Director, Security and Trust - Remote
Who We Are At Elemy:
Elemy is a tech-forward provider of pediatric therapy across the United States. We believe that families, clinicians, and insurers all deserve a better healthcare experience, so we built one.
Backed by General Catalyst, Felicis Ventures, Founders Fund, & others. Our mission is to provide personalized, technology-empowered care for children with autism in the environment best suited to help them grow and thrive — the home. We’re looking to rapidly grow our team with values-driven, diverse, caring professionals to help us improve autism care. .
About The Role:
The Elemy Security and Trust team is committed to achieving and maintaining the trust of our customers. Integral to this mission is providing a robust security and compliance program that carefully considers data protection matters across all our products and offerings, including the data submitted by customers, partners, and employees to our services. Our business is built on trust and security and making sure all our customers trust us to offer great autism care while safeguarding all of their data.
In cloud first environments we have to assume that the perimeter is fluid, and we cannot assume safety. At Elemy we are embracing a modern Zero Trust posture where we continuously want to assess and identify that the right people have the right level of access to the right resources in the right context with the least performance impact and least friction for all involved.
Do you have a passion for SaaS and cloud security? Are you skilled at detecting attackers and protecting cloud infrastructures and SaaS applications? We at Elemy need a Director to organize, lead, and manage our security engineering and operations team and help us protect our company and our customers.
In this role you will bring your leadership and technical expertise to develop, own, manage, and improve the technical security controls that protect our infrastructure, products, services, and data. This role blends security leadership, engineering and analytical skills. We need you to help design, specify, deploy and operate the solutions that protect our products from attack as well as detect and respond to alerts warning of possible anomalous behavior or vulnerabilities in our systems. You will be responsible for improving our information security operations program, including working with other engineering teams to integrate security monitoring into their flows and processes.
You must be comfortable working with cloud technologies and how to best leverage the security features provided by our cloud service provider or by choosing our own. You must lead by example and have experience leading high performing teams.
In this role, you will be working with management, technical leaders and engineers, compliance director, external auditors, and at times, directly with our customers and partners.
- Technical Fluency - A passion for cybersecurity and technology, familiarity with infrastructure as software, container and microservices architectures.
- Advisory Skills - Giving direction, advice and support that helps grow the technical and collaboration skills of the individuals and teams with which they engage.
- Execution - Planning, coordination, managing dependencies and risks, diving deep when issues arise.
- Communications - This role requires someone who has strong both written and verbal skills, given the sheer number and diversity of touchpoints you will be interacting with.
- Provide leadership, guidance, and management of the Elemy Security Engineering and Operations team. Create and implement programs that develop the skills of our existing engineers and attract new talent as Elemy grows.
- Help design and evolve the security operations program to continuously improve Elemy’s ability to effectively detect and respond to new threats. Partnering with engineering teams to design, build, select and implement effective technical security controls to detect and alert on security events across the Elemy infrastructure and protect the Elemy platform and customers.
- Providing security technical leadership to set requirements and help other teams understand and meet their security obligations to make good risk-based decisions.
- At least initially, while the team is in its formative stages, writing code where needed to automate controls and to deploy new security capabilities.
- Identifying gaps in coverage of the Elemy security controls and working across teams to specify and deploy improvements that address these gaps.
- Selecting and/or creating specific applications and functions that integrate with the Elemy platform and build systems that provide the right detective controls that alert on suspicious or anomalous behaviors or vulnerabilities.
- Participating in and helping lead information security response activities across Elemy and its products.
- Developing and implementing solutions to collect, transport, and process security data to support risk-based decision making.
- Integrating security monitoring and measurements that enable engineering teams to quickly spot potential problems and respond to security events within their DevOps processes.
- Scheduling and interpreting the results of penetration test results and other technical audits and working across teams to champion and implement reasonable mitigations and remediations.
- Using DevOps tooling and processes to implement security remediations.
- Creating data flow diagrams and threat models that guide design recommendations.
- Translating security requirements and obligations into effective security controls.
- Providing security subject matter expertise and training to teams across the company.
- Ensuring cross company support for all aspects of security by establishing partnerships with other Elemy teams with the overarching goal of improving trust of Elemy and its products.
Qualifications & experience
- A minimum of 8 years of experience in a cloud security and information security engineering role. Specifically:
- 8+ years of information security, and information technology experience
- 3+ years managing technical teams
- 4+ years in a technical leadership role.
- 3+ years in an engineering role designing and supporting public clouds such as AWS, GCP, or Azure.
- Experience with public cloud security architecture and solutions including but not limited to Network security, segmentation, micro-segmentation strategy, design, and implementation
- Understanding and delivery experience with leading security frameworks (i.e., National Institute of Standards and Technology (NIST) Cybersecurity (CSF), Zero Trust, etc.)
- Experience with design, implementation, configuration, and integration of security products from vendors such as Palo Alto Networks, ZScaler, Crowdstrike, Google BeyondCorp, Microsoft, Cisco, Fortinet, Okta, VMWare, Illumio, Guardicore, Hashicorp, cloud SIEMs like Sumo Logic or Splunk is a definite plus.
