About the roleWe're hiring Pivotal's Head of Security, a senior leader who will own the company's security program from the ground up. This is a rare opportunity to define what security looks like at a fast-growing, AI-native healthcare technology company handling sensitive provider data and complex financial workflows.
This role sits at the intersection of strategy, engineering, compliance, and customer trust. You'll work closely with key stakeholders across the organization to embed security across the organization. Not just as a technical function, but as a core part of how Pivotal builds, operates, and earns the confidence of the providers and partners it serves.
You'll bring enough technical depth to engage credibly with our engineering teams, and enough breadth to set organizational strategy, navigate the regulatory landscape, and represent Pivotal's security posture to customers, auditors, and key stakeholders. If you're energized by building something meaningful from scratch and want your work to matter beyond a checklist, this is the role for you.
What you'll do- Build and own Pivotal's security program
Establish the strategy, policies, processes, and roadmap that define Pivotal's security posture. Identify the company's most critical assets, prioritize risk accordingly, and build a program that scales alongside a fast-growing platform and team.
- Partner with engineering to embed security into the platform
Work closely with engineering and infrastructure teams to ensure security is built into how we design, develop, and deploy - from cloud architecture and CI/CD pipelines to data access controls and third-party integrations. You'll advocate for secure-by-design practices without slowing the team down.
- Lead compliance and regulatory readiness
Own Pivotal's approach to relevant compliance frameworks, including SOC 2 and HIPAA. Translate regulatory requirements into actionable engineering and operational controls, lead audit preparation, and serve as the primary point of contact during security reviews.
- Stay ahead of the threat landscape
Keep a close eye on the evolving security environment - emerging threats, new attack vectors, regulatory changes, and industry best practices. Bring that awareness into how Pivotal prioritizes and evolves its defenses over time.
- Interface with customers and external stakeholders
Represent Pivotal's security program directly to customers, partners, and prospects. Answer security questionnaires, lead trust reviews, and give customers confidence that their data - and their providers' data - is in safe hands.
- Drive security awareness across the organization
Champion a security-conscious culture companywide. Work with teams outside of engineering - including finance, operations, and people - to ensure security practices extend beyond the codebase and into how the whole organization operates.
- Develop guidelines for emerging technologies
As an AI-native company, Pivotal is actively building with and around LLMs and AI tooling. Help define the guardrails for responsible, secure use of these technologies - both in our product and in our internal workflows.
Who you are- 8+ years of experience in security, with meaningful exposure to both technical implementation and program-level strategy
- Strong working knowledge of cloud security, infrastructure security, and application security fundamentals, enough to engage credibly with engineering teams and evaluate tradeoffs
- Experience building or significantly maturing a security program, ideally at an early-stage or high-growth company
- Hands-on experience with compliance frameworks (SOC 2, HIPAA, or similar) including control design, audit preparation, and ongoing management
- Comfortable representing security externally to customers, auditors, and partners with the communication skills to make complex topics accessible
- A collaborator and influencer, not just a gatekeeper: you know how to bring stakeholders along and build trust across functions
- Comfortable operating in ambiguity and building from scratch: you're energized by greenfield work, not slowed down by it
- Up to date on the current threat landscape, security tooling, and best practices: you stay informed and bring that knowledge into your work
Extra credit if you have- Experience in HealthTech, FinTech, or other regulated industries handling sensitive data
- Background working with financial systems, payments infrastructure, or data-intensive platforms
- Familiarity with AI/LLM security considerations and responsible AI deployment practices
- Experience managing or growing a security team
Benefits Include:- Competitive compensation, including equity
- Full health, dental, and vision coverage
- Retirement savings plan through 401(k)
- Flexible time off
- Opportunities for company-wide connection and events
Ready to Make an Impact?We're building something meaningful; and we want you on the team.
Bring your ideas, curiosity, and drive, and let's transform healthcare reimbursement together.
Employment InformationWork AuthorizationCandidates must be authorized to work in the United States without current or future employer sponsorship.