Information Security Manager
AffirmedRx, PBC
| Company | AffirmedRx, PBC |
| Category | Security |
| Location | Remote |
| Remote | Remote |
| Employment | Not stated |
| Level | Manager |
| Salary | Not stated by the employer |
| Posted | 28 Jul 2026 |
| Last verified | 30 Jul 2026 |
| Source | Employer career page (greenhouse) |
Description
AffirmedRx is on a mission to improve health care outcomes by bringing clarity, integrity, and trust to pharmacy benefit management. We are committed to making pharmacy benefits easy to understand, straightforward to access and always in the best interest of employers and the lives they impact. We accomplish this by bringing total clarity to business practices, leading with clinical approaches, and utilizing state-of-the-art technology.
Join us in improving health care outcomes for all! We promise to do what’s right, always.
Position Summary:
The Information Security Manager is responsible for operating and enhancing AffirmedRx’s enterprise security and compliance program within a fully remote, Microsoft-centric environment. This role safeguards protected health information (PHI) and other sensitive data to ensure compliance with HIPAA and organizational security requirements. The position manages identity and access management, security monitoring, incident response, application security, data governance, and vendor security assessments. The Manager also supports audit readiness by maintaining documentation and evidence for regulatory and certification requirements. A key focus of the role is sustaining SOC 2 and URAC compliance while leading efforts toward HITRUST CSF certification.
What you will do:
Identity & Access Management:
Administer Microsoft Entra ID / Active Directory, including users, groups, conditional access, and MFA
Design, implement, and maintain single sign-on (SSO) integrations across the application portfolio (SAML / OIDC)
Run periodic user access reviews and account audits; document findings and drive remediation of access exceptions
Manage provisioning and deprovisioning; enforce least privilege and role-based access control
Security Operations & Monitoring:
Operate and tune the SIEM (such as Microsoft Sentinel); review logs, alerts, and reports across endpoints, servers, network, and cloud
Triage and investigate alerts; participate in incident response (identify, contain, eradicate, recover, and document lessons learned)
Maintain and improve detection coverage in support of a defense-in-depth strategy
Compliance, Audit & Certification:
Maintain SOC 2 and URAC: own evidence collection, control mapping, and coordination with auditors
Lead and support the path to HITRUST CSF certification, including gap assessment, control implementation, evidence gathering, and validated-assessment readiness
Track remediation items, control owners, and audit timelines
Application & Data Security:
Provide security oversight across the application portfolio
Document application and data flows, integrations, and trust boundaries
Support secure configuration, vulnerability remediation, and application access governance
Data Governance & eDiscovery:
Administer Microsoft Purview: data loss prevention (DLP), data classification and labeling, and retention
Execute eDiscovery, content and email search, and legal holds in support of legal and compliance requests
Vendor & Security Tooling Management:
Evaluate, select, and recommend security products and enhancements to existing controls
Conduct and respond to vendor security assessments and support third-party risk review
Manage security tooling vendors: product selection, quote review, renewals, configuration, and invoice oversight
Support & Operations:
Respond to security and provision tickets in a timely, well-documented manner
Create and maintain security documentation: policies, standards, baselines, procedures, and runbooks
What you need:
Bachelor’s degree in Computer Science, Information Security, Information Technology, or a related field, or equivalent experience
4–7 years in information security or security engineering
Hands-on experience with the Microsoft security stack (Entra ID / Active Direct
986,449 openings. Erioun finds yours.Scored against your own profile, every hour.Try the radar →