SIGN IN
Director of IT & Security, CISO jobs in United States
cer-icon
Apply on Employer Site
company-logo

Redox · 2 weeks ago

Director of IT & Security, CISO

Redox is on a mission to accelerate healthcare’s transformation with useful data. They are seeking a hands-on Director of IT & Security, CISO to own enterprise security, cloud, and application security, and corporate IT, while leading security engineering, security operations, and corporate IT. The role requires close collaboration with Engineering, Platform, and Operations to ensure a strong security posture and reliable internal systems.
Big DataMedical DeviceHealthcareInformation TechnologyData IntegrationElectronic Health Record (EHR)Health Care
check
Comp. & Benefits
badNo H1Bnote

Responsibilities

Own end-to-end information security strategy across cloud, application, infrastructure, and corporate environments
Define a pragmatic security roadmap aligned to business risk, regulatory requirements, and engineering velocity
Serve as the executive owner for security posture, risk management, and incident response
Act as a trusted advisor to the CTO and executive team on security, risk, and operational tradeoffs
Drive a DevSecOps-first operating model, embedding security into CI/CD pipelines, infrastructure as code, and developer workflows
Partner deeply with engineering leadership to make security scalable, automated, and measurable
Lead threat modeling, secure design reviews, and risk assessments for new platform initiatives
Champion policy-as-code, guardrails, and automation over manual process
Own security architecture and operations for a primarily AWS-based environment
Lead application security programs, including secure SDLC, dependency scanning, SAST/DAST, penetration testing, and vulnerability management
Own identity and access management strategy with Okta as the backbone
Ensure strong detection, alerting, and response across endpoints and cloud workloads (e.g., CrowdStrike, RAD)
Build and run effective security operations, including monitoring, investigation, incident response, and post-incident learning
Lead incident response for both security and IT incidents, serving as the calm point of accountability
Run tabletop exercises and continuously improve response playbooks
Manage vendor relationships, including CrowdStrike, Flashpoint, RAD, and Okta
Own corporate IT strategy and execution, focused on reliability, security, and employee productivity
Lead end-user computing, device management, endpoint security, identity lifecycle management, and access controls
Oversee IT systems, including identity, email, collaboration tools, endpoint management, and SaaS access governance
Drive automation and standardization across onboarding, offboarding, access management, and device lifecycle
Partner with People Ops, Legal, and Finance on IT processes, audits, and vendor management
Own healthcare-related security and compliance programs (e.g., HIPAA, SOC 2)
Translate regulatory requirements into practical, engineering-friendly controls
Lead third-party risk management and vendor security reviews
Support customer security reviews and serve as an executive point of contact on security matters
Build, lead, and mentor a high-performing team spanning security engineering, security operations, and IT
Create a culture where security and IT are seen as enablers, not blockers
Establish clear ownership, measurable outcomes, and high operational standards
Be visible, decisive, and calm under pressure

Qualification

Information SecurityIT LeadershipSecurity EngineeringSecurity OperationsCorporate ITHealthcare Technology SaaSDevSecOpsAWSEndpoint SecurityIdentity SystemsCrowdStrikeOktaFlashpointRADApplication SecurityCloud SecurityInfrastructure as CodeHIPAA ComplianceSOC 2 ComplianceThird-Party Risk Management

Required

10+ years in information security, IT, or related technical leadership roles, including 5+ years of people management, ideally in healthcare technology SaaS
Proven experience leading security engineering, security operations, and corporate IT in a cloud-native SaaS environment
Direct experience in healthcare or other highly regulated industries
Track record of successfully implementing DevSecOps practices
Deep hands-on experience securing AWS environments
Strong understanding of endpoint security, identity systems, and modern SaaS IT stacks
Practical knowledge of tools such as CrowdStrike, Okta, Flashpoint, RAD, and related platforms
Strong foundation in application security, cloud security, and infrastructure as code
Strong collaborator with engineering, platform, and operations teams
Clear, direct communicator who can articulate risk without theatrics
Comfortable making tradeoffs and prioritizing based on real-world risk
Builder mindset with a bias toward automation and scale

Preferred

Proven experience securing autonomous agentic loops and tool-calling frameworks. Deep understanding of Indirect Prompt Injection and designing 'Human-in-the-Loop' guardrails for agent-driven actions
Technical expertise in securing the Model Context Protocol (MCP), specifically regarding context isolation, sandboxing, and identity propagation between LLMs and private data sources
Direct experience migrating security programs to Vanta or similar automated GRC platforms. Ability to architect 'continuous compliance' by integrating cloud, identity, and developer tools for automated evidence collection
Hands-on application of the NIST AI RMF, OWASP Top 10 for LLMs, etc within a production environment

Company

Redox is an EHR integration and healthcare platform that accelerates the development and distribution of healthcare software solutions.

Funding

Current Stage
Late Stage
Total Funding
$107.28M
Key Investors
Adams Street PartnersBattery VenturesRRE Ventures
2025-05-09Convertible Note· $12.28M
2021-02-24Series D· $45M
2019-04-17Series C· $33M

Leadership Team

leader-logo
Trip Hofer
Chief Executive Officer
linkedin
leader-logo
Luke Bonney
Co-Founder
linkedin
Company data provided by crunchbase