordinating cross-functional response, containment, and communication; build and maintain incident response plans specific to a healthcare environment, including breach notification obligations; lead post-incident reviews focused on systemic fixes.
  • Ensure compliance with the HIPAA Security Rule and other applicable healthcare data protection requirements; own the security policy library, risk register, and control framework; lead internal and external audits and assessments, coordinating evidence collection across Engineering, Product, and Legal.
  • Partner with Engineering and product leadership on the security dimensions of AI governance, since Artisight's core product is AI-driven hospital infrastructure; set risk tolerance, guardrails, and review processes for new AI models, agents, and integrations before rollout; track emerging AI security and regulatory risk and translate it into practical controls.
  • Own vendor and third-party security risk assessment for new tools, integrations, and hospital-system contracts, and maintain a repeatable process for evaluating vendor and partner security posture, including hospital-side IT security requirements.
  • Hire, coach, and develop the security function as it scales beyond a single leader; report program maturity, open risk, and remediation progress to executive leadership on a regular cadence; represent Information Security credibly to executives, hospital customers, and auditors.

What You Have

  • 7+ years in information security, including meaningful experience in security architecture, incident response, and compliance.
  • 3+ years in a security leadership role.
  • Direct incident command experience, including coordinating cross-functional response to significant security events.
  • Experience building or running a healthcare-focused (or otherwise regulated) security compliance program, including familiarity with HIPAA and SOC 2 compliance.
  • Working knowledge of cloud security, identity and access management, and AI/agent architecture risk.
  • Bachelor's degree in Information Security, Information Systems, or a related field, or equivalent experience.
  • Strong written and verbal communication skills, including comfort presenting to executive audiences.

Bonus Points For

  • Experience in a healthcare, medical device, or health-tech company, particularly one operating inside hospital environments.
  • Experience with GRC tooling and control-framework work (SOC 2, ISO 27001, HITRUST, NIST CSF/AI RMF).
  • Familiarity with generative AI and agent security risk, including model/tool access patterns and delegated identity.
  • Relevant certifications (CISSP, CISM, CRISC, HCISPP, or equivalent).
  • Experience leading or building a security function from an early or lean stage.

Why You’ll Enjoy This Role

  • Impact: Your technical leadership will directly shape healthcare systems worldwide, creating AI-powered solutions that improve patient outcomes and provider experiences
  • Growth: You'll work at the intersection of cutting-edge AI, IoT technology, and healthcare innovation while expanding your expertise across our full technical stack
  • Team: Collaborate with executives, operational experts, and Engineering teams who share your passion for transforming healthcare through technology

#LI-REMOTE

Equal Opportunity Employer
Artisight is an equal opportunity employer and does not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other legally protected status.

California Consumer Privacy Act (CCPA)
For information about how we collect and use personal data relating to California residents, please review our Candidate Privacy Notice.

Careers at Artisight
To learn more about our culture and the total rewards we offer, visit our Careers page.

More remote jobs at Artisight

Similar remote jobs