> Markdown version of [/jobs/ext/278667-head-of-it-security](https://www.wearedevelopers.com/jobs/ext/278667-head-of-it-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Head of IT & Security - **Company:** Accord Medical Management, LP - **Location:** Seattle, WA, United States - **Experience:** Expert - **Salary:** $175,000.0 - $220,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Audit Trail, Software as a Service, Cloud Computing Security, Cyber Security, Information Technology Operations, Intrusion Detection Systems, Phishing, Security Information and Event Management, Software Engineering, Software Vulnerability Management, Software Security, Vulnerability Analysis - **Published:** May 17, 2026 - **Apply:** https://www.careerjet.com/jobad/us66df0aee33838735bc89f5aee624150d ## About the Role * 8+ years of relevant security experience, including 3+ years in a security leadership role where you were materially building the program, not maintaining it. * Has built (not inherited) a security program from a near-zero baseline at least once. * Has owned a recurring external audit cycle end-to-end (e.g., SOC 2, ISO, PCI, HITRUST) - designed evidence collection, mapped controls, ran the auditor relationship, and made the next cycle materially easier than the last. * Software engineering background. Can read a pull request, evaluate cloud configurations, and push back on Engineering with technical substance. * Experience hiring and developing senior security or IT individual contributors., * Hands-on experience with security tools and technologies such as SIEM, MDR, IDS/IPS, WAF, DLP, and vulnerability scanners. * You've reshaped how a company engages with auditors, regulators, or customer security teams - moved questionnaires to Trust Centers, audits from manual to automated, or vendor reviews from one-off projects to continuous programs. * You drive sustained operational change in functions you don't manage. * You treat engineering velocity as a security input. Slow shipping creates security risk too. * You can frame risk for a Board-level audience and for an engineering audience in the same week. Behavioral Traits * First-principles thinker. * Writes. NexHealth runs on documents; verbal-first operators struggle here. * Comfortable being the ranking voice on policy and risk. ## Description NexHealth is a technology company building infrastructure that's reshaping how patient data moves and how the HealthTech ecosystem connects. We're looking for a Security Lead to own our security governance, compliance, IT operations, vendor security, and incident response - establishing the function, embedding strong practices, and partnering closely with engineering, legal, and leadership. This is a player-coach role with real hands-on expectation in year one. You'll drive the next phase of our security and compliance program, and build your team. What You'll Do * Own NexHealth's security governance, compliance, and IT programs end-to-end. * Serve as named Information Security Officer and Privacy Officer for SOC 2 and HIPAA - own the policy manual (40+ documents), audit liaison relationship with A-LIGN, control mapping across overlapping regimes, and evidence collection pipelines. * Set security standards across application security, vulnerability management, cloud security (AWS), audit logging, and access controls - driving the technical program through Engineering via influence, not direct authority. * Build, hire, and develop the IT and workforce security program: endpoints, identity, SaaS administration, phishing simulations, role-specific training modules, and facilities security. * Own vendor security: intake, classification, assessment, BAA execution, ongoing oversight, and customer-facing trust artifacts including Trust Center and subprocessor disclosure. * Lead incident response in Officer capacity; partner with outside counsel on breach determinations, own IR tracking, and run annual tabletop exercises. * Own the risk register, risk acceptance decisions, privacy operations (DSARs, data subject rights, privacy complaints), BC/DR plan, and cyber insurance relationship. * Hire a Staff-level IT IC within year one and grow the function from there., When making decisions, think from the perspective of the customer. It's easy to make decisions that make our lives simpler, but not the customers. * Do the things others are not willing to do As a Nexer, always go after the hardest problems. Pursue things at the highest quality. Move at the fastest pace. * Take ownership Act like a founder. Own your roles, destinies, mistakes, behavior, and our mission. The buck stops with each of us - no blaming or excuses. * Say what's on your mind, with positive intent Be direct, proactive, transparent, and frequent in your communication. * Default trust As a Nexer, you do not have to earn trust, trust is given to you by default. If we by default trust each other, our speed of communication, feedback, information sharing, and overall improvements will be a lot faster. * Think in first principles We first identify the problem and then break it down to its fundamentals before diving into solutions. We constantly ask "why" to validate our assumptions. We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, sex, gender expression, sexual orientation, age, marital status, veteran status, or disability status. We provide reasonable accommodation for individuals with disabilities to participate in the application or interview process. Contact talent@nexhealth.com to request assistance. Create a Job Alert Interested in building your career at NexHealth? Get future opportunities sent straight to your email. Create alert, Description The Manager acts as a liaison between patients and families, department staff, physicians and the healthcare team, community agencies, managed care representatives, s… + 6 days ago ## Related Videos - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Skynet wants your Passwords! The Role of AI in Automating Social Engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)