IT 与安全总监,CISO
Director of IT & Security, CISO
Redox致力于通过有用的数据加速医疗行业的转型。Redox Engine是一个灵活的互操作性平台,连接并推动实时医疗数据交换。只需一次连接,数据就可以在不断扩展的12,000+系统和组织网络中进行编排,包括100+电子健康记录系统(EHR)。Redox每月处理超过12亿条消息,覆盖我们的医疗科技供应商、医疗机构、保险公司、EHR和生命科学客户。
机会与影响
Redox正在寻找一位亲力亲为的IT与安全总监、首席信息安全官,负责企业安全、云安全和应用安全以及公司IT。该职位直接向CTO汇报,并是技术领导团队的核心成员。
你将领导安全工程、安全运营和公司IT工作,同时与工程、平台和运营团队紧密合作,将安全性和可靠性嵌入到Redox构建和运行软件的方式中。此职位的成功意味着强大的安全态势、稳健的内部系统,以及员工体验顺畅高效——不会拖慢业务发展。
岗位职责
安全策略与领导:全面负责云、应用、基础设施和企业环境中的信息安全策略。制定符合业务风险、监管要求和工程速度的务实安全路线图。作为安全态势、风险管理及事件响应的高管负责人,为CTO和高管团队在安全、风险和运营权衡方面提供可信建议。
安全工程与DevSecOps:推动以DevSecOps为核心的运营模式,将安全嵌入CI/CD流水线、基础设施即代码和开发人员工作流中。与工程领导深入合作,使安全可扩展、自动化且可衡量。领导新平台项目的威胁建模、安全设计评审和风险评估。倡导政策即代码、护栏和自动化,而非手动流程。
云、应用与基础设施安全:负责主要基于AWS的环境的安全架构和运营。领导应用安全项目,包括安全的SDLC、依赖项扫描、SAST/DAST、渗透测试和漏洞管理。以Okta为核心,制定身份和访问管理策略。确保在终端和云工作负载(如CrowdStrike、RAD)上具备强大的检测、警报和响应能力。
查看英文原文
Redox is on a mission to accelerate healthcare’s transformation with useful data. Redox Engine, a flexible interoperability platform, connects and powers real-time healthcare data exchange. With just one connection, data can be orchestrated across a growing network of 12,000+ systems and organizations, including 100+ electronic health record systems (EHRs). Redox processes over 1.2 billion messages per month across our health tech vendor, provider, payer, EHR, and life sciences customers.
Opportunity & Impact
Redox is seeking a hands-on Director of IT & Security, CISO to own enterprise security, cloud, and application security, and corporate IT. This role reports directly to the CTO and is a core member of the technology leadership team.
You will lead security engineering, security operations, and corporate IT while partnering closely with Engineering, Platform, and Operations to embed security and reliability into how Redox builds and runs software. Success in this role means strong security posture, resilient internal systems, and an employee experience that just works—without slowing the business down.
Job Responsibilities
Security Strategy & Leadership: Own end-to-end information security strategy across cloud, application, infrastructure, and corporate environments. Define a pragmatic security roadmap aligned to business risk, regulatory requirements, and engineering velocity. Serve as the executive owner for security posture, risk management, and incident response. Act as a trusted advisor to the CTO and executive team on security, risk, and operational tradeoffs.
Security Engineering & DevSecOps: Drive a DevSecOps-first operating model, embedding security into CI/CD pipelines, infrastructure as code, and developer workflows. Partner deeply with engineering leadership to make security scalable, automated, and measurable. Lead threat modeling, secure design reviews, and risk assessments for new platform initiatives. Champion policy-as-code, guardrails, and automation over manual process.
Cloud, Application & Infrastructure Security: Own security architecture and operations for a primarily AWS-based environment. Lead application security programs, including secure SDLC, dependency scanning, SAST/DAST, penetration testing, and vulnerability management. Own identity and access management strategy with Okta as the backbone. Ensure strong detection, alerting, and response across endpoints and cloud workloads (e.g., CrowdStrike, RAD).
Security Operations & Incident Response: Build and run effective security operations, including monitoring, investigation, incident response, and post-incident learning. Lead incident response for both security and IT incidents, serving as the calm point of accountability. Run tabletop exercises and continuously improve response playbooks. Manage vendor relationships, including CrowdStrike, Flashpoint, RAD, and Okta.
