Director of Security & IT
$226k - $275kSocial Leverage
Founded in 2019, Nayya is on a mission to connect people’s most important information, so they can thrive in their health and wealth. Powered by AI and advanced analytics, Nayya’s platform transforms complex benefits experiences into intuitive, seamless, and ongoing interactions—meeting people's real world needs. As a trusted platform and partner to leading employers, benefits solutions, and HR tech providers, Nayya unlocks long-term value through helping employees live more resilient lives. Backed by strategic investors like ICONIQ, Felicis Ventures, SemperVirens, Workday Ventures, MetLife Nextgen Ventures, and ADP Ventures, Nayya is ushering in the future of health and wealth for all. Role Summary: We are seeking a Director of Security & IT to lead Nayya's security strategy, compliance programs, and IT operations. This role will serve as the single point of accountability for protecting sensitive health and financial data, maintaining regulatory compliance, and ensuring the reliability and security of internal technology systems. Nayya is a benefits intelligence platform serving approximately 5 million employees. Our AI-powered platform delivers personalized guidance grounded in real plan data and claims history. The security and compliance requirements of this environment are significant: we handle Protected Health Information (PHI) at scale and operate under HIPAA, SOC 2, and other regulatory frameworks. This role reports to the Chief Product & AI Officer. The Director of Security & IT will partner closely with Engineering on infrastructure security while maintaining independent ownership of the security program, compliance posture, and IT operations. Key Responsibilities Security Program Leadership Lead the design, implementation, and continuous improvement of a comprehensive security program spanning application security, infrastructure security, data protection, and incident response. Implement and manage vulnerability assessments, penetration testing, and security audits to identify and mitigate risks across IT infrastructure and systems. Develop and maintain security policies, procedures, and controls aligned to SOC 2 Type II and HIPAA Security Rule requirements. Coordinate response to security incidents, including root cause analysis, containment, remediation, and legal reporting requirements. Own identity and access management (IAM) strategy, ensuring least-privilege access controls across production systems, cloud environments, and internal tools. Implement encryption, access control, audit logging, and other technical safeguards to meet HIPAA security requirements for data at rest, in transit, and during processing. Compliance & Risk Management Own SOC 2 Type II compliance initiatives, including audit preparation, controls documentation, evidence collection, and remediation of findings. Ensure compliance with HIPAA Privacy and Security Rules across Nayya's handling of PHI, including technical safeguards and organizational policies. Develop and maintain a risk management framework that identifies, evaluates, and prioritizes security and compliance risks, ensuring alignment with applicable regulations. Conduct regular risk assessments and vulnerability scans to proactively address potential compliance gaps. Prepare for and manage regulatory audits, customer security assessments, and external inspections related to data security and privacy. Stay current on emerging trends in healthcare data privacy regulations (HIPAA, HITECH, state-level requirements) and assess their impact on company policies and procedures. IT Operations & Help Desk Services Oversee day-to-day IT operations, ensuring all systems, networks, and applications function effectively and securely with minimal downtime. Lead the internal IT help desk function, ensuring timely resolution of technical issues with clear escalation protocols and service level agreements (SLAs). Monitor help desk performance metrics and implement improvements based on organizational needs. Manage IT asset lifecycle, including procurement, tracking, maintenance, and compliance with company policies. Ensure effective onboarding and offboarding processes for IT systems, with a focus on security awareness and HIPAA compliance training. Vendor & Third-Party Risk Management Evaluate and manage relationships with cloud providers, vendors, and third-party services to ensure they meet HIPAA and SOC 2 security and privacy requirements. Conduct due diligence and security assessments of third-party vendors, ensuring alignment with Nayya's data protection and compliance standards. Negotiate and manage contracts and SLAs to ensure third-party vendors meet security, compliance, and privacy expectations. Cross-Functional Collaboration Partner closely with the VP of Engineering on cloud security, infrastructure hardening, disaster recovery, and production access controls. Work with Legal, Finance, and People teams to ensure security and data privacy strategies align with business operations and legal obligations. Serve as the primary security and compliance liaison for enterprise customers, partners, and prospects during due diligence and procurement processes. Act as a strategic advisor to senior leadership on security investments, balancing risk mitigation against operational constraints and business priorities. Provide regular reports to the executive team on the status of security initiatives, compliance posture, and audit results. Lead, mentor, and develop a team of security, IT, and compliance professionals. Foster a culture of continuous improvement to stay ahead of cybersecurity threats and regulatory changes. Provide training to team members and the broader organization on security best practices, with emphasis on HIPAA compliance and PHI protection. Qualifications Required 10+ years of experience in security, IT infrastructure, and compliance, with at least 3 years owning a security function in a leadership capacity. Experience at a scaling software or AI company (50-1,000 employees) with exposure to the tradeoffs of building security programs with constrained resources. Proven depth in HIPAA compliance, healthcare data protection, and SOC 2 Type II audits. Strong understanding of cloud security architecture (AWS), network security, container security, and production access patterns. Experience building or significantly maturing security and compliance programs, not solely operating existing ones. Demonstrated ability to operate cross-functionally with Engineering, Legal, Finance, and People teams, turning ambiguity into