stedi - Head of Security
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT
Requirements
• We are hiring a Head of Security to take full ownership of security at Stedi, reporting directly to the CEO and working at the intersection of engineering, legal, product, and more. • At Stedi, security is job zero. There is nothing more important than securing our systems. This role exists to operationalize that principle across every function of the company. • You won’t be building from scratch. We already have SOC 2 Type 2 and HIPAA certifications and will soon have HITRUST R2 certification. We view these compliance items as a baseline starting point and not the final destination. We have invested heavily in security from the earliest days. We have extensive controls across our engineering and IT infrastructure (from SCPs to DLP and everything in between), and 100% of our customer data is processed within AWS without exception. We work extensively with AWS’s native tools as well as with AWS teams, including on an IAM access vulnerability that we discovered https://www.stedi.com/blog/stedi-discovered-an-aws-access-vulnerability. • You will own our security function end-to-end: incident readiness, regulatory obligations, customer trust, and the day-to-day fundamentals that enable everything else. You will be the bridge between engineering and legal, working closely with leadership from both teams and the CEO. You’ll inherit a strong foundation to scale in our next phase of growth – building out the team, programs, and processes that let a lean company move fast while maintaining a world-class security posture. • Significant experience owning security programs in cloud-native environments. • Deep technical ability in the security domain and enough working knowledge to have high-bandwidth discussions with application engineers. • Strong legal and regulatory instincts – you have the ability to understand legal issues and can speak credibly with regulators; healthcare or HIPAA experience is a strong plus. • Opinionated but pragmatic, with strong judgment about where rigor matters most and a bias toward solutions over problems. • Exceptional communicator: you can explain security risk clearly to engineers, executives, customers, and regulators, in writing and in person. • You’re excited to use automation and modern tooling to eliminate toil and raise the bar, not to build bureaucracy. • We’ve been made aware of individuals impersonating the Stedi recruiting team. Please note: • All official communication about roles at Stedi will only come from an @stedi.com http://stedi.com email address, or from our official identification verification partner, Persona, @frompersona.com http://frompersona.com. • If you’re unsure whether a message is legitimate or have any concerns, feel free to contact us directly at [email protected]. • We appreciate your attention to this and your interest in joining Stedi. • At Stedi, we're looking for people who are deeply curious and aligned to our ways of working. You're encouraged to apply even if your experience doesn't perfectly match the job description.
Responsibilities
• Own and build Stedi's security program end-to-end, including policies, controls, procedures, security tooling, training, vulnerability management, vendor risk, and more. • Be a strong hands-on contributor from day 1 while also building a roadmap for scaling the security function as the company continues to grow. We have a culture where leaders are contributors and are deeply involved in the technical details. • Advise on security risk tied to product decisions, architecture, and partnerships. • Leverage our best-in-category security posture to unlock new customers and strategic relationships. • Partner with Engineering to maintain security excellence while minimizing development friction. • Lead breach preparedness and incident response: build, test, and own the Security Incident Response Plan, Disaster Recovery, and Business Continuity programs so Stedi can detect, contain, and recover rapidly in the unlikely event of a significant issue. • Represent Stedi in conversations with customer and partner security leadership teams, and provide clear, regular reporting on security posture and risk to the executive team and board. • Partner with Legal on regulatory obligations, breach notification requirements, and the legal dimensions of security incidents - be ready to engage directly with regulators should the need ever arise. • Build mechanisms for continuous security improvement, and establish practical, role-appropriate security training across the company.
No credit card. Takes 10 seconds.