Impress employers and recruiters.
Choose from hundreds of resume examples.

Impress employers and recruiters.
Choose from hundreds of resume examples.
Tailor your resume to this Head of IT & Security role.
Rezi rewrites your resume against NexHealth's job description. Free.

Tailor your resume to this Head of IT & Security role.
Rezi rewrites your resume against NexHealth's job description. Free.
Don't guess if your resume is good enough.
See how it scores against the Head of IT & Security posting at NexHealth — free, in seconds.

Don't guess if your resume is good enough.
See how it scores against the Head of IT & Security posting at NexHealth — free, in seconds.
About the Role
NexHealth is seeking a Security Lead to establish and own security governance, compliance, IT operations, vendor security, and incident response. This player-coach role requires hands-on involvement in driving the security and compliance program and building a team.
Responsibilities
- Own NexHealth's security governance, compliance, and IT programs end-to-end.
- Serve as named Information Security Officer and Privacy Officer for SOC 2 and HIPAA.
- Own the policy manual (40+ documents), act as audit liaison with A-LIGN, manage control mapping, and oversee evidence collection pipelines.
- Set security standards for application security, vulnerability management, cloud security (AWS), audit logging, and access controls.
- Drive the technical security program through Engineering via influence.
- Build, hire, and develop the IT and workforce security program, including endpoints, identity, SaaS administration, phishing simulations, training modules, and facilities security.
- Own vendor security, including intake, classification, assessment, BAA execution, oversight, and customer-facing trust artifacts.
- Lead incident response in an Officer capacity, partner with outside counsel on breach determinations, own IR tracking, and run annual tabletop exercises.
- Own the risk register, risk acceptance decisions, privacy operations, BC/DR plan, and cyber insurance relationship.
- Hire a Staff-level IT IC within year one and grow the function.
Requirements
- 8+ years of relevant security experience, with at least 3 years in a security leadership role building a program.
- Experience building a security program from a near-zero baseline.
- Experience owning a recurring external audit cycle end-to-end (e.g., SOC 2, ISO, PCI, HITRUST).
- Software engineering background with the ability to evaluate code and cloud configurations.
- Experience hiring and developing senior security or IT individual contributors.
- Hands-on experience with security tools and technologies such as SIEM, MDR, IDS/IPS, WAF, DLP, and vulnerability scanners.
- Experience reshaping how a company engages with auditors, regulators, or customer security teams.
- Ability to drive sustained operational change in functions not directly managed.
- Understanding that engineering velocity is a security input.
- Ability to frame risk for both Board-level and engineering audiences.
- First-principles thinker.
- Strong written communication skills.
- Comfortable being the ranking voice on policy and risk.
Skills
- Security Governance
- Compliance
- IT Operations
- Vendor Security
- Incident Response
- SOC 2
- HIPAA
- Application Security
- Vulnerability Management
- Cloud Security (AWS)
- Access Controls
- Endpoint Security
- Identity Management
- SaaS Administration
- Phishing Simulations
- Risk Management
- Privacy Operations
- Business Continuity/Disaster Recovery (BC/DR)
- SIEM
- MDR
- IDS/IPS
- WAF
- DLP
- Vulnerability Scanners
Location
- San Francisco, CA
Work Type
- Full-time
Experience Level
- Leadership
- Senior
Salary/Compensations
- $160,000—$200,000 USD
Benefits
- Stock options
- Unlimited paid time off policy
- Up to 100% coverage on medical, vision and dental insurance
- 401K and commuter benefits
- Flexible PTO
- High-impact work that directly improves the healthcare experience for millions
About the Company
- NexHealth's mission is to accelerate innovation in healthcare by connecting patients, providers, and developers.
- We're building the infrastructure layer for modern healthcare, connecting thousands of fragmented, on-premise, and closed EHR systems into a single, modern platform.
- Founded: 2017
- Headquarters: San Francisco, CA
- Funding: $177M Series C
- Employees: 200+
- Trusted by tens of thousands of providers and hundreds of health-tech developers.
Equal Opportunity
- We are an equal opportunity employer and value diversity at our company.
- We do not discriminate on the basis of race, religion, color, national origin, sex, gender expression, sexual orientation, age, marital status, veteran status, or disability status.
- We provide reasonable accommodation for individuals with disabilities to participate in the application or interview process.
- Contact talent@nexhealth.com to request assistance.