structured execution. Strong program execution skills with a track record of driving multi-quarter initiatives across security, compliance, disaster recovery, access management, and vendor risk. Sound judgment in high-trust environments involving sensitive systems, company risk, customer data, and internal operations. Strong people leadership with experience managing technical teams, setting expectations, and creating accountability. Ability and willingness to go deep in a hands-on way where needed and delegate to the team where appropriate. Experience in healthcare, benefits, fintech, or another regulated environment where data sensitivity and compliance requirements are material. Preferred Relevant certifications: CISSP, CISM, CCSP, AWS Certified Solutions Architect, or similar. SOC 2 and HIPAA-specific credentials are highly desirable. Hands-on technical capability to engage in architecture discussions, evaluate operational tradeoffs, and assess technical risk directly when needed. A bias toward simplicity and prioritization across a broad surface area, focusing effort on what materially reduces risk and improves reliability. The salary range for New York based candidates for this role is $226,000- $275,000. We use a location factor to adjust this range for candidates that are located outside of geographic region of our New York office. Placement within the salary band is determined based on experience. Nayya is proud to be an Equal Employment Opportunity employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics Location New York, NY, USA Work Mode On-site Seniority Director Function IT Salary USD 226k-275k / year Company Size 51-200 employees Skills Audit Report Preparation Encryption Identity And Access Management Incident Response Network Security Penetration Testing Regulatory Compliance Risk Management Security Strategies Team Leadership Vulnerability Assessments #J-18808-Ljbffr
- ...Nayya in New York is searching for a Director of Security & IT to oversee security programs and IT operations. You'll be responsible for protecting sensitive health and financial data while maintaining compliance with regulatory standards. Your role includes leading security...Suggested
- ...Job Description As a Director of Technology, you will be a core member of RBW supporting our... .... Key Responsibilities Accountable for IT operations, including management of business... ...equipment, management of systems security processes Accountable for the design, implementation...SuggestedWork at officeFlexible hours
$105k - $155k
...approaches and learn by experimentation. The biggest learning through this was that persistence and calculated risks, pay off." The Director of Security & Loss Prevention is responsible for overseeing all aspects of the hotel's safety and security operations, including loss...SuggestedLocal area- ...Valid8 Financial, Inc. is looking for a Director, Critical Infrastructure Security (Utilities) to enhance security and compliance across utility sectors in the U.S. This role demands leadership in developing risk management strategies, understanding regulatory requirements...Suggested
$70k - $74k
...Women’s Shelter located in the Bushwick section of Brooklyn serves 165 women, approximately 37 of whom are MICA. Position: Director of Security & Operations Reports To: Vice President, Broadway House Location: 1245 Broadway, Brooklyn, NY 11221 What the Director of Security...SuggestedPermanent employmentFull timeContract workImmediate start- ...Join us in our mission to advance clinical research and improve patient care. One mission. One team. That’s OneStudyTeam. The Director of Security leads enterprise security strategy and execution across governance, risk, compliance, and security engineering. This role...Contract workFor contractorsFor subcontractorWork at officeRemote workVisa sponsorshipWork visa
$70k - $74k
...CAMBA is looking for a Director of Security & Operations for their facility in Brooklyn, New York. The role involves overseeing the security and maintenance of the facility, ensuring compliance with city and state regulations, and implementing crisis intervention strategies...$140k
...of people we serve thereby righting societal imbalances. The Director of Security is responsible for the strategic leadership, development, and... ...work collaboratively with program, real estate, facilities, and IT to promote a safe and respectful community. Responsibilities...Work at officeLocal area$226k - $275k
...A leading benefits intelligence platform is seeking a Director of Security & IT to lead enterprise security strategy and IT operations. This hybrid position based in NYC requires expertise in security architecture and HIPAA compliance. The candidate will manage security...- ...Montefiore New Rochelle is seeking a Director of Security responsible for overseeing the security operations for the Moses campus, ensuring the safety of patients, associates, and visitors. You will lead a team while developing strategic security goals and collaborating...Full time
- ...DE, FL, GA, HI, IL, IN, KY, MD, MA, MI, MS, NE, NV, NJ, NY, NC, OH, OR, PA, SC, TN, TX, UT, VA, WA. The Role The Director of Safety & Security is the network leader responsible for enterprise‑wide Environmental Health & Safety (EHS), physical security, loss prevention...Temporary workH1bLive inWork at officeRemote workWorldwideVisa sponsorship
$70k - $74k
...CAMBA is seeking a Director of Security & Operations in Brooklyn, NY, to ensure the safety and security of our facilities. This role involves developing and overseeing crisis management strategies, ensuring compliance with city regulations, and training staff for security...Full time- ...Position Title: Operations Director Reports to: Program Director Department: Security Employment Status: Full-Time FLSA Status: Exempt Position Status: Essential GENERAL JOB DESCRIPTION The Operations Director is responsible for the daily oversight...Full timeImmediate startShift workNight shift
$75k - $85k
...time. The majority of these clients are diagnosed with mental illness, some dually with chemical addictions as well. Position: Director of Security & Operations Reports To: Vice President Location: Brooklyn, NY What The Director of Security & Operations Does: The person...Permanent employmentFull timeContract workLive inImmediate start- ...Overview The Operations and Security Director works in cooperation and in conjunction with the Site Director and the Director of Social Services. The position ensures the overall operational, safety, and maintenance of the facility. In addition, must cross train the Operations...
