Skip to content
NexHealthNexHealthSan Francisco, CA

Head of IT & Security

Leads NexHealth’s security governance, compliance, IT operations, vendor security, privacy, and incident response programs while building the security function and team. Requires 8+ years of security experience, leadership building programs from the ground up, audit ownership, and a software engineering background.

160k – 200k/yr
On-site8+ YOESecurity Engineering

About the role

Responsibilities

  • Own NexHealth's security governance, compliance, and IT programs end-to-end.
  • Serve as the named Information Security Officer and Privacy Officer for SOC 2 and HIPAA.
  • Own the policy manual, audit liaison relationship, control mapping, and evidence collection pipelines.
  • Set security standards across application security, vulnerability management, cloud security, audit logging, and access controls.
  • Build, hire, and develop the IT and workforce security program, including endpoints, identity, SaaS administration, phishing simulations, role-specific training, and facilities security.
  • Own vendor security, including intake, classification, assessment, BAA execution, ongoing oversight, Trust Center materials, and subprocessor disclosures.
  • Lead incident response, partner with outside counsel on breach determinations, track incidents, and run annual tabletop exercises.
  • Own the risk register, risk acceptance decisions, privacy operations, business continuity and disaster recovery planning, and cyber insurance relationships.
  • Hire a Staff-level IT individual contributor within the first year and grow the function.

Requirements

  • 8+ years of relevant security experience.
  • 3+ years in a security leadership role building a program.
  • Experience building a security program from a near-zero baseline.
  • Experience owning a recurring external audit cycle end-to-end, such as SOC 2, ISO, PCI, or HITRUST.
  • Software engineering background, including the ability to read pull requests and evaluate cloud configurations.
  • Experience hiring and developing senior security or IT individual contributors.
  • Hands-on experience with SIEM, MDR, IDS/IPS, WAF, DLP, and vulnerability scanners.
  • Experience improving engagement with auditors, regulators, or customer security teams.
  • Ability to drive operational change across functions without direct authority.
  • Ability to communicate risk to board-level and engineering audiences.
  • Strong first-principles thinking and writing skills.

Compensation and Benefits

  • Base salary range: $160,000–$200,000 USD.
  • Stock options may be included in the total compensation package.
  • Medical, dental, and vision insurance, with up to 100% coverage.
  • 401(k) and commuter benefits.
  • Flexible, unlimited paid time off.

Skills

SOC 2HIPAAAWSApplication SecurityVulnerability ManagementCloud SecuritySIEMmdrids/ipswafdlpIncident Responseprivacy operationsbusiness continuitydisaster recovery
Virta Health

Director, Security Engineering

Virta HealthUnited States

Leads enterprise security engineering and SecOps, directing a security team, outsourced MDR/SOC operations, incident response, and a Zero Trust transformation. Requires 10+ years in cybersecurity or cloud infrastructure security, leadership experience, and deep GCP, micro-segmentation, workload identity, and CI/CD expertise.

162k – 209k/yrRemote10+ YOESecurity Engineering
Fetch

Director, Trust & Safety Detection and Intelligence

FetchUnited States

Leads Fetch’s fraud detection and threat intelligence function, overseeing investigations, detection systems, risk prioritization, and anti-abuse strategy. Requires 10+ years in fraud, trust and safety, cybersecurity, or related risk work, plus 5+ years managing senior teams.

176k – 207k/yrRemote10+ YOESecurity Engineering
Casca

Head of Security & Compliance

CascaSan Francisco, CA

Lead security and compliance for an AI-native banking startup. Build security tooling, manage a team of appsec engineers, own compliance (SOC 2, ISO 27001), and secure AI agent workflows.

200k – 255k/yrOn-site5+ YOESecurity Engineering
Tatari

Head of Security

TatariNew York, NY +2

Lead security engineering team and roadmap for a late-stage AdTech SaaS company. Own incident response, risk management, AWS/K8s security, and compliance programs including SOC 2.

200k – 250k/yrHybrid7+ YOESecurity Engineering
Komodo Health

Director, Corporate Security

Komodo HealthUnited States

Director of Corporate Security responsible for building and maturing the company's internal security program, including identity/access management, endpoint protection, SaaS security, AI governance, incident response, and compliance. Requires 7+ years director-level experience, team leadership, and cross-functional partnership in regulated or healthcare environments.

206k – 290k/yrOn-site7+ YOESecurity Engineering