# Head of IT & Security

**Company:** [NexHealth](https://hotfix.jobs/companies/nexhealth)
**Location:** San Francisco, CA
**Role:** Security Engineering
**Salary:** $160k – $200k/yr
**Experience:** 8+ years
**Skills:** SOC 2, HIPAA, AWS, Application Security, Vulnerability Management, Cloud Security, SIEM, mdr, ids/ips, waf, dlp, Incident Response, privacy operations, business continuity, disaster recovery
**Posted:** 2026-08-07

> Leads NexHealth’s security governance, compliance, IT operations, vendor security, privacy, and incident response programs while building the security function and team. Requires 8+ years of security experience, leadership building programs from the ground up, audit ownership, and a software engineering background.

## Job Description

## Responsibilities
- Own NexHealth's security governance, compliance, and IT programs end-to-end.
- Serve as the named Information Security Officer and Privacy Officer for SOC 2 and HIPAA.
- Own the policy manual, audit liaison relationship, control mapping, and evidence collection pipelines.
- Set security standards across application security, vulnerability management, cloud security, audit logging, and access controls.
- Build, hire, and develop the IT and workforce security program, including endpoints, identity, SaaS administration, phishing simulations, role-specific training, and facilities security.
- Own vendor security, including intake, classification, assessment, BAA execution, ongoing oversight, Trust Center materials, and subprocessor disclosures.
- Lead incident response, partner with outside counsel on breach determinations, track incidents, and run annual tabletop exercises.
- Own the risk register, risk acceptance decisions, privacy operations, business continuity and disaster recovery planning, and cyber insurance relationships.
- Hire a Staff-level IT individual contributor within the first year and grow the function.

## Requirements
- 8+ years of relevant security experience.
- 3+ years in a security leadership role building a program.
- Experience building a security program from a near-zero baseline.
- Experience owning a recurring external audit cycle end-to-end, such as SOC 2, ISO, PCI, or HITRUST.
- Software engineering background, including the ability to read pull requests and evaluate cloud configurations.
- Experience hiring and developing senior security or IT individual contributors.
- Hands-on experience with SIEM, MDR, IDS/IPS, WAF, DLP, and vulnerability scanners.
- Experience improving engagement with auditors, regulators, or customer security teams.
- Ability to drive operational change across functions without direct authority.
- Ability to communicate risk to board-level and engineering audiences.
- Strong first-principles thinking and writing skills.

## Compensation and Benefits
- Base salary range: **$160,000–$200,000 USD**.
- Stock options may be included in the total compensation package.
- Medical, dental, and vision insurance, with up to 100% coverage.
- 401(k) and commuter benefits.
- Flexible, unlimited paid time off.

## Similar roles

- [Director, Security Engineering](https://hotfix.jobs/jobs/121737e7-8a7c-4c2e-a7ba-806e477a9491) - Virta Health - Remote - $162k – $209k/yr
- [Director, Trust & Safety Detection and Intelligence](https://hotfix.jobs/jobs/1f7e0b07-06b8-4f92-9bb2-cd2b6d396d03) - Fetch - Remote - $176k – $207k/yr
- [Head of Security & Compliance](https://hotfix.jobs/jobs/0c31140a-05ba-40ab-a5aa-12713d69cde4) - Casca - San Francisco, CA - $200k – $255k/yr
- [Head of Security](https://hotfix.jobs/jobs/f857e28d-567e-4a7a-8dfd-56496a7b4fa9) - Tatari - New York, NY - $200k – $250k/yr
- [Director, Corporate Security](https://hotfix.jobs/jobs/7837c97d-5d29-4ed2-ba76-f6b2161f84cd) - Komodo Health - $206k – $290k/yr

**Apply:** https://hotfix.jobs/jobs/9d80b823-e1b2-4da6-8807-713816b09be9
**Canonical:** https://hotfix.jobs/jobs/9d80b823-e1b2-4da6-8807-713816b09be9