Head of IT & Security
$175k - $220kNexHealth
About NexHealth Our healthcare system remains frustratingly analog. When you live in a world of one-tap car rides, instant meal delivery, and unlimited streaming, why do you still have to call to schedule a doctor's appointment and fill out a clipboard in the waiting room? NexHealth's mission is to accelerate innovation in healthcare by connecting patients, providers, and developers. We're building the infrastructure layer for modern healthcare, connecting thousands of fragmented, on-premise, and closed EHR systems into a single, modern platform that powers software, APIs, payments, and patient experiences across the ecosystem.
What You'll Do
Experience
We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, sex, gender expression, sexual orientation, age, marital status, veteran status, or disability status. We provide reasonable accommodation for individuals with disabilities to participate in the application or interview process. Contact View email address on click.appcast.io to request assistance.
- Founded: 2017
- Headquarters: San Francisco, CA
- Funding: $177M Series C
- Employees: 200+
- Trusted by tens of thousands of providers and hundreds of health-tech developers - forging the infrastructure layer that modern healthcare needs
What You'll Do
- Own NexHealth's security governance, compliance, and IT programs end-to-end.
- Serve as named Information Security Officer and Privacy Officer for SOC 2 and HIPAA - own the policy manual (40+ documents), audit liaison relationship with A-LIGN, control mapping across overlapping regimes, and evidence collection pipelines.
- Set security standards across application security, vulnerability management, cloud security (AWS), audit logging, and access controls - driving the technical program through Engineering via influence, not direct authority.
- Build, hire, and develop the IT and workforce security program: endpoints, identity, SaaS administration, phishing simulations, role-specific training modules, and facilities security.
- Own vendor security: intake, classification, assessment, BAA execution, ongoing oversight, and customer-facing trust artifacts including Trust Center and subprocessor disclosure.
- Lead incident response in Officer capacity; partner with outside counsel on breach determinations, own IR tracking, and run annual tabletop exercises.
- Own the risk register, risk acceptance decisions, privacy operations (DSARs, data subject rights, privacy complaints), BC/DR plan, and cyber insurance relationship.
- Hire a Staff-level IT IC within year one and grow the function from there.
Experience
- 8+ years of relevant security experience, including 3+ years in a security leadership role where you were materially building the program, not maintaining it.
- Has built (not inherited) a security program from a near-zero baseline at least once.
- Has owned a recurring external audit cycle end-to-end (e.g., SOC 2, ISO, PCI, HITRUST) - designed evidence collection, mapped controls, ran the auditor relationship, and made the next cycle materially easier than the last.
- Software engineering background. Can read a pull request, evaluate cloud configurations, and push back on Engineering with technical substance.
- Experience hiring and developing senior security or IT individual contributors.
- Hands-on experience with security tools and technologies such as SIEM, MDR, IDS/IPS, WAF, DLP, and vulnerability scanners.
- You've reshaped how a company engages with auditors, regulators, or customer security teams - moved questionnaires to Trust Centers, audits from manual to automated, or vendor reviews from one-off projects to continuous programs.
- You drive sustained operational change in functions you don't manage.
- You treat engineering velocity as a security input. Slow shipping creates security risk too.
- You can frame risk for a Board-level audience and for an engineering audience in the same week.
- First-principles thinker.
- Writes. NexHealth runs on documents; verbal-first operators struggle here.
- Comfortable being the ranking voice on policy and risk.
- Full Medical, Dental, and Vision (up to 100% covered)
- 401K and commuter benefits
- Flexible PTO
- High-impact work that directly improves the healthcare experience for millions
- Solve the customer's problems, not yours When making decisions, think from the perspective of the customer. It's easy to make decisions that make our lives simpler, but not the customers.
- Do the things others are not willing to do As a Nexer, always go after the hardest problems. Pursue things at the highest quality. Move at the fastest pace.
- Take ownership Act like a founder. Own your roles, destinies, mistakes, behavior, and our mission. The buck stops with each of us - no blaming or excuses.
- Say what's on your mind, with positive intent Be direct, proactive, transparent, and frequent in your communication.
- Default trust As a Nexer, you do not have to earn trust, trust is given to you by default. If we by default trust each other, our speed of communication, feedback, information sharing, and overall improvements will be a lot faster.
