NexHealth
Head of IT & Security
Seattle, Washington, United States · Exec
Sponsorship not specified$160k-$200kDetected 6 days ago
AWSCybersecuritySIEMIncident ResponseComplianceAuditingFirewall5G/LTEHIPAAEHR/EMRLeadershipCommunicationInternal Audit
About the role
- This is a player-coach role with real hands-on expectation in year one.
Responsibilities
- Own NexHealth's security governance, compliance, and IT programs end-to-end.
- Serve as named Information Security Officer and Privacy Officer for SOC 2 and HIPAA - own the policy manual (40+ documents), audit liaison relationship with A-LIGN, control mapping across overlapping regimes, and evidence collection pipelines.
- Build, hire, and develop the IT and workforce security program: endpoints, identity, SaaS administration, phishing simulations, role-specific training modules, and facilities security.
- Own vendor security: intake, classification, assessment, BAA execution, ongoing oversight, and customer-facing trust artifacts including Trust Center and subprocessor disclosure.
- Lead incident response in Officer capacity
- Own the risk register, risk acceptance decisions, privacy operations (DSARs, data subject rights, privacy complaints), BC/DR plan, and cyber insurance relationship.
- 8+ years of relevant security experience, including 3+ years in a security leadership role where you were materially building the program, not maintaining it.
- Has owned a recurring external audit cycle end-to-end (e.g., SOC 2, ISO, PCI, HITRUST) - designed evidence collection, mapped controls, ran the auditor relationship, and made the next cycle materially easier than the last.
Requirements
- Hands-on experience with security tools and technologies such as SIEM, MDR, IDS/IPS, WAF, DLP, and vulnerability scanners.
- You can frame risk for a Board-level audience and for an engineering audience in the same week.
- You've reshaped how a company engages with auditors, regulators, or customer security teams - moved questionnaires to Trust Centers, audits from manual to automated, or vendor reviews from one-off projects to continuous programs.
- You drive sustained operational change in functions you don't manage.
- You treat engineering velocity as a security input. Slow shipping creates security risk too.
- Behavioral Traits
- First-principles thinker.
- Writes. NexHealth runs on documents
- verbal-first operators struggle here.
- Comfortable being the ranking voice on policy and risk.
Compensation
- The range listed is just the base salary component of NexHealth's total compensation package for employees.
- NexHealth Compensation Range
- $160,000 - $200,000 USD
- partner with outside counsel on breach determinations, own IR tracking, and run annual tabletop exercises.
Benefits
- Full Medical, Dental, and Vision (up to 100% covered)
- 401K and commuter benefits
- High-impact work that directly improves the healthcare experience for millions
Company info
- NexHealth is a technology company building infrastructure that's reshaping how patient data moves and how the HealthTech ecosystem connects.
- It's easy to make decisions that make our lives simpler, but not the customers.
Apply directly at NexHealth →Create a free account for alerts like thisView NexHealth immigration profile
This listing is sourced directly from NexHealth's careers page and normalized into a canonical job model.