Director of IT & Security, CISO

🕒 March 12

🇺🇸 United States – Remote

💵 $224k - $260k / year

⏰ Full Time

🔴 Lead

👮‍♂️ Cybersecurity / Security Engineer

🦅 H1B Visa Sponsor

infoinfo

👻 Ghost score 34%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Redox

Redox

201 - 500 employees

Founded 2014

🏥 Healthcare

⚕️ Healthcare Insurance

☁️ SaaS

Healthcare • Healthcare Insurance • SaaS

Redox is a company specializing in healthcare data interoperability. It provides a platform that facilitates real-time data exchange for vendors, providers, and payers in the healthcare industry. With over 7,300 connected healthcare organizations, Redox enables efficient data exchange and processing, helping to improve patient care and streamline operations. The platform supports massive data transactions, maintains high uptime, and is certified for security standards like HITRUST. Redox is renowned for integrating EHR systems, improving AI and machine learning outcomes, and enhancing patient and member experiences. Its solutions are trusted by key players in the healthcare sector to manage and consolidate healthcare data effectively.

📋 Description

• Own end-to-end information security strategy across cloud, application, infrastructure, and corporate environments. • Define a security roadmap aligned to business risk, regulatory requirements, and engineering velocity. • Serve as executive owner for security posture, risk management, and incident response; advise the CTO and executive team. • Drive a DevSecOps-first operating model across CI/CD pipelines, infrastructure as code, and developer workflows. • Lead threat modeling, secure design reviews, risk assessments, policy-as-code, guardrails, and automation. • Own security architecture and operations for a primarily AWS-based environment. • Lead application security programs including secure SDLC, dependency scanning, SAST/DAST, penetration testing, and vulnerability management. • Own identity and access management strategy with Okta. • Build and run security operations covering monitoring, investigation, incident response, and post-incident learning. • Run tabletop exercises and improve response playbooks. • Manage vendor relationships including CrowdStrike, Flashpoint, RAD, and Okta. • Own corporate IT strategy and execution, including end-user computing, device management, endpoint security, identity lifecycle management, access controls, email, collaboration tools, endpoint management, and SaaS access governance. • Drive automation and standardization across onboarding, offboarding, access management, and device lifecycle. • Partner with People Ops, Legal, and Finance on IT processes, audits, and vendor management. • Own healthcare-related security and compliance programs such as HIPAA and SOC 2. • Lead third-party risk management and vendor security reviews. • Support customer security reviews and serve as an executive security contact. • Build, lead, and mentor a team spanning security engineering, security operations, and IT. • Establish clear ownership, measurable outcomes, and high operational standards.

🎯 Requirements

• 10+ years in information security, IT, or related technical leadership roles, including 5+ years of people management, ideally in healthcare technology SaaS. • Proven experience leading security engineering, security operations, and corporate IT in a cloud-native SaaS environment. • Direct experience in healthcare or other highly regulated industries. • Track record of successfully implementing DevSecOps practices. • Deep hands-on experience securing AWS environments. • Strong understanding of endpoint security, identity systems, and modern SaaS IT stacks. • Practical knowledge of tools such as CrowdStrike, Okta, Flashpoint, RAD, and related platforms. • Strong foundation in application security, cloud security, and infrastructure as code. • Proven proficiency in AI tools and techniques, including prompt engineering and hands-on experience across multiple large language model platforms, with a demonstrated ability to drive AI adoption enterprise-wide. • Strong collaborator with engineering, platform, and operations teams. • Clear, direct communicator who can articulate risk without theatrics. • Comfortable making tradeoffs and prioritizing based on real-world risk. • Builder mindset with a bias toward automation and scale. • Preferred: Proven experience securing autonomous agentic loops and tool-calling frameworks; understanding of Indirect Prompt Injection and Human-in-the-Loop guardrails. • Preferred: Expertise securing the Model Context Protocol (MCP), including context isolation, sandboxing, and identity propagation. • Preferred: Experience migrating security programs to Vanta or similar automated GRC platforms and architecting continuous compliance. • Preferred: Hands-on application of NIST AI RMF and OWASP Top 10 for LLMs in production. • Required software: CrowdStrike, AWS, Okta. • Successful candidates must be eligible to be employed in the U.S. and must reside & work in the continental U.S.

🏖️ Benefits

• 100% remote first culture (must be based in the US) • Unlimited Flexible Time Off • 15+ Observed Holidays • Rest & R^Charge days (guaranteed a 3-day weekend each month) • R^Charge (6 weeks paid sabbatical + stipend) • 401k match 50% for up to 8% on Day 1 • Medical/Dental/Vision Benefits on Day 1 • HSA & FSA, Life, Disability, Medical Travel & Employee Assistance Program • Paid Parental Leave (16 weeks) • Productivity Stipend & Wellness Fund • Redox Issued MacBook • Virtual and/or in-person Team & Company Events • Stock Options • Employee Referral Bonus Program

Apply Now

Similar Jobs

🕒 March 6

Conduent

10,000+ employees

🏥 Healthcare

📦 Logistics

💼 Consulting

IT Security Architect at Conduent defining security architecture across on-site, hybrid, and cloud environments. Establishing standards and guiding modernization initiatives for enterprise technology platforms.

🕒 March 4

Gainwell Technologies

10,000+ employees

💼 Consulting

📦 Logistics

⚕️ Healthcare Insurance

Lead Security Officer at Gainwell driving security governance and compliance for technology. Manage operational activities ensuring delivery excellence and relationship management with suppliers and clients.

🕒 February 26

Doctronic

51 - 200

🏥 Healthcare

💼 Consulting

📦 Logistics

Information Security Engineer maintaining security posture for AI healthcare platform. Responsible for ensuring compliance and implementing security measures as the company scales.

🇺🇸 United States – Remote

💵 $180k - $240k / year

🔥 Funding within the last year

💰 $20M Series A on 2025-10

⏰ Full Time

🟠 Senior

🔴 Lead

👮‍♂️ Cybersecurity / Security Engineer

🕒 February 20

Akamai Technologies

5001 - 10000

🔒 Cybersecurity

🏢 Enterprise

📱 Media

Manager of Information Security leading and scaling high-performing Infosec DevOps and tooling team. Safeguarding operational platform of Akamai's key products and infrastructure with technical leadership and program management.

🕒 February 2

Affirm

1001 - 5000

💳 Fintech

👥 B2C

🛍️ eCommerce

Director of Information Security leading Affirm's cybersecurity and information security programs in a remote capacity. Responsible for developing security frameworks and overseeing risk management in a regulated environment.