Head of InfoSec in United States Embassy at Jobgether
Explore Related Opportunities
Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Head of InfoSec based in United States.
This role offers the opportunity to build and lead a world-class information security function within a rapidly scaling technology-driven healthcare environment.
You will own the cybersecurity strategy, security operations, and internal systems protection across multiple business areas and geographies.
The position combines strategic leadership with hands-on execution, giving you the autonomy to design scalable security foundations from the ground up.
You will partner closely with engineering, operations, compliance, and executive teams to protect sensitive data and maintain operational resilience.
This is an ideal opportunity for a security leader who thrives in high-growth environments and enjoys solving complex challenges with speed and ownership.
The role provides significant impact, executive visibility, and the chance to shape security practices that support global healthcare innovation.
The Head of InfoSec will own the overall cybersecurity strategy, security operations, and information systems protection framework. This role requires a hands-on security leader who can establish scalable processes, strengthen controls, and enable business growth while maintaining trust, compliance, and resilience.
- Define and execute the cybersecurity strategy, roadmap, and operating model across all business entities and locations.
- Build and continuously improve security programs, including policies, controls, processes, tooling, and governance frameworks.
- Establish security operations and incident response capabilities to detect, investigate, contain, and recover from security events.
- Lead security incident management, ensuring effective communication, remediation, and continuous improvement after incidents.
- Own identity and access management processes, including authentication, permissions, onboarding, offboarding, and device security.
- Strengthen application, infrastructure, API, cloud, and data security practices in collaboration with engineering teams.
- Review technical architectures, identify vulnerabilities, and drive remediation initiatives while supporting rapid product development.
- Translate healthcare, privacy, and security requirements into practical compliance programs and operational controls.
- Lead security risk assessments, audits, vendor reviews, and readiness efforts for frameworks such as HIPAA, GDPR, SOC 2, and ISO 27001.
- Develop business continuity, disaster recovery, backup, and resilience strategies for critical systems.
- Assess and manage third-party security risks across vendors, partners, contractors, and business relationships.
- Build a strong security culture through employee education, clear ownership models, and effective collaboration across teams.
- Advise executive leadership on security risks, priorities, and strategic investments.
- Develop internal security capabilities and external partnerships as the organization scales.
The ideal candidate is an experienced information security leader who combines deep technical expertise with strong business judgment and the ability to build security programs in evolving environments. They should be comfortable operating independently, influencing stakeholders, and balancing security requirements with business velocity.
- 5+ years of experience leading cybersecurity, information security, security engineering, or related functions within complex, fast-growing organizations.
- Proven experience building or significantly improving security programs, including strategy, controls, policies, tooling, and operating models.
- Strong technical understanding across identity and access management, endpoint security, cloud infrastructure, application security, vulnerability management, incident response, and corporate systems.
- Experience managing security incidents and leading investigations, containment, recovery, communication, and remediation efforts.
- Ability to identify critical risks, prioritize effectively, and implement practical security solutions without unnecessary operational friction.
- Experience protecting highly sensitive customer, patient, financial, employee, or regulated data.
- Strong communication skills with the ability to work effectively with engineering, operations, legal, compliance, clinical, and executive teams.
- Ability to operate autonomously in ambiguous environments, define priorities, and drive initiatives to completion.
- Experience managing security compliance programs and supporting frameworks such as HIPAA, GDPR, UK GDPR, SOC 2, or ISO 27001.
- Experience in healthcare, digital health, telemedicine, pharmacy, insurance, or other regulated industries is preferred.
- Experience managing security across multiple countries, entities, or business units is a plus.
- Experience hiring, developing, or managing security and IT professionals is preferred.
- Strong understanding of internal IT operations, employee lifecycle management, device management, and productivity systems is beneficial.
- Fully remote work environment with flexibility across time zones.
- Competitive compensation package ranging from $150,000–$250,000, including equity opportunities.
- Early-stage equity participation with significant growth potential.
- Comprehensive healthcare benefits where applicable.
- Flexible paid time off policy with yearly minimum vacation allowance and local holidays.
- Remote-first culture with globally distributed teams.
- Annual personal development budget for books, courses, coaching, and professional growth.
- Annual wellness budget supporting fitness, health apps, and personal wellbeing.
- Access to regular health coaching support.
- Company-provided MacBook and home office equipment as needed.
- Opportunity to shape security strategy, culture, and operational foundations during a high-growth phase.