Nayya

Nayya

Director of Security & IT

New York, NY (Hybrid) · Director

Sponsorship not specified$226k-$275kDetected 127 days ago
AWSCloud PlatformsRESTCybersecurityPenetration TestingNetwork SecurityComplianceProcurementHRISHIPAALeadershipCollaborationCISSP

About the role

  • Backed by strategic investors like ICONIQ, Felicis Ventures, SemperVirens, Workday Ventures, MetLife Nextgen Ventures, and ADP Ventures, Nayya is ushering in the future of health and wealth for all.
  • This role will serve as the single point of accountability for protecting sensitive health and financial data, maintaining regulatory compliance, and ensuring the reliability and security of internal technology systems.
  • This role reports to the Chief Product & AI Officer.

Responsibilities

  • Lead the design, implementation, and continuous improvement of a comprehensive security program spanning application security, infrastructure security, data protection, and incident response.
  • Implement and manage vulnerability assessments, penetration testing, and security audits to identify and mitigate risks across IT infrastructure and systems.
  • Develop and maintain security policies, procedures, and controls aligned to SOC 2 Type II and HIPAA Security Rule requirements.
  • Own identity and access management (IAM) strategy, ensuring least-privilege access controls across production systems, cloud environments, and internal tools.
  • Implement encryption, access control, audit logging, and other technical safeguards to meet HIPAA security requirements for data at rest, in transit, and during processing.
  • Own SOC 2 Type II compliance initiatives, including audit preparation, controls documentation, evidence collection, and remediation of findings.
  • Develop and maintain a risk management framework that identifies, evaluates, and prioritizes security and compliance risks, ensuring alignment with applicable regulations.
  • Prepare for and manage regulatory audits, customer security assessments, and external inspections related to data security and privacy.
  • Lead the internal IT help desk function, ensuring timely resolution of technical issues with clear escalation protocols and service level agreements (SLAs).
  • Monitor help desk performance metrics and implement improvements based on organizational needs.

Requirements

  • 10+ years of experience in security, IT infrastructure, and compliance, with at least 3 years owning a security function in a leadership capacity.
  • Strong understanding of cloud security architecture (AWS), network security, container security, and production access patterns.
  • Demonstrated ability to operate cross-functionally with Engineering, Legal, Finance, and People teams, turning ambiguity into structured execution.
  • Strong program execution skills with a track record of driving multi-quarter initiatives across security, compliance, disaster recovery, access management, and vendor risk.
  • Required
  • Experience at a scaling software or AI company (50-1,000 employees) with exposure to the tradeoffs of building security programs with constrained resources.
  • Proven depth in HIPAA compliance, healthcare data protection, and SOC 2 Type II audits.
  • Experience building or significantly maturing security and compliance programs, not solely operating existing ones.
  • Sound judgment in high-trust environments involving sensitive systems, company risk, customer data, and internal operations.
  • Strong people leadership with experience managing technical teams, setting expectations, and creating accountability.
  • Ability and willingness to go deep in a hands-on way where needed and delegate to the team where appropriate.
  • Experience in healthcare, benefits, fintech, or another regulated environment where data sensitivity and compliance requirements are material.
  • Preferred
  • Relevant certifications: CISSP, CISM, CCSP, AWS Certified Solutions Architect, or similar. SOC 2 and HIPAA-specific credentials are highly desirable.

Compensation

  • The salary range for New York based candidates for this role is $226,000- $275,000.

Benefits

  • Founded in 2019, Nayya is on a mission to connect people's most important information, so they can thrive in their health and wealth.
  • Powered by AI and advanced analytics, Nayya's platform transforms complex benefits experiences into intuitive, seamless, and ongoing interactions-meeting people's real world needs.
  • As a trusted platform and partner to leading employers, benefits solutions, and HR tech providers, Nayya unlocks long-term value through helping employees live more resilient lives.
  • Nayya is a benefits intelligence platform serving approximately 5 million employees.
  • Stay current on emerging trends in healthcare data privacy regulations (HIPAA, HITECH, state-level requirements) and assess their impact on company policies and procedures.

Company info

  • Serve as the primary security and compliance liaison for enterprise customers, partners, and prospects during due diligence and procurement processes.

Equal opportunity

  • Hands-on technical capability to engage in architecture discussions, evaluate operational tradeoffs, and assess technical risk directly when needed.
  • A bias toward simplicity and prioritization across a broad surface area, focusing effort on what materially reduces risk and improves reliability.

This listing is sourced directly from Nayya's careers page and normalized into a canonical job model.