Corporate IT & Enterprise Systems: Own corporate IT strategy and execution, focused on reliability, security, and employee productivity. Lead end-user computing, device management, endpoint security, identity lifecycle management, and access controls. Oversee IT systems, including identity, email, collaboration tools, endpoint management, and SaaS access governance. Drive automation and standardization across onboarding, offboarding, access management, and device lifecycle. Partner with People Ops, Legal, and Finance on IT processes, audits, and vendor management.
Compliance, Risk & Healthcare Context: Own healthcare-related security and compliance programs (e.g., HIPAA, SOC 2). Translate regulatory requirements into practical, engineering-friendly controls. Lead third-party risk management and vendor security reviews. Support customer security reviews and serve as an executive point of contact on security matters.
Team Leadership & Culture: Build, lead, and mentor a high-performing team spanning security engineering, security operations, and IT. Create a culture where security and IT are seen as enablers, not blockers. Establish clear ownership, measurable outcomes, and high operational standards. Be visible, decisive, and calm under pressure.
Required Skills & Experience
10+ years in information security, IT, or related technical leadership roles, including 5+ years of people management, ideally in healthcare technology SaaS.
Proven experience leading security engineering, security operations, and corporate IT in a cloud-native SaaS environment.
Direct experience in healthcare or other highly regulated industries.
Track record of successfully implementing DevSecOps practices.
Deep hands-on experience securing AWS environments.
Strong understanding of endpoint security, identity systems, and modern SaaS IT stacks.
Practical knowledge of tools such as CrowdStrike, Okta, Flashpoint, RAD, and related platforms.
Strong foundation in application security, cloud security, and infrastructure as code.
Proven proficiency in AI tools and techniques, including prompt engineering and hands-on experience across multiple large language model platforms, with a demonstrated ability to drive AI adoption enterprise-wide.
Strong collaborator with engineering, platform, and operations teams.
Clear, direct communicator who can articulate risk without theatrics.
Comfortable making tradeoffs and prioritizing based on real-world risk.
Builder mindset with a bias toward automation and scale.
Preferred Skills & Experience
Proven experience securing autonomous agentic loops and tool-calling frameworks. Deep understanding of Indirect Prompt Injection and designing "Human-in-the-Loop" guardrails for agent-driven actions.
Technical expertise in securing the Model Context Protocol (MCP), specifically regarding context isolation, sandboxing, and identity propagation between LLMs and private data sources.
Direct experience migrating security programs to Vanta or similar automated GRC platforms. Ability to architect "continuous compliance" by integrating cloud, identity, and developer tools for automated evidence collection.
Hands-on application of the NIST AI RMF, OWASP Top 10 for LLMs, etc within a production environment.
Software Platform / Tools
Required: Crowdstrike, AWS, Okta
Preferred: Vanta
About Redox - Take a look here: https://youtu.be/4OjENXR6UXA
What We Do
Healthcare organizations and technology vendors connect to Redox once, then authorize what data they send to and receive from partners through a centralized hub. Redox's cloud-based platform is vendor and standards-agnostic and enables the secure and efficient exchange of healthcare data.
This approach eradicates the need for point-to-point integrations and accelerates the discovery, adoption, and distribution of patient and provider-facing technology solutions. With hundreds of healthcare organizations and technology vendors exchanging data today, Redox represents the largest interoperable network in healthcare. Learn how you can leverage the Redox platform at www.redoxengine.com.
Other Stuff About Us
Redox is an EEO company. We fully support the diversity of our team. As part of our ongoing work to build more diverse teams at Redox, you will be asked to complete a voluntary EEO survey when applying. This survey is anonymous, we cannot link your application record with your survey responses. We request that you complete this voluntary survey as we run monthly reports for each team which provides data for diversity in terms of gender and ethnic background in our Applicants and our Hired Redoxers. We take this data very seriously and appreciate your willingness and time to complete this step in the process.
Successful candidates must be eligible to be employed in the U.S. and must reside & work in the continental U.S.
Thank you for your interest in Redox!
#LI-TA1