wagey.ggwagey.gg
31,365  jobs31,365  jobs
Browse Tech JobsCompaniesFeaturesPricingFAQs
Log InGet Started Free
Jobs(31,365)/CISO Role(54)/Redox (1) - Director of IT & Security, CISO
Redox

Redox - Director of IT & Security, CISO

Remote - USA$224k - $260k+ Equity5mo ago
RemoteC-levelNACybersecurityCloud ComputingCISOCTODirector of SecurityAWSTeam LeadershipRisk ManagementVendor ManagementGovernance

Requirements

• Security Strategy & Leadership:  Own end-to-end information security strategy across cloud, application, infrastructure, and corporate environments. Define a pragmatic security roadmap aligned to business risk, regulatory requirements, and engineering velocity. Serve as the executive owner for security posture, risk management, and incident response. Act as a trusted advisor to the CTO and executive team on security, risk, and operational tradeoffs. • Security Engineering & DevSecOps: Drive a DevSecOps-first operating model, embedding security into CI/CD pipelines, infrastructure as code, and developer workflows. Partner deeply with engineering leadership to make security scalable, automated, and measurable. Lead threat modeling, secure design reviews, and risk assessments for new platform initiatives. Champion policy-as-code, guardrails, and automation over manual process. • Cloud, Application & Infrastructure Security: Own security architecture and operations for a primarily AWS-based environment. Lead application security programs, including secure SDLC, dependency scanning, SAST/DAST, penetration testing, and vulnerability management. Own identity and access management strategy with Okta as the backbone. Ensure strong detection, alerting, and response across endpoints and cloud workloads (e.g., CrowdStrike, RAD). • Security Operations & Incident Response:  Build and run effective security operations, including monitoring, investigation, incident response, and post-incident learning. Lead incident response for both security and IT incidents, serving as the calm point of accountability. Run tabletop exercises and continuously improve response playbooks. Manage vendor relationships, including CrowdStrike, Flashpoint, RAD, and Okta. • Corporate IT & Enterprise Systems: Own corporate IT strategy and execution, focused on reliability, security, and employee productivity. Lead end-user computing, device management, endpoint security, identity lifecycle management, and access controls. Oversee IT systems, including identity, email, collaboration tools, endpoint management, and SaaS access governance. Drive automation and standardization across onboarding, offboarding, access management, and device lifecycle. Partner with People Ops, Legal, and Finance on IT processes, audits, and vendor management. • Compliance, Risk & Healthcare Context: Own healthcare-related security and compliance programs (e.g., HIPAA, SOC 2). Translate regulatory requirements into practical, engineering-friendly controls. Lead third-party risk management and vendor security reviews. Support customer security reviews and serve as an executive point of contact on security matters. • Team Leadership & Culture: Build, lead, and mentor a high-performing team spanning security engineering, security operations, and IT. Create a culture where security and IT are seen as enablers, not blockers. Establish clear ownership, measurable outcomes, and high operational standards. Be visible, decisive, and calm under pressure. • 10+ years in information security, IT, or related technical leadership roles, including 5+ years of people management, ideally in healthcare technology SaaS. • Proven experience leading security engineering, security operations, and corporate IT in a cloud-native SaaS environment. • Direct experience in healthcare or other highly regulated industries. • Track record of successfully implementing DevSecOps practices. • Deep hands-on experience securing AWS environments. • Strong understanding of endpoint security, identity systems, and modern SaaS IT stacks. • Practical knowledge of tools such as CrowdStrike, Okta, Flashpoint, RAD, and related platforms. • Strong foundation in application security, cloud security, and infrastructure as code. • Strong collaborator with engineering, platform, and operations teams. • Clear, direct communicator who can articulate risk without theatrics. • Comfortable making tradeoffs and prioritizing based on real-world risk. • Builder mindset with a bias toward automation and scale. • Proven experience securing autonomous agentic loops and tool-calling frameworks. Deep understanding of Indirect Prompt Injection and designing "Human-in-the-Loop" guardrails for agent-driven actions. • Technical expertise in securing the Model Context Protocol (MCP), specifically regarding context isolation, sandboxing, and identity propagation between LLMs and private data sources. • Direct experience migrating security programs to Vanta or similar automated GRC platforms. Ability to architect "continuous compliance" by integrating cloud, identity, and developer tools for automated evidence collection. • Hands-on application of the NIST AI RMF, OWASP Top 10 for LLMs, etc within a production environment. • Required: Crowdstrike, AWS, Okta • Preferred: Vanta

