Job Title: Head of SecurityWe're hiring a Head of Security to own our security program. This is a high-ownership, hands-on role: you'll be responsible for identifying the highest leverage ways to improve the company's security posture and then build and personally execute that roadmap. You'll run the operational core of security, including risk assessments, audits, incident response, and policy questions, while working both with our MSP and across the org to identify and execute. You'll also be responsible for supporting portions of our compliance efforts, including SOC 2 and HITRUST, as we continue building out compliance more broadly.
What You'll Achieve: A Glimpse into Your Contributions- Own our security program and serve as the senior-most security voice in the company, advising leadership on risk posture and tradeoffs
- Identify gaps against our target security posture and build a roadmap to close them; personally execute that roadmap rather than delegating it
- Run core security procedures: risk assessments, access and policy questions ("is this allowed"), audits, and incident response when issues arise
- Partner with our MSP and stakeholders across engineering and the business to improve our overall security posture
- Support and help run portions of our compliance program, including SOC 2 and HITRUST
- Build a small security team over time, starting hands-on and hiring as the workload requires it
What You'll Bring: The Skills and Experience You'll LeverageWe believe that diverse experiences and backgrounds lead to better solutions. While we have an idea of what will help someone succeed in this role, we are open to being convinced by your unique story and skills. If you believe you can achieve the outcomes above, we encourage you to apply.
Core Skills & Experience:- 8+ years in security or information security, including direct ownership of a security program at a startup or growth-stage company
- Experience running the operational mechanics of security: risk assessments, audits, access reviews, and incident response from detection through remediation
- Working knowledge of HIPAA, HITRUST, and/or SOC 2 control frameworks, enough to support and operate controls
- Experience with MSP relationships and cross-functional work with engineering to close security gaps
- Comfort operating without a team initially: hands-on-keyboard, building the function before hiring into it
- Strong communication skills, able to give clear, practical answers on what is and isn't permitted, and to represent our posture to auditors and enterprise customers, in addition to advising leadership on risk and strategy
Benefits:- Competitive compensation.
- Opportunities for rapid career advancement in a growing company.
- 100% premium coverage for health insurance.
- 401(k) with no matching at this time.
This is a hybrid role based in our New York office and will require you to be in the office 4x in a week.