Stedi
Head of Security
Remote in the USA · Exec
Sponsorship not specifiedDetected 83 days ago
AWSCybersecurityIncident ResponseComplianceHIPAALeadershipCommunication
About the role
- Clearinghouses process the majority of these transactions, offering consolidated connectivity to carriers and providers.
- Until Stedi, the space was occupied entirely by a small group of legacy players, built on outdated, often pre-internet technology.
- Stedi is the world's only programmable healthcare clearinghouse.
Responsibilities
- Own and build Stedi's security program end-to-end, including policies, controls, procedures, security tooling, training, vulnerability management, vendor risk, and more.
- Be a strong hands-on contributor from day 1 while also building a roadmap for scaling the security function as the company continues to grow. We have a culture where leaders are contributors and are deeply involved in the technical details.
- Partner with Engineering to maintain security excellence while minimizing development friction.
- Lead breach preparedness and incident response: build, test, and own the Security Incident Response Plan, Disaster Recovery, and Business Continuity programs so Stedi can detect, contain, and recover rapidly in the unlikely event of a significant issue.
- Represent Stedi in conversations with customer and partner security leadership teams, and provide clear, regular reporting on security posture and risk to the executive team and board.
- Partner with Legal on regulatory obligations, breach notification requirements, and the legal dimensions of security incidents - be ready to engage directly with regulators should the need ever arise.
- Build mechanisms for continuous security improvement, and establish practical, role-appropriate security training across the company.
- You'll inherit a strong foundation to scale in our next phase of growth - building out the team, programs, and processes that let a lean company move fast while maintaining a world-class security posture.
- You're excited to use automation and modern tooling to eliminate toil and raise the bar, not to build bureaucracy.
Nice to have
- Significant experience owning security programs in cloud-native environments.
- Deep technical ability in the security domain and enough working knowledge to have high-bandwidth discussions with application engineers.
- Strong legal and regulatory instincts - you have the ability to understand legal issues and can speak credibly with regulators
- Opinionated but pragmatic, with strong judgment about where rigor matters most and a bias toward solutions over problems.
Benefits
- Stedi is building the first new healthcare clearinghouse in decades.
- By offering modern API interfaces alongside traditional real-time and batch EDI processes, we enable both healthcare technology businesses and established players to exchange mission-critical transactions.
- healthcare or HIPAA experience is a strong plus.
Company info
- engineers and designers shipping products week in and week out; a lean business team supporting the company's infrastructure; passion for automation and eliminating toil; $142 million in funding from top investors like Stripe, Addition, USV, Bloomberg Beta, First Round Capital, and more.
- To learn more about how we work, watch our founder Zack's interview with First Round Capital https://www.youtube.com/watch?v=IO6sR-i5rSs.
- Leverage our best-in-category security posture to unlock new customers and strategic relationships.
This listing is sourced directly from Stedi's careers page and normalized into a canonical job model.