Responsibilities

• Security Strategy & Leadership: Own end-to-end information security strategy across cloud, application, infrastructure, and corporate environments. Define a pragmatic security roadmap aligned to business risk, regulatory requirements, and engineering velocity. Serve as the executive owner for security posture, risk management, and incident response. Act as a trusted advisor to the CTO and executive team on security, risk, and operational tradeoffs. • Security Engineering & DevSecOps: Drive a DevSecOps-first operating model, embedding security into CI/CD pipelines, infrastructure as code, and developer workflows. Partner deeply with engineering leadership to make security scalable, automated, and measurable. Lead threat modeling, secure design reviews, and risk assessments for new platform initiatives. Champion policy-as-code, guardrails, and automation over manual process. • Cloud, Application & Infrastructure Security: Own security architecture and operations for a primarily AWS-based environment. Lead application security programs, including secure SDLC, dependency scanning, SAST/DAST, penetration testing, and vulnerability management. Own identity and access management strategy with Okta as the backbone. Ensure strong detection, alerting, and response across endpoints and cloud workloads (e.g., CrowdStrike, RAD). • Security Operations & Incident Response: Build and run effective security operations, including monitoring, investigation, incident response, and post-incident learning. Lead incident response for both security and IT incidents, serving as the calm point of accountability. Run tabletop exercises and continuously improve response playbooks. Manage vendor relationships, including CrowdStrike, Flashpoint, RAD, and Okta. • Corporate IT & Enterprise Systems: Own corporate IT strategy and execution, focused on reliability, security, and employee productivity. Lead end-user computing, device management, endpoint security, identity lifecycle management, and access controls. Oversee IT systems, including identity, email, collaboration tools, endpoint management, and SaaS access governance. Drive automation and standardization across onboarding, offboarding, access management, and device lifecycle. Partner with People Ops, Legal, and Finance on IT processes, audits, and vendor management. • Compliance, Risk & Healthcare Context: Own healthcare-related security and compliance programs (e.g., HIPAA, SOC 2). Translate regulatory requirements into practical, engineering-friendly controls. Lead third-party risk management and vendor security reviews. Support customer security reviews and serve as an executive point of contact on security matters. • Team Leadership & Culture: Build, lead, and mentor a high-performing team spanning security engineering, security operations, and IT. Create a culture where security and IT are seen as enablers, not blockers. Establish clear ownership, measurable outcomes, and high operational standards. Be visible, decisive, and calm under pressure.

Benefits

• 100% remote first culture (must be based in the US) • Unlimited Flexible Time Off • 15+ Observed Holidays • Rest & R^Charge days (guaranteed a 3-day weekend each month) • R^Charge (6 weeks paid sabbatical + stipend) • 401k match 50% for up to 8% on Day 1 • Medical/Dental/Vision Benefits on Day 1 • HSA & FSA, Life, Disability, Medical Travel & Employee Assistance Program • Paid Parental Leave (16 weeks) • Productivity Stipend & Wellness Fund • Redox Issued MacBook • Virtual and/or in-person Team & Company Events • Stock Options • Employee Referral Bonus Program • Please keep reading... • Research shows that while men apply to jobs when they meet an average of 60% of the criteria, women and other marginalized folks tend to only apply when they check every box. So if you think you have what it takes, but don't necessarily meet every single point on the job description, please still get in touch. We'd love to have a chat and see if you could be a great fit. https://hbr.org/2014/08/why-women-dont-apply-for-jobs-unless-theyre-100-qualified

Apply in one click

Upload My Resume

Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT

Apply in One Click
Apply in One Click

Similar roles

payscalepayscale - Director, Security Engineering & Operations3w ago
·Remote - Canada
RemoteNADirectorCybersecurityCloud ComputingDirector of SecurityCISOPerformance ManagementReportingAWSBashPythonCloudflareAnsibleCoachingFiberPerformance Reviews
VaricentVaricent - Director, Security Architecture & Threat Modeling3w ago
·Toronto, Canada - Hybrid·$138k - $181k/year
In OfficeNADirectorCybersecurityCloud ComputingDirector of SecurityTraining DevelopmentIBM CloudAWSAzureRisk ManagementCircomGovernanceCPCDocumentationKubernetesDecision Making
Clover HealthClover Health - Director, Governance, Risk, and Compliance (GRC)4mo ago
·Remote - USA·$212k - $212k/year + Equity
RemoteNADirectorHealthcareCybersecurityCISOCompliance ManagerRisk ManagementGovernanceDocumentationProduct MarketingVendor Management
LavendoLavendo - Field CTO5mo ago
·Remote - San Francisco, California, United States·$295k - $365k/year + Equity
RemoteNAC-levelCloud ComputingGamingCTOKubernetesGoTeam Leadership
Tribe AITribe AI - Forward Deployed CTO1mo ago
·United States·$300k - $450k/year + Equity
In OfficeNAC-levelFintechArtificial IntelligenceLogisticsCTOAccount ManagementClient ConsultingRisk ManagementTeam LeadershipVector
Defense UnicornsDefense Unicorns - Chief Information Security Officer2mo ago
·Hybrid - USA *·$260k - $260k/year + Equity
In OfficeNAC-levelCybersecuritySoftwareCISOChief Privacy OfficerGovernanceReportingTeam ManagementIntellectual PropertyRisk Management
Nimble GravityNimble Gravity - CTO, Data Platforms2w ago
·USA (Remote) - Hybrid
In OfficeNAC-levelCloud ComputingData AnalyticsCTODatabricksAzureAirflowdbtSynapseGovernanceMLflowCross-functional Collaboration
LatamCentLatamCent - IT & Compliance Specialist1mo ago
·Remote - USA·$48k - $66k/year + Equity
RemoteNAMidCybersecurityCloud ComputingCompliance ManagerIT Support SpecialistCTODocumentationTeam LeadershipLinuxAWSPython
Sonrai SecuritySonrai Security - Sonrai Security3mo ago
·Philadelphia, PA
In OfficeNASeniorCybersecurityCloud ComputingSales EngineerDirector of SecurityAmbassadorProduct MarketingAzureGCPGovernanceAWS

Browse more by category

Show 54 moreCISOShow 207 moreCTOShow 80 moreDirector of SecurityShow 3,040 moreAWSShow 2,313 moreTeam LeadershipShow 846 moreRisk ManagementShow 280 moreVendor ManagementShow 1,759 moreGovernance
Privacy·Terms··Contact·FAQ·Wagey on X