Head of IT & Security at NexHealth | CA, US | Rezi

Head of IT & Security at NexHealth

Head of IT & Security

NexHealth · CA, US

1 months ago

Head of IT & Security

NexHealth · CA, US

a month ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now
Resume preview

Tailor your resume to this Head of IT & Security role.

Rezi rewrites your resume against NexHealth's job description. Free.

Resume score gauge reading 58 out of 100

Don't guess if your resume is good enough.

See how it scores against the Head of IT & Security posting at NexHealth — free, in seconds.

About the Role

NexHealth is seeking a Security Lead to establish and own security governance, compliance, IT operations, vendor security, and incident response. This player-coach role requires hands-on involvement in driving the security and compliance program and building a team.

Responsibilities

  • Own NexHealth's security governance, compliance, and IT programs end-to-end.
  • Serve as named Information Security Officer and Privacy Officer for SOC 2 and HIPAA.
  • Own the policy manual (40+ documents), act as audit liaison with A-LIGN, manage control mapping, and oversee evidence collection pipelines.
  • Set security standards for application security, vulnerability management, cloud security (AWS), audit logging, and access controls.
  • Drive the technical security program through Engineering via influence.
  • Build, hire, and develop the IT and workforce security program, including endpoints, identity, SaaS administration, phishing simulations, training modules, and facilities security.
  • Own vendor security, including intake, classification, assessment, BAA execution, oversight, and customer-facing trust artifacts.
  • Lead incident response in an Officer capacity, partner with outside counsel on breach determinations, own IR tracking, and run annual tabletop exercises.
  • Own the risk register, risk acceptance decisions, privacy operations, BC/DR plan, and cyber insurance relationship.
  • Hire a Staff-level IT IC within year one and grow the function.

Requirements

  • 8+ years of relevant security experience, with at least 3 years in a security leadership role building a program.
  • Experience building a security program from a near-zero baseline.
  • Experience owning a recurring external audit cycle end-to-end (e.g., SOC 2, ISO, PCI, HITRUST).
  • Software engineering background with the ability to evaluate code and cloud configurations.
  • Experience hiring and developing senior security or IT individual contributors.
  • Hands-on experience with security tools and technologies such as SIEM, MDR, IDS/IPS, WAF, DLP, and vulnerability scanners.
  • Experience reshaping how a company engages with auditors, regulators, or customer security teams.
  • Ability to drive sustained operational change in functions not directly managed.
  • Understanding that engineering velocity is a security input.
  • Ability to frame risk for both Board-level and engineering audiences.
  • First-principles thinker.
  • Strong written communication skills.
  • Comfortable being the ranking voice on policy and risk.

Skills

  • Security Governance
  • Compliance
  • IT Operations
  • Vendor Security
  • Incident Response
  • SOC 2
  • HIPAA
  • Application Security
  • Vulnerability Management
  • Cloud Security (AWS)
  • Access Controls
  • Endpoint Security
  • Identity Management
  • SaaS Administration
  • Phishing Simulations
  • Risk Management
  • Privacy Operations
  • Business Continuity/Disaster Recovery (BC/DR)
  • SIEM
  • MDR
  • IDS/IPS
  • WAF
  • DLP
  • Vulnerability Scanners

Location

  • San Francisco, CA

Work Type

  • Full-time

Experience Level

  • Leadership
  • Senior

Salary/Compensations

  • $160,000—$200,000 USD

Benefits

  • Stock options
  • Unlimited paid time off policy
  • Up to 100% coverage on medical, vision and dental insurance
  • 401K and commuter benefits
  • Flexible PTO
  • High-impact work that directly improves the healthcare experience for millions

About the Company

  • NexHealth's mission is to accelerate innovation in healthcare by connecting patients, providers, and developers.
  • We're building the infrastructure layer for modern healthcare, connecting thousands of fragmented, on-premise, and closed EHR systems into a single, modern platform.
  • Founded: 2017
  • Headquarters: San Francisco, CA
  • Funding: $177M Series C
  • Employees: 200+
  • Trusted by tens of thousands of providers and hundreds of health-tech developers.

Equal Opportunity

  • We are an equal opportunity employer and value diversity at our company.
  • We do not discriminate on the basis of race, religion, color, national origin, sex, gender expression, sexual orientation, age, marital status, veteran status, or disability status.
  • We provide reasonable accommodation for individuals with disabilities to participate in the application or interview process.
  • Contact talent@nexhealth.com to request assistance.