Head of Security
Lead the build-out of Plenful's Security organization from the ground up as a strategic executive partner. Own end-to-end security strategy across product, cloud (AWS), compliance (HIPAA/SOC 2), incident response, and customer trust for a high-growth healthcare AI platform.
About the job
What You'll Do
Build the Security Organization
- Define and execute Plenful's long-term security strategy.
- Build, hire, mentor, and lead a high-performing security team.
- Establish the organizational structure, operating model, and roadmap for Security.
- Create scalable security processes that support rapid product development without slowing innovation.
- Serve as the company's security leader internally and externally.
Product & Application Security
- Establish secure software development lifecycle (SSDLC) practices across Engineering.
- Integrate security into CI/CD pipelines and developer workflows.
- Lead threat modeling, secure architecture reviews, penetration testing, vulnerability management, and application security initiatives.
- Define security standards for AI-powered products and machine learning systems.
Cloud & Infrastructure Security
- Own cloud security strategy across AWS infrastructure.
- Lead identity and access management, secrets management, endpoint security, infrastructure hardening, and network security.
- Build monitoring, detection, logging, and incident response capabilities.
Governance, Risk & Compliance
- Lead Plenful's security compliance strategy, including SOC 2, HIPAA, HITRUST, and future certifications.
- Develop company-wide security policies, standards, and governance.
- Own vendor risk management and third-party security reviews.
- Partner closely with Legal and Compliance on security and privacy initiatives.
Customer Trust & Executive Partnership
- Represent Security during enterprise customer security reviews.
- Partner with Sales and Customer Success to support enterprise deals and customer due diligence.
- Regularly advise executive leadership and the Board on security posture, investments, risks, and strategic priorities.
- Build a security-first culture across the organization through education and partnership.
Incident Response
- Build and mature Plenful's incident response program.
- Lead investigations, postmortems, tabletop exercises, and business continuity planning.
- Continuously improve security monitoring and threat detection capabilities.
What We're Looking For
Required Qualifications
- 15+ years of progressive experience in cybersecurity, information security, cloud security, or infrastructure security.
- 5+ years leading security organizations in technology companies.
- Experience building and scaling security programs from the ground up.
- Strong technical background in modern cloud environments, preferably AWS.
- Deep expertise in application security, cloud security, IAM, DevSecOps, vulnerability management, and incident response.
- Experience securing enterprise SaaS platforms.
- Experience with healthcare security and compliance frameworks including HIPAA and SOC 2.
- Demonstrated success partnering closely with Engineering to build secure development practices.
- Exceptional communication skills with the ability to influence executives, engineers, customers, and auditors alike.
- Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or equivalent practical experience.
Preferred Qualifications
- Experience leading Security at a startup or high-growth technology company.
- Experience building organizations through periods of rapid scale.
- Experience with HITRUST certification.
- Experience securing AI/ML platforms and modern data infrastructure.
- Experience with Kubernetes, container security, Infrastructure as Code, and cloud-native architectures.
- CISSP, CISM, CCSP, GIAC, or comparable certifications.
What Success Looks Like
Within your first 12 months, you will:
- Build and execute a comprehensive company-wide security roadmap.
- Establish a high-performing Security organization.
- Mature Plenful's cloud, application, and corporate security capabilities.
- Strengthen compliance and customer trust programs to support enterprise growth.
- Implement scalable security practices that become embedded throughout Engineering and Product.
- Serve as a trusted executive partner helping shape the company's long-term technology strategy.
Benefits & Perks
- Healthcare Coverage — Full medical, dental, and vision insurance for you and participation for your family.
- 401(k) with Company Match — Plenful matches 50% of your first 3% contributed.
- Equity — Every full-time employee shares in our success.
- Unlimited PTO — Take the time you need, when you need it.
- Daily Lunch Stipend — $100/week to cover your midday meals.
- Wellness Stipend — $100/month to support your health and well-being.
- Commuter Benefits — $100/month for SF and NYC-based employees.
- Parental Leave — Paid leave to support growing families.
Skills
AWS, HIPAA, SOC 2, Hitrust, DevSecOps, IAM, Kubernetes, Incident Response, Threat Modeling, Vulnerability Management, Cissp, Cism
Similar jobs
Security Engineering jobsLeads LogicGate’s internal security organization, compliance posture, risk management, and customer trust program while serving as Deputy CISO. Requires 7–10 years of information security experience, substantial people leadership, SaaS compliance expertise, and strong technical knowledge of modern security architectures.
Leads GameChanger’s Information Security and Technology strategy, teams, roadmap, and risk decisions, with primary focus on product and application security. Requires 10+ years of security experience, broad security-program leadership, and experience managing technical leaders and partnering with Engineering and executives.
Leads Exa’s company-wide security strategy, architecture, engineering, governance, incident response, and team development across AI infrastructure, cloud, products, and corporate systems. Requires executive-level security accountability and deep technical credibility in a rapidly scaling technology company.
Leads Fetch’s end-to-end information security program, including application security, vulnerability management, incident response, architecture, GRC, AI risk, and third-party risk. The role requires 7+ years of security experience, incident command capability, and people leadership.
Leads Chronograph’s information security and IT strategy, combining executive leadership with hands-on oversight of cloud, application, AI, corporate, and compliance security. Requires at least seven years of security experience, broad technical depth, assurance-program leadership, and strong executive communication.