HamburgerMenu
hirist

Job Description

About the Role :

We are looking for an experienced Security Lead to drive and strengthen our security posture across cloud infrastructure, AI systems, compliance, and enterprise security initiatives.

This is a hands-on IC role for someone who enjoys solving complex security challenges and building scalable security practices for modern cloud-native applications in regulated environments.

Join us in building secure, scalable, and AI-powered solutions that transform healthcare. Lead enterprise security initiatives, strengthen compliance, and build trust in everything we deliver.

Key Responsibilities :

- Lead security initiatives across cloud infrastructure, applications, and AI platforms.

- Own and maintain compliance programs such as HITRUST and SOC 2 Type II.

- Conduct security risk assessments and communicate cost-versus-risk recommendations.

- Design, implement, and improve security controls for cloud-native environments.

- Build and enhance security infrastructure across AWS, Azure, and GCP.

- Assess security risks of AI/LLM applications and govern internal AI tool usage.

- Collaborate with engineering teams to integrate security throughout the SDLC.

- Evaluate and manage third-party security vendors, consultants, and assessments.

- Support enterprise customers through security questionnaires, audits, trust reviews, and compliance discussions.

- Stay current with emerging threats, security best practices, and evolving AI security standards.

- Partner with leadership, compliance, and business teams to drive a strong security culture and informed business decisions.

Must-Have Qualifications:

1. Experience:

- 7+ years in Information Security/Cybersecurity.

- At least 3 years in a regulated environment (Healthcare, Financial Services, or Government).

- Recent hands-on security engineering experience in an IC role.

2. Compliance & Governance:

- Operational experience managing HITRUST or SOC 2 programs.

- Experience maintaining ongoing compliance.

- Strong understanding of governance, risk, and security controls.

3. Cloud Security:

- Experience designing or improving security infrastructure in AWS, Azure, or GCP.

- Strong understanding of cloud-native security architecture.

4. Risk Management:

- Experience performing structured security risk assessments.

- Ability to present business-focused cost-versus-risk recommendations.

- Make pragmatic security decisions aligned with business priorities.

5. AI Security:

- Hands-on experience securing AI/LLM systems.

- Assess risks of AI products and govern internal AI usage.

- Knowledge of security controls for modern AI applications.

6. Vendor Management:

- Experience evaluating and managing third-party security vendors, consultants, and security assessments.

Preferred Qualifications:

- Operational experience with SOC 2 Type II.

- Certifications such as CISSP, CISM, or CCSP.

- Healthcare integrations (FHIR, HL7, Epic/Athena ecosystems).

- Experience with Agentic AI systems, multi-agent workflows, and AI security assessments.

- Experience working in high-growth startups (Series A - C).

- Experience supporting enterprise customers during security reviews and trust assessments.

Nice-to-Have:

- Healthcare security experience beyond compliance.

- Experience designing security awareness programs.

- Hands-on expertise with GCP.

- Experience designing security for multi-tenant SaaS platforms.

- Research publications, conference talks, patents, or open-source contributions.

Technical Skills:

- Cloud Security (AWS, Azure, GCP)

- Security Architecture

- HITRUST

- SOC 2 Type II

- Risk Assessment & Governance

- AI / LLM Security

- Identity & Access Management (IAM)

- Vulnerability Management

- Security Compliance

- Vendor Risk Management

- Security Operations

- Threat Modeling

Ideal Candidate Profile:

We are looking for someone who can demonstrate:

- Building and improving cloud security infrastructure.

- Operating security programs in regulated environments.

- Securing AI & LLM-based applications.

- Making informed, business-focused security decisions.

- Taking ownership and delivering independently in a hands-on IC role.

- Collaborating effectively with engineering, product, compliance, and leadership teams

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...