- Think in first principles We first identify the problem and then break it down to its fundamentals before diving into solutions. We constantly ask "why" to validate our assumptions.
We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, sex, gender expression, sexual orientation, age, marital status, veteran status, or disability status. We provide reasonable accommodation for individuals with disabilities to participate in the application or interview process. Contact View email address on click.appcast.io to request assistance.
Vacancy posted 19 hours ago
Similar jobs that could be interesting for youBased on the Head of IT & Security in San Francisco, CA vacancy
- ...PayZen is looking for a Sr. IT Manager to head our IT operations from our San Francisco office. This role requires a strong leader with 8+ years in IT management, overseeing our global IT infrastructure and ensuring operational productivity. Your contributions will directly...SuggestedWork at office
- ...and complexity of modern manufacturing. So we decided to upgrade it. Engineers make million-dollar decisions every day, and they... ...Francisco, CA. About the role: As CISO, you will own Lumafield's security function end-to-end—from cloud infrastructure and product...SuggestedWork at officeFlexible hours
- ...we're building a smarter, faster, and more secure financial future by revolutionizing the... ...Chief Information Security Officer (CISO) & Head of Information Technology will serve as Trustly... ..., and response, while also leading the IT organization that underpins Trustly’s...SuggestedFull timeContract workTemporary workWork at officeWorldwideHome officeFlexible hours
- Job Description Job Description Chiropractor (DC) – Fast-Growing Chiropractic Clinic | The Joint Chiropractic The Joint Chiropractic is seeking Licensed Chiropractors (DCs)who are passionate about patient care, wellness, pain relief, and long-term health . As...SuggestedFull timePart timeFlexible hours
- ...build the future of inclusive finance through cutting‑edge technology and customer‑centric solutions. Overview As Chief Information Security Officer (CISO), you will be the primary leader responsible for developing and implementing our information security strategy. You’...SuggestedImmediate startFlexible hours
- ...Location Toronto; London; Montreal; New York; San Francisco Employment Type Full time Location Type Hybrid Department Platform, Security Who are we? Our mission is to scale intelligence to serve humanity. We’re training and deploying frontier models for developers and...Full timeWork at officeRemote workFlexible hours
$170k - $220k
...Distyl AI is seeking a Head of IT in San Francisco, CA to lead the global IT organization as the company scales from 180 to over 500 employees... .... This role involves overseeing all aspects of IT including security, compliance, and employee technology across multiple locations...- ...Information Technology CGS is seeking an Information Systems Security Officer (ISSO) with DIACAP and/or RMF experience who has deep expertise... ...as HBSS or ACAS, and patch management, such as IAVM to ensure IT staff pushes patches to all systems in an effort to maintain...Full timeLocal areaFlexible hours
- ...Cohere is looking for a Chief Information Security Officer to lead security strategy and governance. You will build trust across teams, ensuring security and innovation coexist. The ideal candidate will have extensive experience in high-growth tech, cloud security, and...Remote workFlexible hours
- ...IT Director We are looking for an experienced IT Director to oversee all IT functions in our company. This person will be in charge of the IT team and will be experienced in creating and implementing IT policies and systems that will meet objectives. The IT Director...
- ...travel About the Role Sardine is hiring a Deputy Chief Information Security Officer to partner closely with our CISO and help scale our... ...security, GRC, security operations, cloud and SaaS security, corporate IT, customer trust, and overall security strategy. You’ll serve as...Remote workHome officeFlexible hours
- ...A fast-growing fintech firm in San Francisco is seeking a Chief Information Security Officer to develop and implement its information security strategy. The ideal candidate will have significant experience in cybersecurity, particularly in fintech. This role involves...Flexible hours
- ...Sardine is seeking a Deputy Chief Information Security Officer to strengthen our security program. This senior role involves partnering with the CISO on security strategy, prioritizing risks, and representing the security program across teams. The candidate should have...Remote workFlexible hours
- ...all sizes to explore, design, and implement AI strategies that are secure, scalable, and human-centered. We believe AI should amplify human... ...through thoughtful, responsible innovation. And through it all, we lead with purpose, love, and adventure. We do meaningful...Full timeFor contractorsRemote work
- ...forensic data collection and basic forensic analysis in both on-site and remote capacity - Coordinate directly with legal teams/client IT departments to understand project scope - Maintain forensic tool set by staying current on version updates and new options in the...Full timeWork at officeRemote workFlexible hours
- Lambda Inc. is seeking a seasoned technology leader to drive AI cloud infrastructure initiatives. The role demands a minimum of 15 years of experience in cloud design and deployment, enhancing relationships with C-suite executives, and mentoring teams. Candidates should...Flexible hours
- Job Description Job Description What is special about Lighthouse? Lighthouse is built on a foundation of unique, compassionate, highly driven individuals. We elevate the strengths and talents of those around us while leveraging opportunities for growth. We offer ...Temporary workWork at officeRemote workFlexible hoursWeekend workAfternoon shift2 days per week3 days per week
- ...A tech-focused company in San Francisco is seeking a CISO to own the end-to-end security function. This role involves defining security culture, managing both cloud and product security while ensuring compliance. The ideal candidate will have over 10 years of experience...
