Director of IT & Security, CISO

4 months ago
Full-time
Executive
DevOps and Infrastructure
Redox

Redox

Redox is a top integration platform enabling seamless interoperability between healthcare software and EHRs, accelerating implementations, reducing costs, and empowering healthcare innovators to bring cutting-edge solutions to market efficiently.

Internet Software & Services
51-250
$95M raised

Description

  • Own the end-to-end security strategy across cloud, application, infrastructure, and corporate environments.
  • Define and execute a pragmatic security roadmap aligned to business risk, regulatory requirements, and engineering velocity.
  • Serve as executive owner for security posture, risk management, and incident response.
  • Drive a DevSecOps-first operating model by embedding security into CI/CD pipelines, infrastructure as code, and developer workflows.
  • Lead threat modeling, secure design reviews, and risk assessments for new platform initiatives.
  • Own security architecture and operations for a primarily AWS-based environment.
  • Lead application security programs including secure SDLC, dependency scanning, SAST/DAST, penetration testing, and vulnerability management.
  • Own identity and access management strategy, with Okta as the backbone.
  • Build and run security operations, including monitoring, investigation, incident response, and post-incident learning.
  • Own corporate IT strategy and execution, including end-user computing, device management, and SaaS access governance.
  • Drive automation and standardization across onboarding, offboarding, access management, and device lifecycle.
  • Lead and mentor a high-performing team across security engineering, security operations, and IT.

Requirements

  • 10+ years of experience in information security, IT, or related technical leadership roles.
  • 5+ years of people management experience, ideally in healthcare technology SaaS.
  • Experience leading security engineering, security operations, and corporate IT in a cloud-native SaaS environment.
  • Direct experience in healthcare or another highly regulated industry.
  • Proven track record implementing DevSecOps practices.
  • Deep hands-on experience securing AWS environments.
  • Strong understanding of endpoint security, identity systems, and modern SaaS IT stacks.
  • Practical knowledge of tools such as CrowdStrike, Okta, Flashpoint, RAD, and related platforms.
  • Strong foundation in application security, cloud security, and infrastructure as code.
  • Ability to work in the U.S. and reside/work in the continental U.S.
  • Preferred experience securing autonomous agentic loops and tool-calling frameworks.
  • Preferred experience with indirect prompt injection, human-in-the-loop guardrails, MCP security, and continuous compliance.
  • Preferred experience migrating security programs to Vanta or similar automated GRC platforms.
  • Preferred hands-on application of the NIST AI RMF and OWASP Top 10 for LLMs in production environments.

Benefits

  • Base salary range of $224,000 to $260,000 per year.
  • Stock options as part of the total rewards package.
  • 100% remote-first culture for U.S.-based employees.
  • Unlimited flexible time off.
  • 15+ observed holidays.
  • Rest & R^Charge days with a guaranteed three-day weekend each month.
  • R^Charge sabbatical: 6 weeks paid sabbatical plus stipend.
  • 401(k) match of 50% up to 8% starting on Day 1.
  • Medical, dental, and vision coverage starting on Day 1.
  • HSA, FSA, life, disability, medical travel, and employee assistance program benefits.
  • Paid parental leave of 16 weeks.
  • Productivity stipend and wellness fund.
  • Redox-issued MacBook.
  • Virtual and/or in-person team and company events.
  • Employee referral bonus program.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

DevOps Engineer - SRE Observability

Lingaro 5K-10K IT Services

An infrastructure-focused role at Lingaro responsible for monitoring, automating, and designing cloud systems within an Azure-based environment.

Azure Azure Pipelines CI/CD Docker GitHub GitHub Actions Grafana Kubernetes MySQL PostgreSQL Prometheus SQL Terraform
20 hours, 26 minutes ago

Customer Support Engineer - Endpoint/MTD (Device) & Cybersecurity

Zimperium 251-1K Professional Services

Zimperium is hiring a Customer Support Engineer to provide technical support for its mobile security platform, helping enterprise customers troubleshoot issues and resolve product problems in coordination with internal teams.

Android Android Studio AWS Cybersecurity Docker iOS Java JIRA JUnit Kafka Linux Machine Learning PostgreSQL Python SIEM Splunk SQL Unix Xcode
20 hours, 41 minutes ago

Director , Information Security and IT

Luna Physical Therapy 251-1K Health Care Providers & Services

Luna is hiring a Director of Information Security & IT to lead enterprise technology and security programs supporting secure operations and patient care in a HIPAA-regulated environment.

AWS Azure GCP HIPAA Penetration Testing
20 hours, 41 minutes ago

Senior MS Intune & Cloud Security Specialist (Freelance)

Coderio 51-250 Internet Software & Services

Coderio is seeking a Senior Cloud Security Architect / MS Intune Specialist to lead a greenfield Microsoft Intune, Entra ID, and Defender for Endpoint implementation for a multi-cloud environment spanning Google Workspace, AWS, and DevOps pipelines.

Active Directory Android AWS Bash GitHub GitLab iOS macOS PowerShell
20 hours, 41 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers