Skip to content
Virta HealthVirta HealthUnited States

Director, Security Engineering

Leads enterprise security engineering and SecOps, directing a security team, outsourced MDR/SOC operations, incident response, and a Zero Trust transformation. Requires 10+ years in cybersecurity or cloud infrastructure security, leadership experience, and deep GCP, micro-segmentation, workload identity, and CI/CD expertise.

162k – 209k/yr
Remote10+ YOESecurity Engineering

About the role

Responsibilities

Hands-on Engineering & Operational Leadership

  • Direct, mentor, and grow a high-performing team of security engineers.
  • Conduct technical sprint planning, alignment, and coaching while maintaining the technical depth to dive into configurations alongside the team.

Zero Trust Strategy

  • Lead the enterprise-wide transition to Zero Trust Architecture (ZTA) across IT, corporate platforms, and cloud engineering infrastructure.
  • Establish identity as the perimeter, inhibit lateral movement, and prioritize data survivability.

Security Operations

  • Own monitoring, detection engineering, and incident response operations.
  • Manage outsourced MDR/SOC vendor relationships, telemetry pipelines, alert triage, and threat containment.

Blast Radius Reduction

  • Design, deploy, and maintain blast-radius reduction solutions.
  • Implement micro-segmentation boundaries, including GCP VPC Service Controls.
  • Enforce ephemeral Workload Identity protocols using temporary tokens instead of static passwords.

Threat Defense and Containment

  • Maintain the Data Topology Map, Cyber Asset Attack Surface (CAA) Matrix, Workload Ledger, and technical Containment Playbooks.

Risk-Based Vulnerability Management

  • Evaluate legacy stacks and cloud services against the Zero Trust Maturity Model (ZTMM).
  • Define patching and remediation SLAs.
  • Partner with IT and Foundations Engineering on targeted mitigation.

Cross-Functional Collaboration

  • Coordinate with GRC, IT, and Product teams to integrate security policies into code pipelines.
  • Apply context-aware guardrails to enterprise AI tools.

90-Day Plan

  • First 30 days: Deep dive into GCP infrastructure and IT security tools, establish relationships with engineering, IT, GRC, and MDR partners, and assess Zero Trust Maturity Model status.
  • Days 30–60: Deliver the baseline Data Topology Map and CAA Matrix, audit MDR ingestion pipelines, tune high-priority alert workflows, integrate security alerting into team communication channels, and expand automated secrets detection in GitHub pipelines.
  • Days 60–90: Finalize the Workload Ledger, pilot micro-segmentation guardrails including GCP VPC Service Controls, standardize technical Containment Playbooks, and present Security Operations and ZTA maturity metrics to executive leadership.

Requirements

  • 10+ years of dedicated experience in cybersecurity, cloud infrastructure security, or SecOps.
  • At least 3+ years managing, leading, or mentoring high-performing security teams.
  • Experience overseeing incident response programs and managing external vendors, including outsourced MDR/SOC partners, SIEM platforms, and EDR/XDR toolsets.
  • Deep technical expertise in cloud security architecture, ideally GCP.
  • Hands-on experience building micro-segmentation models, establishing ephemeral workload identity controls, and securing CI/CD pipelines.
  • Ability to map systemic relationships, formulate risk-prioritization frameworks, and apply Zero Trust Maturity Models.
  • Experience architecting durable AI systems or automation workflows that solve cross-functional challenges and improve operational efficiency.
  • Exceptional communication skills for conveying complex security strategies to non-technical business leaders and external stakeholders.
  • Experience designing and implementing repeatable AI-enabled workflows that address team bottlenecks and improve efficiency.

Compensation and Benefits

  • Compensation range: $161,500–$209,000.
  • Benefits information is available on the company’s Careers page.
  • This is a remote-first role with office hubs in Denver and San Francisco.

Skills

GCPCloud Securityzero trust architecturesecurity operationsIncident ResponsemdrsocSIEMedrxdrmicro-segmentationworkload identityCI/CDGitHubVulnerability Management
NexHealth

Head of IT & Security

NexHealthSan Francisco, CA

Leads NexHealth’s security governance, compliance, IT operations, vendor security, privacy, and incident response programs while building the security function and team. Requires 8+ years of security experience, leadership building programs from the ground up, audit ownership, and a software engineering background.

160k – 200k/yrOn-site8+ YOESecurity Engineering
Fetch

Director, Trust & Safety Detection and Intelligence

FetchUnited States

Leads Fetch’s fraud detection and threat intelligence function, overseeing investigations, detection systems, risk prioritization, and anti-abuse strategy. Requires 10+ years in fraud, trust and safety, cybersecurity, or related risk work, plus 5+ years managing senior teams.

176k – 207k/yrRemote10+ YOESecurity Engineering
Casca

Head of Security & Compliance

CascaSan Francisco, CA

Lead security and compliance for an AI-native banking startup. Build security tooling, manage a team of appsec engineers, own compliance (SOC 2, ISO 27001), and secure AI agent workflows.

200k – 255k/yrOn-site5+ YOESecurity Engineering
Tatari

Head of Security

TatariNew York, NY +2

Lead security engineering team and roadmap for a late-stage AdTech SaaS company. Own incident response, risk management, AWS/K8s security, and compliance programs including SOC 2.

200k – 250k/yrHybrid7+ YOESecurity Engineering
Komodo Health

Director, Corporate Security

Komodo HealthUnited States

Director of Corporate Security responsible for building and maturing the company's internal security program, including identity/access management, endpoint protection, SaaS security, AI governance, incident response, and compliance. Requires 7+ years director-level experience, team leadership, and cross-functional partnership in regulated or healthcare environments.

206k – 290k/yrOn-site7+ YOESecurity Engineering