- Experience creating, implementing, and managing technical information security controls including developing or leading security incident response processes and teams.
- Cybersecurity related certifications (e.g., GSEC, GCIH, CEH, GCIA, CISSP or CISM) are a plus
- Deep understanding as well as working knowledge of NIST 800-171 and the Cybersecurity Maturity Model Certification and of other security frameworks and processes - CIS, NIST, PCI/DSS, etc.
- Familiarity and experience with other compliance frameworks such as FedRAMP, FISMA, SOC, ISO, HIPAA, HITRUST, and GDPR/CCPA/Privacy Shield
- Depth of experience with multiple security technologies such as Firewalls, Intrusion Detection/Prevention Systems, Vulnerability Scanning, WAF, Wireless LAN, NAC, DLP, DDoS Mitigation, WAN security, CASB, SIEM, Content Filtering, Cloud Security gateways, Secure Proxies, SSL crypto solutions, and automation.
- Demonstrated capability to design, deploy, operationalize and automate secure and highly scalable enterprise systems on public cloud - AWS, Azure or Google Cloud.
- Experience with secure software development, data protection, cryptography, key management, identity and access management (IAM), network security (VPNs) within cloud environments.
- Understanding of authentication, federation and authorization frameworks and protocols, e.g. OAuth/OpenID/SAML 20.0/FIDO and commercial offerings such as Okta or Azure AD.
- Experience supporting engineers building applications and security tooling using primary AWS services such as: VPC, EC2, ELB/ALB, RDS, Route53, S3, Lambda and IAM a definite plus.
- Good working knowledge of other AWS services such as: CloudTrail, CloudWatch, GuardDuty, Inspector, AWS Certificate Manager, AWS WAF & Shield, Key Management Service (KMS), VPC Flow Logs, Macie is a definite plus.
- Experience with container technology security is a definite plus (Docker, Kubernetes, etc.).
- Experience conducting cloud infrastructure security assessments.
- Automation knowledge (Python, Golang, and bash scripting) & experience in hardening Linux, Windows, and/or Mac systems.
- Knowledge and experience of vulnerability scanning tools (Qualys, Nessus).
- Experience in architecting and developing security solutions on one or more cloud platforms (at a minimum AWS and/or GCP proficiency) and applying the cloud native security services.
- Experience automating AWS services to support information security goals and missions.
- Direct experience working with SaaS cloud based applications in AWS or Azure.
- Experience defining and implementing security controls for containers, microservices, and orchestration software is also a plus.
- Experience identifying and collecting the data that supports effective security dashboards that summarize the security health of the environment across multiple security domains (e.g., networking, host, application, identity, etc.). Reinforce a culture of data-driven decision making.
- Have a history of successful cross-organizational efforts.
At Elemy, we are a globally distributed team with many of our team members located throughout the world, including in the following cities: San Francisco, New York, Los Angeles, Miami, Toronto, Montreal, and Kyiv. While everyone currently works remotely, we envision a future that balances face to face collaboration with a remote friendly environment.
Explore more Cyber Security career opportunities
Find open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Analysis, Cryptography, Digital Forensics and Cybersecurity in general, filtered by job title or popular skill, toolset and products used.
- Open Cyber Security Engineer jobs
- Open Staff Application Security Engineer jobs
- Open Penetration Tester jobs
- Open Senior DevSecOps Engineer jobs
- Open Application Security Engineer/Architect jobs
- Open Senior Security Operations Engineer jobs
- Open Cyber Threat Intelligence Analyst jobs
- Open Lead Security Engineer jobs
- Open Senior Information Security Engineer jobs
- Open SOC Analyst jobs
- Open Cyber Security Analyst jobs
- Open Staff Security Engineer jobs
- Open Cybersecurity Engineer jobs
- Open Information System Security Officer (ISSO) jobs
- Open Vulnerability Analyst jobs
- Open Sr. Security Engineer jobs
- Open Senior Penetration Tester jobs
- Open Security Officer 3 jobs
- Open Offensive Security Engineer jobs
- Open Senior Threat Intelligence Analyst jobs
- Open Cloud Security Automation Specialist jobs
- Open Information Security Officer jobs
- Open Azure Security Engineer jobs
- Open Head of Information Security jobs
- Open Senior Information Security Analyst jobs
- Open DevOps-related jobs
- Open Analytics-related jobs
- Open Audits-related jobs
- Open Application security-related jobs
- Open PCI-related jobs
- Open OWASP-related jobs
- Open Threat intelligence-related jobs
- Open Clearance-related jobs
- Open Security assessments-related jobs
- Open IDS-related jobs
- Open Forensics-related jobs
- Open Ruby-related jobs
- Open Splunk-related jobs
- Open Encryption-related jobs
- Open CEH-related jobs
- Open Open Source-related jobs
- Open CISM-related jobs
- Open GDPR-related jobs
- Open Agile-related jobs
- Open Threat detection-related jobs
- Open OSCP-related jobs
- Open Machine Learning-related jobs
- Open Intrusion detection-related jobs
- Open Docker-related jobs