- ...A leading financial technology company is seeking a Chief Information Security Officer (CISO) to establish and lead its information security and cybersecurity programs. This role involves developing an enterprise-wide security framework and managing all aspects of cybersecurity...Remote workFlexible hours
- Veriswap is seeking a driven individual for a role involving proactive planning and management of the CEO and CTO’s appointments. While mostly remote, some assistance is required in person near Palo Alto, CA. The ideal candidate will be highly organized with a zest for ...Remote job
- Lighthouse, based in San Francisco, is seeking a Forensics Associate to collect and analyze electronically stored information for investigations. Candidates should ideally have a Bachelor's degree and at least two years of experience in digital forensics. The role demands...Flexible hours
- The chiropractor will provide care for patients with health problems of the neuro‑musculoskeletal system, which includes nerves, bones, muscles, ligaments, and tendons. He/she will use spinal adjustments, manipulation, and other techniques to manage patients’ health concerns...Part time
- ...scale a growing technology team, fostering a culture of innovation, security, and accountability. Oversee Windows and Mac hardware... ...across all employees and offices. Collaborate with third-party IT vendors to outsource services when necessary. Trouble shoot, resolve...Ongoing contractFull timeContract workWork at officeRemote work
$220k - $245k
Responsible for developing the investment strategy and leading investment activities, managing investments in portfolio, and assisting in raising investment capital through fundraising with endowments/foundations. Oversees and builds a dynamic team of six professionals...Immediate start- ...partners, and the broader AI infrastructure ecosystem. This is not a traditional pre-sales, solutions architect, or management role. It is a market-shaping position for an experienced technology leader who can influence customer strategy, represent Cornelis Networks in...Full timeRemote workFlexible hoursShift work
- North East Medical Services seeks a dedicated chiropractor in San Francisco to care for patients with neuro-musculoskeletal health issues. Responsibilities include consultations, spinal adjustments, and developing treatment plans for recovery. The ideal candidate will ...Part time
$163.15k - $191.88k
...strategic vision, planning, and execution of all IT functions. Reporting directly to the Chief... ...mission enabler: driving efficiency, data security, and digital transformation across a $70M... ...regular needs assessments with department heads and program leaders to identify technology...Full timeContract workWork at officeLocal areaImmediate startRelocationWeekend workAfternoon shift- ...building an agentic Trust Graph: an AI system that maps your real connections and acts as the orchestration layer for your network. It understands who you know, how well you know them, and who can introduce you to the people that matter based on what you're looking for...Full timeWork at officeRelocationVisa sponsorship
$250k - $375k
Who Are We? Postman is the world's leading API platform, used by more than 45 million+ developers and 500,000 organizations, including 98% of the Fortune 500. Postman is helping developers and professionals across the globe build the API-first world by simplifying ...Work at officeFlexible hours3 days per week- We are seeking a highly experienced and visionary technical business development leader to spearhead and expand our rapidly growing AWS business. As the AWS Partnership CTO , you will oversee the technical aspects of our AWS collaboration, driving alignment with AWS ...Temporary workRemote workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Head of IT & Security. Be the first to apply!
Related searches
- chief information security officer ciso San Francisco, CA
- ciso San Francisco, CA
- chief information security officer San Francisco, CA
- information security officer San Francisco, CA
- business information security officer San Francisco, CA
- IT security San Francisco, CA
- IT security analyst San Francisco, CA
- chief information security officer ciso
- ciso
- chief information security officer


