Live opening · Posted 11 days ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
Description
Since 2000, Smartlinx has been redefining how senior care organizations manage their workforce. Our modern, purpose-built solutions from dynamic scheduling and compliance to integrated payroll and real-time analytics give providers the agility and intelligence needed to thrive in today's healthcare environment.
As the parent company of BekTek (HostedTime) and StafferLink, Smartlinx brings together a wide range of solutions for managing both full-time and contingent staff. Together, these capabilities give Smartlinx the most comprehensive workforce management solution set in senior care.
We are driven by one mission: to power exceptional senior care through smarter workforce management. Join us as we shape the future of work in long-term care.
About The Role
Reporting to the Head of IT, the Lead, Cybersecurity is responsible for defining and operating Smartlinx's cybersecurity program across its multi-tenant SaaS products, cloud infrastructure, corporate technology environment, data platforms, integrations, and third-party services.
This leader owns SaaS product and application security, cloud and infrastructure security, identity and access management, vulnerability management, security monitoring, incident response, third-party risk, and SOC 2 Type II readiness and audit execution. The role is accountable for protecting sensitive healthcare workforce, payroll, personally identifiable information, and customer data while enabling reliable and timely product delivery.
The Lead, Cybersecurity will partner closely with Product, Engineering, Architecture, Quality Assurance, DevOps, Data Engineering, Corporate IT, Compliance, Legal, Customer Support, and Customer Success to integrate security into design, development, deployment, operations, and customer commitments.
Success in this role requires a hands-on, pragmatic security leader who can translate business and regulatory requirements into effective technical controls, personally investigate risk and incidents, drive remediation to closure, and communicate clearly with executives, auditors, customers, and technical teams.
Key Responsibilities
SaaS Product and Application Security
Own the product-security strategy and operating model across the Smartlinx, BekTek (HostedTime), and StafferLink product portfolio.
Embed security throughout the product development lifecycle, including requirements, architecture, design, development, testing, release, and production operation.
Lead threat modeling, security architecture reviews, abuse-case analysis, and risk assessments for new products, features, APIs, integrations, mobile applications, and material platform changes.
Establish secure coding standards and engineering guidance based on OWASP, CWE, API security, and relevant industry practices.
Integrate automated security testing into CI/CD pipelines, including static application security testing, dynamic application security testing, software composition analysis, secrets scanning, infrastructure-as-code scanning, container scanning, and software bill of materials generation.
Review and strengthen authentication, authorization, role-based access control, session management, tenant isolation, API security, file handling, encryption, audit logging, and secure data-export capabilities.
Plan and coordinate independent application and API penetration testing, validate findings, assign risk-based remediation deadlines, and confirm closure through retesting.
Assess AI-enabled product capabilities and third-party AI services for prompt injection, data leakage, tenant isolation, model access, sensitive-data handling, human oversight, and other emerging risks.
Define proportionate release-security gates and exception processes that protect customers without creating unnecessary friction for engineering delivery.
Cloud and Infrastructure Security
Lead security architecture and control implementation for Smartlinx's Microsoft Azure cloud environments, production and non-production infrastructure, corporate systems, endpoints, networks, and remote-work capabilities.
Establish secure cloud baselines using recognized frameworks and vendor guidance; continuously identify and remediate configuration drift, exposed services, excessive permissions, unsupported software, and insecure defaults.
Strengthen network security through segmentation, private connectivity, firewall and security-group governance, DDoS protection, secure administrative access, and controlled ingress and egress.
Implement and govern secrets management, certificate management, encryption, key rotation, secure service identities, and protection of privileged credentials across applications and infrastructure.
Partner with DevOps and Corporate IT to maintain effective patching, endpoint protection, malware defense, vulnerability scanning, cloud security posture management, and secure configuration management.
Review the security of databases, data lakes, warehouses, analytics platforms, ETL and ELT pipelines, customer data exchanges, backups, and disaster-recovery environments.
Ensure logging, telemetry, alerting, and forensic data are available across cloud resources, applications, identities, endpoints, networks, and data platforms to support timely detection and investigation.
Assess resilience to destructive cyber events, including ransomware and credential compromise, and validate recoverability through protected backups, restoration tests, and cyber-recovery exercises.
SOC 2, Healthcare Compliance, and Audit Readiness
Lead Smartlinx's SOC 2 Type II readiness, control design, evidence collection, auditor coordination, remediation, management responses, and annual attestation cycle.
Build a continuous-control-monitoring program that keeps the organization audit-ready throughout the year rather than relying on a point-in-time preparation effort.
Define, document, test, and improve controls across access management, change management, secure software development, vulnerability management, incident response, vendor risk, data protection, and business continuity.
Maintain the control matrix, security policies, standards, procedures, risk register, evidence repository, exception records, remediation plans, and executive compliance reporting.
Apply healthcare security and privacy requirements, including HIPAA and HITECH, to product, infrastructure, operational, vendor, and data-handling decisions; support business associate and customer contractual obligations.
Evaluate alignment with NIST, CIS Controls, ISO 27001, and HITRUST expectations where they strengthen the security program or support customer and market requirements.
Coordinate effectively with external auditors, penetration-testing providers, legal counsel, cyber-insurance partners, customers, and other independent assessors.
Lead or support responses to customer security questionnaires, due-diligence reviews, contractual security requirements, and customer audit requests with accurate, consistent, and timely information.
Vulnerability, Risk, and Third-Party Security
Establish a unified vulnerability-management program covering SaaS applications, APIs, cloud infrastructure, endpoints, containers, databases, open-source components, and third-party software.
Prioritize remediation using severity, exploitability, exposure, asset criticality, data sensitivity, customer impact, compensating controls, and active-threat intelligence rather than relying on CVSS scores alone.
Define measurable remediation service-level targets for critical, high, medium, and low-risk findings; monitor aging, exceptions, recurrence, and closure quality.
Own formal security-risk acceptance, exception, escalation, and expiration processes, ensuring material risks receive appropriate executive visibility and approval.
Conduct periodic enterprise, product, cloud, and data-security risk assessments and translate findings into prioritized, funded remediation roadmaps.
Evaluate vendors, subprocessors, managed services, technology partners, and AI providers for security, privacy, resilience, data handling, incident notification, and contractual risk before onboarding and throughout the relationship.
Monitor changes in the threat landscape, exploited vulnerabilities, attack techniques, and healthcare-sector risks; convert relevant intelligence into actionable protections and tests.
Security Operations, Incident Response, and Resilience
Define and operate security monitoring across applications, cloud infrastructure, identities, endpoints, networks, databases, and data platforms using SIEM, EDR, WAF, and related capabilities.
Develop high-value detection use cases for account compromise, privilege escalation, anomalous access, data exfiltration, malicious application activity, insecure configuration changes, and other material threats.
Own the cybersecurity incident-response plan, severity model, escalation paths, on-call expectations, investigation procedures, communications protocols, evidence handling, and post-incident review process.
Lead or coordinate containment, eradication, recovery, forensic analysis, customer-impact assessment, regulatory and contractual notification support, and executive communication during security incidents.
Conduct regular tabletop exercises involving executive leadership, Engineering, DevOps, IT, Legal, Compliance, Customer Support, Customer Success, and Communications; document gaps and drive corrective a
Work arrangement
No
More openings worth a look
Recently tracked roles with full details and direct application links.