NexHealth

NexHealth

Head of IT & Security

Seattle, Washington, United States · Exec

Sponsorship not specified$160k-$200kDetected 6 days ago
AWSCybersecuritySIEMIncident ResponseComplianceAuditingFirewall5G/LTEHIPAAEHR/EMRLeadershipCommunicationInternal Audit

About the role

  • This is a player-coach role with real hands-on expectation in year one.

Responsibilities

  • Own NexHealth's security governance, compliance, and IT programs end-to-end.
  • Serve as named Information Security Officer and Privacy Officer for SOC 2 and HIPAA - own the policy manual (40+ documents), audit liaison relationship with A-LIGN, control mapping across overlapping regimes, and evidence collection pipelines.
  • Build, hire, and develop the IT and workforce security program: endpoints, identity, SaaS administration, phishing simulations, role-specific training modules, and facilities security.
  • Own vendor security: intake, classification, assessment, BAA execution, ongoing oversight, and customer-facing trust artifacts including Trust Center and subprocessor disclosure.
  • Lead incident response in Officer capacity
  • Own the risk register, risk acceptance decisions, privacy operations (DSARs, data subject rights, privacy complaints), BC/DR plan, and cyber insurance relationship.
  • 8+ years of relevant security experience, including 3+ years in a security leadership role where you were materially building the program, not maintaining it.
  • Has owned a recurring external audit cycle end-to-end (e.g., SOC 2, ISO, PCI, HITRUST) - designed evidence collection, mapped controls, ran the auditor relationship, and made the next cycle materially easier than the last.

Requirements

  • Hands-on experience with security tools and technologies such as SIEM, MDR, IDS/IPS, WAF, DLP, and vulnerability scanners.
  • You can frame risk for a Board-level audience and for an engineering audience in the same week.
  • You've reshaped how a company engages with auditors, regulators, or customer security teams - moved questionnaires to Trust Centers, audits from manual to automated, or vendor reviews from one-off projects to continuous programs.
  • You drive sustained operational change in functions you don't manage.
  • You treat engineering velocity as a security input. Slow shipping creates security risk too.
  • Behavioral Traits
  • First-principles thinker.
  • Writes. NexHealth runs on documents
  • verbal-first operators struggle here.
  • Comfortable being the ranking voice on policy and risk.

Compensation

  • The range listed is just the base salary component of NexHealth's total compensation package for employees.
  • NexHealth Compensation Range
  • $160,000 - $200,000 USD
  • partner with outside counsel on breach determinations, own IR tracking, and run annual tabletop exercises.

Benefits

  • Full Medical, Dental, and Vision (up to 100% covered)
  • 401K and commuter benefits
  • High-impact work that directly improves the healthcare experience for millions

Company info

  • NexHealth is a technology company building infrastructure that's reshaping how patient data moves and how the HealthTech ecosystem connects.
  • It's easy to make decisions that make our lives simpler, but not the customers.

This listing is sourced directly from NexHealth's careers page and normalized into a canonical job model.