Live opening · Posted 12 days ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
We're hiring a Security Lead to own governance, risk, and compliance (GRC) while building and strengthening security architecture in a cloud-native environment. This is a hands-on individual contributor role with no direct reports, but senior ownership of security programs and architecture.
Responsibilities:
Own and operate HITRUST/SOC2 programs; ongoing management, not just audit participation.
Translate risks into structured cost vs. risk quantification for nontechnical leadership.
Build and improve cloud-native security infrastructure (AWS, GCP, Azure).
Evaluate and manage external security vendors/consultants (scoping, risk assessment, accountability).
Drive AI/LLM security initiatives, assess risks in AI products, govern internal LLM usage, and build controls for agentic AI systems.
Embed security into SDLC: IAM, secrets management, network segmentation, architecture reviews.
Represent security credibly in customer-facing forums (questionnaires, trust reviews).
Operate as a solo IC; recent hands-on security work, not pure people management.
Requirements:
7+ years in security, with 3+ years in a regulated environment (HIPAA, finance, or government).
Proficiency in Operational HITRUST or SOC2 experience (managed/maintained ongoing program).
Knowledge of Structured risk quantification with documented cost vs. risk recommendations.
Proven experience building/improving cloud-native security infrastructure.
Track record evaluating/managing external security vendors.
Direct hands-on AI/LLM security work.
Evidenced cost vs. risk judgment (documented tradeoffs, not defaults).
Comfort operating as a solo IC with recent hands-on security work.
Should Have:
SOC2 Type II operational experience.
CISSP / CISM / CCSP or equivalent certification.
Familiarity with EHR integration security (HL7 FHIR, Epic/Athena).
Agentic AI systems experience (tool calling, multistep workflows).
High-growth startup exposure (Series A-C).
Direct enterprise customer-facing security work.
Could Have:
Healthcare domain depth (RCM, clinical workflows).
Security awareness/training program design.
GCP specialisation (AWS/Azure equally acceptable).
Multitenant / multi-BAA architecture experience.
Publications, conference talks, or research contributions.
Experience
7-11 yrs
More openings worth a look
Recently tracked roles with full details and direct application links.