Head of Security
United StatesSecurity EngineeringRemote
Summary
Leads end-to-end security program for healthcare clearinghouse, owning policies, incident response, compliance (SOC 2, HIPAA, HITRUST), and risk advisory. Requires deep cloud security expertise, regulatory knowledge, and hands-on technical leadership in AWS environments.
About the role
What you'll do
- Own and build Stedi's security program end-to-end, including policies, controls, procedures, security tooling, training, vulnerability management, vendor risk, and more.
- Be a strong hands-on contributor from day 1 while also building a roadmap for scaling the security function as the company continues to grow.
- Advise on security risk tied to product decisions, architecture, and partnerships.
- Leverage our best-in-category security posture to unlock new customers and strategic relationships.
- Partner with Engineering to maintain security excellence while minimizing development friction.
- Lead breach preparedness and incident response: build, test, and own the Security Incident Response Plan, Disaster Recovery, and Business Continuity programs.
- Represent Stedi in conversations with customer and partner security leadership teams, and provide clear, regular reporting on security posture and risk to the executive team and board.
- Partner with Legal on regulatory obligations, breach notification requirements, and the legal dimensions of security incidents.
- Build mechanisms for continuous security improvement, and establish practical, role-appropriate security training across the company.
Who you are
- Significant experience owning security programs in cloud-native environments.
- Deep technical ability in the security domain and enough working knowledge to have high-bandwidth discussions with application engineers.
- Strong legal and regulatory instincts – you have the ability to understand legal issues and can speak credibly with regulators; healthcare or HIPAA experience is a strong plus.
- Opinionated but pragmatic, with strong judgment about where rigor matters most and a bias toward solutions over problems.
- Exceptional communicator: you can explain security risk clearly to engineers, executives, customers, and regulators, in writing and in person.
- You’re excited to use automation and modern tooling to eliminate toil and raise the bar, not to build bureaucracy.
Skills
AWSSOC 2HIPAAHITRUSTDLPIAMvulnerability managementincident responseSecurity Incident Response Planvendor risk managementcloud securitySCPs