Senior Director, Information Security

Well Dot, Inc.
Chapel Hill, NC, United States
3 months ago
Apply on indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$190,000.0 - $230,000.0
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Software as a Service Cloud Computing Control Objectives for Information and Related Technology (COBIT) Cyber Security Data Integrity Information Security Management Information Systems Security Architecture Professional Network Security Open Web Application Security Software Engineering Virtualization Technology
+2 more
Software Vulnerability Management Large Language Models

Job description

Description: As the Security Officer for Well, you will collaborate with executive management and key operational teams to determine acceptable levels of risk for the organization and you will be responsible for developing and maintaining the company’s information security management program, which includes policies designed to protect enterprise communications, systems and assets from both internal and external threats. Reporting to the VP, Legal & General Counsel, you will provide independent partnership to our key operational teams, most notably the technology organization, driving both the development of policies that achieve the right posture, given our strategic and operational needs, and consulting on the implementation of such policies that you own and maintain on an ongoing basis. You will also serve as the subject matter expert and key contact for customers on security and member data privacy issues as they relate to the use of our platform, in close collaboration with the General Counsel (Privacy Officer). Additionally, you will collaborate with the General Counsel to provide independent risk reporting and escalation directly to the Board of Directors., * Partner with infrastructure and engineering teams to develop and monitor a strategic, comprehensive enterprise security and IT risk management framework and program

  • Work directly with the business units to facilitate risk assessment and risk management processes
  • Understand and interact with related disciplines (e.g., through committees or working groups) to ensure our policies are tuned correctly to balance strategic and operational realities, and the consistent application of our policies and standards across all technology projects, systems and services
  • Serve as a subject matter expert and point of contact for customers, potential customers, and sales colleagues on security and member data privacy issues as they relate to the use of our platform (e.g., in RFP responses, contracts, implementation, security audits)
  • Lead selection and management of external vendors to conduct third-party audits, assessments and certifications (e.g., HITRUST, SOC2, etc.)
  • Partner with infrastructure and engineering teams to design, maintain, and regularly test business continuity and disaster recovery strategies to ensure platform resilience and data availability, as well as to lead incident response plan (IRP) development and act as quarterback for IRP issues
  • Partner with infrastructure and engineering teams on continuous security monitoring operations, vulnerability management programs, threat intelligence, and the deployment of the corporate endpoint/network security stack
  • Partner with business stakeholders across the company to raise awareness of risk management concerns and ensure compliance with required policy acknowledgments and training
  • Assist with overall business technology planning, providing a current knowledge and future vision of technology and systems
  • Take personal responsibility for keeping all Well systems and data, including sensitive member data, secure and safe, according to Well data and security policies and HIPAA guidelines

Requirements

Do you have experience in Regulatory Frameworks (Architecture security)?, * Minimum of 8 years of experience in a combination of compliance, risk management, information security and IT roles in a high-growth organization

  • Knowledge of common information security management frameworks, such as SOC, HIPAA/HITRUST, NIST and ISO
  • Demonstrated ability to develop effective security policies and governance programs in a health-related business context
  • Commercially minded, strong track record of partnership across the business, including successful collaboration with technical teams
  • Deep understanding of software engineering workflows and work products along with the ability to apply this knowledge to optimize strategies that achieve strategic alignment with organizational objectives
  • Experience with Cloud computing across virtualized environments, * Professional security management certification(s)
  • Experience with contract and vendor negotiations and management, including managed services
  • Familiarity with internal audit methodologies applicable to SaaS companies, IT general controls (ITGC) testing, and control framework evaluation (e.g. COSO, COBIT); experience building or managing an internal audit function
  • Familiarity with AI security best practices and governance frameworks (e.g., NIST AI RMF, OWASP LLM Top 10, ISO/IEC 42001), including experience assessing and mitigating AI-specific risks such as model security, data integrity, and prompt injection in a healthcare or SaaS context

Well is on a mission to redefine the healthcare experience. This is an opportunity to re-shape healthcare for America. We are developing solutions to improve the quality and affordability of healthcare. We welcome team members who are passionate about that mission. We embrace diversity and are committed to building an inclusive team.

About the company

Company: Well is a healthcare innovation company with the heart of a services organization and the DNA of a SaaS platform. Our Dynamic Engagement System transforms workforce health by uniting AI, human guidance, and proven behavioral science to reduce costs, improve outcomes, and create resilient, thriving workforces. We partner with the world’s largest, most sophisticated employers and the consultants who advise them. We’re a highly diverse and engaged organization whose employees are passionate about the mission of the company and whose management is passionate about the employees. We promote an employee- and member-centric culture with generous benefits, which you can learn more about here: https://www.well.co/careers.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:30 min

Scaling agile frameworks and data interoperability in healthcare

Leo Lindhorst · World Congress 2022

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:55 min

Maintaining software and data integrity during execution

Christian Wenz Christian Wenz · World Congress 2026 Europe

2:27 min

Introduction to WebAssembly in a cloud computing context

Edo Edo · World Congress 2024

6:32 min

Designing domain-specific systems with ethical data guardrails

Julian Joseph · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all