Director, Security and Compliance Job at Redesign Health

Redesign Health New York, NY

Redesign Health has recently become aware of the fraudulent use of our name on job postings and via recruiting emails that are illegitimate and not in any way associated with us. Redesign Health will never ask you to provide sensitive personal information as part of the recruiting process, such as your social security number; send you any unsolicited job offers or employment contracts; require any fees, payments or access to any financial accounts; and/or conduct text-only interviews. If you suspect you are being scammed or have been scammed online, you may report the crime to the Federal Bureau of Investigation and obtain more information regarding online scams at the Federal Trade Commission. If you have any questions regarding the authenticity of any communication sent purportedly by on or behalf of Redesign Health, we encourage you to contact us here.

Redesign Health is a proud Equal Opportunity Employer – we recruit, train, compensate and promote our team members based on qualifications. We know how important it is not only to include, but to actively seek out a diversity of opinions and voices.

We want to hear from you regardless of your race, religion, national origin, sex, gender identity, sexual orientation, disability, age, veteran status, or any other applicable legally protected characteristics.

Redesign Health is a company that powers innovation in healthcare. We develop technologies, tools, and insights that lower the barriers to change in healthcare, and provide a platform that enables founders and the broader healthcare ecosystem to build high-quality health solutions at scale. We have powered the launch of over 30 companies to-date, impacting more than ten million lives across many aspects of the healthcare ecosystem including cancer care, teleaudiology, COVID-19 testing, metabolic health and more. We're on a mission to redesign health for everyone.

About the Job

As our Director, Security and Compliance, you will help build and lead a team and function responsible for designing, implementing, and managing Information Security and Compliance measures within our company. You will serve as both a leader and strategist and help inform our overall Technology roadmap, ensuring security is top of mind and built into what we do, not just an afterthought. You will also play a hands-on role in performing security and compliance related activities.

This role is fully remote and reports to the VP of Technology and Security at Redesign Health.

What you'll do

  • Responsible for developing, implementing, maintaining, and monitoring a strategic comprehensive enterprise cybersecurity and IT risk management program.
    • Identifying, evaluating, and mitigating risks across the organization.
    • Drive security-related investigations and resolutions.
    • Ensure employees are trained on security related concepts, as well as our internal policies, procedures, and controls.
    • Including but not limited to:
  • Provide vision, leadership, strategy, and execution to manage technology-related risks to the organization, ensuring business alignment, governance, systems availability, integrity, and confidentiality.
    • Strategically apply technology-based solutions to key initiatives for the business.
  • Oversee, coordinate, and execute on information security and compliance initiatives working with executive leadership, business and functional leaders, and staff including Legal/Compliance, People Operations, Product/Engineering, Technology Operations, etc.
    • Be able to lead and manage a Security team
  • Develop, maintain, publish, and update security policies, procedures, standards and guidelines.
    • Implement security and compliance solutions in partnership with Vendor Management, Technology Operations, and Product/Engineering teams with a rigorous, thoughtful, and contextual implementation process.

What you'll need (Background)

  • You have 7+ years experience in Security and IT roles, and having implemented cybersecurity programs
  • You have 5+ years of direct security related experience and third party risk management experience (software security principles, secure coding practices, etc) and knowing how to implement and manage Snyk, Veracode, Checkmarx, Burp Suite, OWASP ZAP, or related technologies
  • You have 3+ years of experience with securing infrastructure in cloud environments such as AWS, DevOps and/or DevSecOps, as well as software engineering related cloud security experience
  • You have 3+ years of experience leading a security team and success working collaboratively across departments to achieve security outcomes
  • You bring a solid understanding of HIPAA compliance experience, SOC audit experience, and related regulations.
  • You can demonstrate third party risk management experience (take what vendor management has built and build a security component to it)

What you will bring to the table (Specialized/Technical skills)

  • You have proven technical ability with AWS Security
  • You have working knowledge and technical ability with Information Security Identity & Access Management
  • You hold at least 1 certification in Security & Compliance (CISSP, CISM, CISA, CISSP, etc)

Who you are (Behavioral Competencies)

  • Balances Stakeholders. You understand and anticipate internal and external stakeholder requirements, expectations, and needs. You consider cultural and ethical factors in the decision-making process, and act fairly despite conflicting demands.
  • Manages Complexity. You ask the right questions to accurately analyze situations and uncover root causes to difficult issues. Through acquiring data from multiple and diverse sources, you are able to make sense of complex, high-quantity, and sometimes contradictory information to solve problems.
  • Communicates Effectively. You are effective in a variety of communication settings: one-on-one, small and large groups, or among diverse styles and position levels.

You will work out of one of the following locations:

In-office: New York, NY

Remote: Alabama, Arizona, Arkansas, California, Colorado, Connecticut, Delaware, District of Columbia, Florida, Georgia, Idaho, Illinois, Indiana, Iowa, Kansas, Kentucky, Louisiana, Maine, Maryland, Massachusetts, Michigan, Minnesota, Mississippi, Missouri, Montana, Nebraska, Nevada, New Hampshire, New Jersey, New Mexico, New York, North Carolina, North Dakota, Ohio, Oklahoma, Oregon, Pennsylvania, Rhode Island, South Carolina, South Dakota, Tennessee, Texas, Utah, Vermont, Virginia, Washington, West Virginia, Wisconsin, Wyoming.

Full-time base salary of $209,000.00 plus a competitive equity & benefits package listed under the "Why work with us?" section.

What Redesign is all about

Redesign's mission is to elevate healthcare companies that empower people to live their healthiest lives. To give a sense of what our team is all about, these are the values that guide our work:

  • Redesign healthcare - We bring positive change to patients' lives
  • Own the outcome - We do the work to get the job done
  • Be trusted partners - We strive to be the teammates and co-founders of choice
  • Champion diverse perspectives - We work to unlock our joint potential
  • Practice kindness - We aim to build bridges, not walls
  • Learn continuously - We focus on constantly growing as individuals and as a team

Why work with us?

We care deeply about your well-being. And we've tailored our unique benefits around your wellness. Check out our full range of benefits here, and a few of our highlighted benefits below:

  • Benefits for your physical wellness:
    • Full medical, dental, and vision coverage with no monthly contribution for you and your dependents (for all of our plans!)
    • Quarterly in-home house cleaning
    • $50 a month wellness stipend
  • Benefits for your financial wellness:
    • 401K match
    • Student loan repayment contribution
    • Tax preparation services
  • Benefits for your mental wellness:
    • Unlimited PTO
    • An annual 2-week company-wide winter break
    • 2 month sabbatical after 4 years
    • Reimbursements to Spotify & Headspace
  • Benefits for the wellness of parents:
    • 16 week full paid parental leave
    • Maven Clinic access with $2k lifetime contributions to fertility & adoption services
    • Diaper subscription service & summer camp reimbursement program



Please Note :
epokagency.com is the go-to platform for job seekers looking for the best job postings from around the web. With a focus on quality, the platform guarantees that all job postings are from reliable sources and are up-to-date. It also offers a variety of tools to help users find the perfect job for them, such as searching by location and filtering by industry. Furthermore, epokagency.com provides helpful resources like resume tips and career advice to give job seekers an edge in their search. With its commitment to quality and user-friendliness, Site.com is the ideal place to find your next job.