Nayya
Director of Security & IT
New York, NY (Hybrid) · Director
Sponsorship not specified$226k-$275kDetected 127 days ago
AWSCloud PlatformsRESTCybersecurityPenetration TestingNetwork SecurityComplianceProcurementHRISHIPAALeadershipCollaborationCISSP
About the role
- Backed by strategic investors like ICONIQ, Felicis Ventures, SemperVirens, Workday Ventures, MetLife Nextgen Ventures, and ADP Ventures, Nayya is ushering in the future of health and wealth for all.
- This role will serve as the single point of accountability for protecting sensitive health and financial data, maintaining regulatory compliance, and ensuring the reliability and security of internal technology systems.
- This role reports to the Chief Product & AI Officer.
Responsibilities
- Lead the design, implementation, and continuous improvement of a comprehensive security program spanning application security, infrastructure security, data protection, and incident response.
- Implement and manage vulnerability assessments, penetration testing, and security audits to identify and mitigate risks across IT infrastructure and systems.
- Develop and maintain security policies, procedures, and controls aligned to SOC 2 Type II and HIPAA Security Rule requirements.
- Own identity and access management (IAM) strategy, ensuring least-privilege access controls across production systems, cloud environments, and internal tools.
- Implement encryption, access control, audit logging, and other technical safeguards to meet HIPAA security requirements for data at rest, in transit, and during processing.
- Own SOC 2 Type II compliance initiatives, including audit preparation, controls documentation, evidence collection, and remediation of findings.
- Develop and maintain a risk management framework that identifies, evaluates, and prioritizes security and compliance risks, ensuring alignment with applicable regulations.
- Prepare for and manage regulatory audits, customer security assessments, and external inspections related to data security and privacy.
- Lead the internal IT help desk function, ensuring timely resolution of technical issues with clear escalation protocols and service level agreements (SLAs).
- Monitor help desk performance metrics and implement improvements based on organizational needs.
Requirements
- 10+ years of experience in security, IT infrastructure, and compliance, with at least 3 years owning a security function in a leadership capacity.
- Strong understanding of cloud security architecture (AWS), network security, container security, and production access patterns.
- Demonstrated ability to operate cross-functionally with Engineering, Legal, Finance, and People teams, turning ambiguity into structured execution.
- Strong program execution skills with a track record of driving multi-quarter initiatives across security, compliance, disaster recovery, access management, and vendor risk.
- Required
- Experience at a scaling software or AI company (50-1,000 employees) with exposure to the tradeoffs of building security programs with constrained resources.
- Proven depth in HIPAA compliance, healthcare data protection, and SOC 2 Type II audits.
- Experience building or significantly maturing security and compliance programs, not solely operating existing ones.
- Sound judgment in high-trust environments involving sensitive systems, company risk, customer data, and internal operations.
- Strong people leadership with experience managing technical teams, setting expectations, and creating accountability.
- Ability and willingness to go deep in a hands-on way where needed and delegate to the team where appropriate.
- Experience in healthcare, benefits, fintech, or another regulated environment where data sensitivity and compliance requirements are material.
- Preferred
- Relevant certifications: CISSP, CISM, CCSP, AWS Certified Solutions Architect, or similar. SOC 2 and HIPAA-specific credentials are highly desirable.
Compensation
- The salary range for New York based candidates for this role is $226,000- $275,000.
Benefits
- Founded in 2019, Nayya is on a mission to connect people's most important information, so they can thrive in their health and wealth.
- Powered by AI and advanced analytics, Nayya's platform transforms complex benefits experiences into intuitive, seamless, and ongoing interactions-meeting people's real world needs.
- As a trusted platform and partner to leading employers, benefits solutions, and HR tech providers, Nayya unlocks long-term value through helping employees live more resilient lives.
- Nayya is a benefits intelligence platform serving approximately 5 million employees.
- Stay current on emerging trends in healthcare data privacy regulations (HIPAA, HITECH, state-level requirements) and assess their impact on company policies and procedures.
Company info
- Serve as the primary security and compliance liaison for enterprise customers, partners, and prospects during due diligence and procurement processes.
Equal opportunity
- Hands-on technical capability to engage in architecture discussions, evaluate operational tradeoffs, and assess technical risk directly when needed.
- A bias toward simplicity and prioritization across a broad surface area, focusing effort on what materially reduces risk and improves reliability.
This listing is sourced directly from Nayya's careers page and normalized into a canonical job model.