- ...A leading direct mail and business communications company in New York is seeking a Director of IT to oversee IT strategy, daily operations, and technology support. The ideal candidate will have over 10 years in IT, including 5 years in leadership roles, and will drive...
$80k
...and providing the support you need to advance your career while making a meaningful difference in people’s lives. Title Director of Operations & Security Reports to Regional Director Pay Range $80,000 -80,000 per year FLSA Status Exempt Status Full-time (35 hour per week)...Permanent employmentFull timeTemporary workWork at officeLocal areaTrial periodMonday to FridayShift work$170k - $210k
...A leading security consultancy in the United States is seeking a Security Operations Leader to drive their global operations strategy. This role involves leading a high-performing team for 24/7 security monitoring, incident response, and ensuring regulatory compliance...$75k - $85k
...CAMBA is seeking a Director of Security & Operations to manage day-to-day security and operations at our facilities in Brooklyn, NY. The candidate will supervise staff, ensure compliance with security policies, and maintain a safe environment for clients. This full-time...Full time$130k - $150k
...A leading organization in copyright protection is seeking a Director of Security Operations in New York. This role involves overseeing daily security operations and developing security policies. The ideal candidate should have 20+ years of experience in law enforcement...$200k - $240k
...Overview Director of Cloud-Native Security Operations - 245347 Medix is seeking a Director of Cloud-Native Security Operations for one of our top healthcare data clients. Our client is a non-profit healthcare services organization that owns and manages a single source...Hourly payFull timeContract workRemote workShift work- ...Compensation Type Yearly Highgate Hotels Location M Social Hotel Overview The Director of Engineering & Security is responsible for all administrative, financial and operating aspects of the hotel as they directly relate to the engineering and security division. He/she...Local areaImmediate start
- ...Director of Safety & Security Location: New York City (Overseeing all NYC Cipriani properties) POSITION PURPOSE: Cipriani is seeking an experienced and highly discreet Director of Security to lead all security operations across our New York City locations. This...Local areaFlexible hoursNight shift
- ...Director of Global IT DevOps & AI Infrastructure Remote - US Endeavour has an exciting opportunity for someone passionate about sustainability... ...to take full ownership of how technology is built, deployed, secured, and scaled across the organization. This role is part of...Full timePart timeFor contractorsRemote work
- ...technology organizations. Strong expertise in enterprise architecture, IT infrastructure, and cloud platforms, including AWS, Google Cloud... ..., enterprise systems, and ensure employees have reliable, secure, and efficient technology tools. Develop and execute a...Permanent employment
- ...Overview The Director of IT Operations is responsible for the leadership, delivery, and continuous improvement of all operational and endpoint... ...hospitality environment. This role ensures the reliability, security, and performance of business‑critical systems that directly...Temporary work
$140k - $170k
...Corps Team Our client, a social prescribing platform, is seeking a Director of Engineering for a remote direct hire role. The Opportunity... ...practices, enforce HIPAA-compliant data handling, and shape a secure, resilient architecture. You’ll also be instrumental in hiring...Full timeWork at officeRemote work- ...like you to make a real difference in the industry. As a Senior Director of Architecture at JPMorganChase within Connected Commerce... ..., credential lifecycle, and fraud signals/decisioning. Design secure APIs and event-driven patterns enabling reusable trust services...
$136.5k - $350k
...Senior Director Of Network Security – Engineering Lead At BNY, our culture allows us to run our company better and enables employees' growth and success. As a leading global financial services company at the heart of the global financial system, we influence nearly...Temporary workWork experience placementRemote workWorldwideFlexible hours- ...The New York Public Library is seeking an Associate Director of IT Operations to lead the architecture, deployment, and management of desktop... ...through automation, while ensuring compliance with security standards. With a focus on modernizing the Library’s IT operations...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Director of Security & IT. Be the first to apply!
- director of corporate security New York, NY
- director of security New York, NY
- chief security officer New York, NY
- head of security New York, NY
- remote cio New York, NY
- information management officer New York, NY
- cio New York, NY
- it director remote New York, NY
- director of it audit New York, NY
- chief information officer New York, NY



