> Markdown version of [/jobs/ext/1250332-information-security-officer-iso](https://www.wearedevelopers.com/jobs/ext/1250332-information-security-officer-iso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Officer (ISO) - **Company:** WOUNDTECH CORP. - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $160,000.0 - $175,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Application Layers, Cloud Computing, Cloud Computing Security, Static Program Analysis, CompTIA Security+, Cyber Security, Continuous Integration, Linux, DevOps, Identity and Access Management, Cloud Services, Security Information and Event Management, Software Vulnerability Management, Data Logging, Software Security, Mttr, SentinelOne Expertise, Devsecops - **Published:** July 12, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=c1d4370f25dcc3fb ## About the Role 5-8+ years of experience in cybersecurity, with both technical and GRC exposure-Hands-on experience with:-Cloud security (AWS preferred)-EDR/XDR platforms (e.g., SentinelOne, CrowdStrike)-SIEM and log management tools-Vulnerability management processes-Experience supporting compliance frameworks such as HIPAA, SOC 2, HITRUST-Strong understanding of:-Networking, Linux systems, and cloud infrastructure-Security operations and incident responsePreferred Qualifications· Experience in healthcare or regulated environments· Familiarity with DevSecOps practices and CI/CD security integration· Certifications such as CISSP, GSEC, Security+, or AWS Security Specialty· Experience working in lean teams where individuals own both strategy and execution ## Description Woundtech is seeking a hands-on Information Security Officer (ISO) to lead and execute our cybersecurity program in a fast-paced, healthcare environment. This role is a hybrid of security leadership and engineering execution, responsible for both Governance, Risk, and Compliance (GRC) and day-to-day security operations.The ideal candidate is equally comfortable defining security policies and leading audits as they are remediating vulnerabilities, tuning security tools, and responding to incidents. This role will partner closely with IT, DevSecOps, and Engineering to drive measurable improvements in security posture. Primary Responsibilities: Security Operations & Engineering (Hands-On Execution) -Monitor, investigate, and respond to security alerts and incidents across: -SentinelOne (EDR/XDR) -SIEM and centralized logging platforms -AWS-native tools (GuardDuty, Inspector, CloudTrail) -Lead vulnerability management lifecycle: -Identify, prioritize, and drive remediation of vulnerabilities and misconfigurations -Partner with Engineering, DevOps, and IT to resolve issues within defined SLAs -Identify and remediate AWS cloud security risks: -IAM, network exposure, logging, encryption, and configuration gaps -Administer and improve security tooling across endpoint, cloud, identity, and application layers -Support DevSecOps initiatives: -Integrate and maintain tools such as container scanning, code analysis, and secrets detection -Develop automation and improve detection and monitoring capabilitiesGovernance, Risk & Compliance (GRC) -Develop, implement, and maintain the enterprise Information Security Program -Lead and execute compliance initiatives: -HIPAA -SOC 2 Type II -HITRUST (or equivalent frameworks) -Conduct enterprise risk assessments and technical security assessments -Establish and maintain security policies, standards, and procedures -Manage third-party/vendor risk assessments and due diligence -Maintain audit readiness, documentation, and evidence collectionCloud, Infrastructure & Application Security -Define and enforce security standards for AWS infrastructure and cloud services -Partner with DevOps to embed security into CI/CD pipelines and engineering workflows -Conduct application and infrastructure security reviews and risk assessments -Ensure proper logging, monitoring, and alerting across all environments Metrics, Reporting & Leadership -Define and track key security metrics: -Vulnerability remediation SLAs -Incident response metrics (MTTD, MTTR) -Coverage (EDR, logging, scanning) -Provide regular updates to leadership on security posture, risks, and progress -Promote a strong security awareness culture across the organization ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [What Developers Get Wrong About Application Quality](https://www.wearedevelopers.com/videos/233-what-developers-get-wrong-about-application-quality) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [#90DaysOfDevOps - The DevOps Learning Journey](https://www.wearedevelopers.com/videos/548-90daysofdevops-the-devops-learning-journey) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)