Proven track record (10+ years) leading or heavily involved in security operations in a technology or SaaS environment
Ideally experience with regulated data (healthcare, life sciences, or similarly regulated)
Comfortable operating in ambiguity and high-growth environments
Responsibilities
Develop and own the security operations strategy: define missions, objectives, KPIs, service levels, and a roadmap for detection, response, monitoring, and operations
Build, lead, and scale the security operations team: SOC/SecOps analysts, threat hunters, response engineers; define roles, hiring, training, and leadership
Oversee real-time security monitoring, detection, triage, investigation, and containment of incidents across cloud, infrastructure, product, clinical data pipelines, and end-user interfaces
Perform tabletop and DR/BR scenarios
Define incident response playbooks, run-books, escalation paths, crisis communication, post-mortem mechanics, and lessons-learned cycles specific to regulated health-AI contexts
Manage security tooling and architecture for operations: SIEM, SOAR, threat intel platforms, cloud-native logging/alerting, automation of response
Embed security operations practices into product and engineering life cycles: collaborate with product security, devops, data science, and clinical operations to integrate detection/response capabilities
Work with GRC to establish vendor/third-party risk monitoring for security operations: ensure that outsourced services, clinical-data vendors, and cloud providers meet operational security expectations
Maintain readiness for audits, compliance, and regulatory demands (HIPAA-adjacent, healthcare data, AI-governance) as operations scale
Liaise with other functional leads (GRC, privacy, product, legal) to ensure alignment of security operations with governance and compliance frameworks