The IT company Andersen invites an experienced Compliance Manager (Healthcare) to become a part of a successful team.
Andersen is a pre-IPO software development company that provides a full cycle of services. For over 19 years, we have been helping enterprises and middle-sized firms transform their businesses by creating effective digital solutions using innovative technologies.
– Leading and developing the group compliance team across all three streams.
– Owning the compliance strategy, policies, controls, and risk register for the group.
– Ensuring compliance with healthcare regulations (HIPAA, GDPR, fraud and abuse, billing/coding), information security and privacy frameworks (ISO 27001, ISO 27701, SOC 2), and medical device/pharma regulations (ISO 13485, 21 CFR Part 820, MDR, GxP, FDA).
– Running internal risk assessments, audits, and compliance training across all streams.
– Leading certification initiatives (ISO 27001, ISO 27701, ISO 9001, ISO 13485, SOC 2, HITRUST, MDSAP).
– Managing relationships with external auditors, certification bodies, regulators, and accreditation bodies.
– Owning ISMS, PIMS, and QMS documentation and continuous compliance.
– Developing and launching compliance services for clients (audits, readiness programs, DPO-as-a-Service).
– Supporting sales and presales in designing compliance solutions and overseeing delivery of compliance consulting projects.
– Owning medical device/pharma regulatory compliance, including 510(k) submissions, FDA guidance, GxP validation, and IQ/OQ/PQ.
– Reporting regularly to senior management and the board on compliance status and risk exposure.
– 8+ years in compliance, regulatory affairs, quality, information security, or risk management.
– At least 3 years in a healthcare-related environment.
– Experience managing or mentoring compliance teams across more than one business line.
– Deep knowledge of HIPAA, GDPR, and global healthcare regulations.
– Strong working knowledge of ISO 27001, ISO 27701, and SOC 2.
– Strong working knowledge of ISO 13485, ISO 9001, 21 CFR Part 820, MDR, and GxP.
– Hands-on experience with ISO 14971, IEC 62304, IEC 62366, FDA compliance, 510(k), and IQ/OQ/PQ.
– Experience in at least two of the following: healthcare provider, health tech/software, medical device/pharma, compliance consulting.
– Strong documentation, process management, and communication skills.
– Proven cross-functional work with Legal, HR, Security, Quality, Regulatory, Clinical, Product, and leadership.
– English proficiency at Upper-Intermediate+ level or higher.
– CHC, CHPC, CHRC, CIPP, CIPM, ISO 27001 Lead Implementer/Auditor, CISM, CISA, CQA, RAC, or equivalent certifications.
– Experience building compliance services in consulting or technology.
– Knowledge of NIST, COBIT, CIS, HITRUST CSF, ISO 14971.
– Experience with MDSAP, HITRUST, or other healthcare certifications.
– Experience leading regulatory inspections, notified body audits, or accreditation surveys.
– Experience in a group, holding, or multi-entity environment.