Stedi

Stedi

Head of Security

Remote in the USA · Exec

Sponsorship not specifiedDetected 83 days ago
AWSCybersecurityIncident ResponseComplianceHIPAALeadershipCommunication

About the role

  • Clearinghouses process the majority of these transactions, offering consolidated connectivity to carriers and providers.
  • Until Stedi, the space was occupied entirely by a small group of legacy players, built on outdated, often pre-internet technology.
  • Stedi is the world's only programmable healthcare clearinghouse.

Responsibilities

  • Own and build Stedi's security program end-to-end, including policies, controls, procedures, security tooling, training, vulnerability management, vendor risk, and more.
  • Be a strong hands-on contributor from day 1 while also building a roadmap for scaling the security function as the company continues to grow. We have a culture where leaders are contributors and are deeply involved in the technical details.
  • Partner with Engineering to maintain security excellence while minimizing development friction.
  • Lead breach preparedness and incident response: build, test, and own the Security Incident Response Plan, Disaster Recovery, and Business Continuity programs so Stedi can detect, contain, and recover rapidly in the unlikely event of a significant issue.
  • Represent Stedi in conversations with customer and partner security leadership teams, and provide clear, regular reporting on security posture and risk to the executive team and board.
  • Partner with Legal on regulatory obligations, breach notification requirements, and the legal dimensions of security incidents - be ready to engage directly with regulators should the need ever arise.
  • Build mechanisms for continuous security improvement, and establish practical, role-appropriate security training across the company.
  • You'll inherit a strong foundation to scale in our next phase of growth - building out the team, programs, and processes that let a lean company move fast while maintaining a world-class security posture.
  • You're excited to use automation and modern tooling to eliminate toil and raise the bar, not to build bureaucracy.

Nice to have

  • Significant experience owning security programs in cloud-native environments.
  • Deep technical ability in the security domain and enough working knowledge to have high-bandwidth discussions with application engineers.
  • Strong legal and regulatory instincts - you have the ability to understand legal issues and can speak credibly with regulators
  • Opinionated but pragmatic, with strong judgment about where rigor matters most and a bias toward solutions over problems.

Benefits

  • Stedi is building the first new healthcare clearinghouse in decades.
  • By offering modern API interfaces alongside traditional real-time and batch EDI processes, we enable both healthcare technology businesses and established players to exchange mission-critical transactions.
  • healthcare or HIPAA experience is a strong plus.

Company info

  • engineers and designers shipping products week in and week out; a lean business team supporting the company's infrastructure; passion for automation and eliminating toil; $142 million in funding from top investors like Stripe, Addition, USV, Bloomberg Beta, First Round Capital, and more.
  • To learn more about how we work, watch our founder Zack's interview with First Round Capital https://www.youtube.com/watch?v=IO6sR-i5rSs.
  • Leverage our best-in-category security posture to unlock new customers and strategic relationships.

This listing is sourced directly from Stedi's careers page and normalized into a canonical job model.