Summary
What you’ll impact
The Head of Security will own and lead the organization's security program, advising leadership on risk posture and building a roadmap to improve security. This hands‑on role involves running risk assessments, audits, incident response, and supporting compliance efforts such as SOC 2 and HITRUST, while eventually building a small security team.
Responsibilities
What you'll do
- Own our security program and serve as the senior-most security voice in the company, advising leadership on risk posture and tradeoffs
- Identify gaps against our target security posture and build a roadmap to close them; personally execute that roadmap rather than delegating it
- Run core security procedures: risk assessments, access and policy questions ("is this allowed"), audits, and incident response when issues arise
- Partner with our MSP and stakeholders across engineering and the business to improve our overall security posture
- Support and help run portions of our compliance program, including SOC 2 and HITRUST
- Build a small security team over time, starting hands‑on and hiring as the workload requires it
Requirements
What you’ll bring
- 8+ years in security or information security, including direct ownership of a security program at a startup or growth-stage company
- Experience running the operational mechanics of security: risk assessments, audits, access reviews, and incident response from detection through remediation
- Working knowledge of HIPAA, HITRUST, and/or SOC 2 control frameworks, enough to support and operate controls
- Experience with MSP relationships and cross-functional work with engineering to close security gaps
- Comfort operating without a team initially: hands‑on‑keyboard, building the function before hiring into it
- Strong communication skills, able to give clear, practical answers on what is and isn’t permitted, and to represent our posture to auditors and enterprise customers, in addition to advising leadership on risk and strategy