Leads NexHealth’s security governance, compliance, IT operations, vendor security, privacy, and incident response programs while building the security function and team. Requires 8+ years of security experience, leadership building programs from the ground up, audit ownership, and a software engineering background.
160k – 200k/yr
On-site8+ YOESecurity Engineering
About the role
Responsibilities
Own NexHealth's security governance, compliance, and IT programs end-to-end.
Serve as the named Information Security Officer and Privacy Officer for SOC 2 and HIPAA.
Own the policy manual, audit liaison relationship, control mapping, and evidence collection pipelines.
Set security standards across application security, vulnerability management, cloud security, audit logging, and access controls.
Build, hire, and develop the IT and workforce security program, including endpoints, identity, SaaS administration, phishing simulations, role-specific training, and facilities security.
Own vendor security, including intake, classification, assessment, BAA execution, ongoing oversight, Trust Center materials, and subprocessor disclosures.
Lead incident response, partner with outside counsel on breach determinations, track incidents, and run annual tabletop exercises.
Own the risk register, risk acceptance decisions, privacy operations, business continuity and disaster recovery planning, and cyber insurance relationships.
Hire a Staff-level IT individual contributor within the first year and grow the function.
Requirements
8+ years of relevant security experience.
3+ years in a security leadership role building a program.
Experience building a security program from a near-zero baseline.
Experience owning a recurring external audit cycle end-to-end, such as SOC 2, ISO, PCI, or HITRUST.
Software engineering background, including the ability to read pull requests and evaluate cloud configurations.
Experience hiring and developing senior security or IT individual contributors.
Hands-on experience with SIEM, MDR, IDS/IPS, WAF, DLP, and vulnerability scanners.
Experience improving engagement with auditors, regulators, or customer security teams.
Ability to drive operational change across functions without direct authority.
Ability to communicate risk to board-level and engineering audiences.
Strong first-principles thinking and writing skills.
Compensation and Benefits
Base salary range: $160,000–$200,000 USD.
Stock options may be included in the total compensation package.
Medical, dental, and vision insurance, with up to 100% coverage.
Leads enterprise security engineering and SecOps, directing a security team, outsourced MDR/SOC operations, incident response, and a Zero Trust transformation. Requires 10+ years in cybersecurity or cloud infrastructure security, leadership experience, and deep GCP, micro-segmentation, workload identity, and CI/CD expertise.
162k – 209k/yrRemote10+ YOESecurity Engineering
Director, Trust & Safety Detection and Intelligence
FetchUnited States
Leads Fetch’s fraud detection and threat intelligence function, overseeing investigations, detection systems, risk prioritization, and anti-abuse strategy. Requires 10+ years in fraud, trust and safety, cybersecurity, or related risk work, plus 5+ years managing senior teams.
176k – 207k/yrRemote10+ YOESecurity Engineering
Head of Security & Compliance
CascaSan Francisco, CA
Lead security and compliance for an AI-native banking startup. Build security tooling, manage a team of appsec engineers, own compliance (SOC 2, ISO 27001), and secure AI agent workflows.
200k – 255k/yrOn-site5+ YOESecurity Engineering
Head of Security
TatariNew York, NY +2
Lead security engineering team and roadmap for a late-stage AdTech SaaS company. Own incident response, risk management, AWS/K8s security, and compliance programs including SOC 2.
200k – 250k/yrHybrid7+ YOESecurity Engineering
Director, Corporate Security
Komodo HealthUnited States
Director of Corporate Security responsible for building and maturing the company's internal security program, including identity/access management, endpoint protection, SaaS security, AI governance, incident response, and compliance. Requires 7+ years director-level experience, team leadership, and cross-functional partnership in regulated or healthcare environments.