Back to jobs
New

Director, Cloud Security

Remote

About Judi Health

Judi Health is an enterprise health technology company providing a comprehensive suite of solutions for employers and health plans, including:

  • Capital Rx, a public benefit corporation delivering full-service pharmacy benefit management (PBM) solutions to self-insured employers,
  • Judi Health™, which offers full-service health benefit management solutions to employers, TPAs, and health plans, and
  • Judi®, the industry’s leading proprietary Enterprise Health Platform (EHP), which consolidates all claim administration-related workflows in one scalable, secure platform.

Together with our clients, we’re rebuilding trust in healthcare in the U.S. and deploying the infrastructure we need for the care we deserve. To learn more, visit www.judi.health.

Position Summary:

Reporting to the CISO, the Director of Cloud Security leads Judi Health’s cloud security strategy and engineering execution across our AWS environment. This role is responsible for advancing the security roadmap across FedRAMP readiness, continuous compliance, resilient cloud architecture, and automation at scale. The leader in this role will partner closely with engineering, infrastructure, compliance, and AI teams to embed modern security practices, strengthen detection and response capabilities, mature identity and access controls, and help establish a practical security framework that enables Judi Health’s AI initiatives while managing risk.

Position Responsibilities:

  • Lead, mentor, and scale a high-performing cloud security engineering function, fostering strong ownership, operational excellence, and continuous improvement.
  • Own execution of the cloud security roadmap, prioritizing initiatives across FedRAMP readiness, zero trust architecture, cloud hardening, security automation, and continuous control validation.
  • Define and evolve the cloud security strategy for Judi Health, aligning technical investments and security architecture decisions to business growth, regulatory commitments, platform resilience goals, and emerging AI initiatives.
  • Serve as a trusted advisor to the CISO, engineering leaders, and executive stakeholders, helping drive secure-by-design decisions and modern security engineering practices across the organization.
  • Lead the design, implementation, and continuous improvement of cloud security controls across AWS infrastructure, platforms, application environments, and supporting services.
  • Identify, prioritize, and drive remediation of security risks across cloud services, infrastructure as code, third-party integrations, developer workflows, and enterprise platforms.
  • Build and operationalize cloud security capabilities that support compliance with frameworks and customer obligations including FedRAMP, FISMA, SOC 2, HITRUST, HIPAA, and related control requirements.
  • Drive threat detection, incident response readiness, vulnerability management, penetration testing, and security validation efforts to proactively identify and reduce risk.
  • Advance automation for security monitoring, alerting, evidence collection, and policy enforcement to improve scalability and support continuous compliance.
  • Establish meaningful security metrics and reporting for cloud posture, control effectiveness, and roadmap progress, and communicate insights clearly to senior leadership.
  • Partner with software engineering, platform engineering, DevOps, IT, and AI teams to embed security into architecture, infrastructure, the software development lifecycle, and AI-enabled capabilities.
  • Work closely with compliance, legal, privacy, and risk management teams to translate regulatory and customer requirements into practical, auditable technical controls.
  • Lead technical engagement for third-party assessments, customer security reviews, and external audits, ensuring strong preparation, evidence readiness, and timely remediation.
  • Help define and operationalize a modern security framework for AI initiatives, including governance, data protection, access controls, third-party risk, and secure adoption practices.

Required Qualifications:

  • 10+ years of experience in cloud security, information security, or related field, including 5+ years in leadership roles.
  • Proven experience leading cloud security or security engineering programs, including team leadership, roadmap execution, and cross-functional influence.
  • Deep expertise in AWS security architecture, cloud-native security controls, and modern practices for securing scalable SaaS environments.
  • Strong technical depth in at least one modern programming or scripting language, with experience enabling secure engineering and automation in cloud environments.
  • Hands-on experience securing infrastructure as code and cloud deployment pipelines, including Terraform and CI/CD environments.
  • Expertise with security tooling and operational disciplines such as SIEM, cloud security posture management, vulnerability management, detection engineering, and incident response.
  • Experience supporting regulated or audited environments, including technical control implementation, evidence management, and readiness for external assessments.
  • Experience partnering with engineering or product teams to define security guardrails and governance for emerging technologies, including AI-enabled initiatives.
  • Strong understanding of identity and access management, least privilege, authentication, privileged access, and zero trust principles.
  • Excellent communication and stakeholder management skills, with the ability to translate complex security priorities into clear decisions and practical outcomes.
  • Ability to operate effectively in a fast-paced, high-growth environment while balancing strategic priorities with hands-on execution.

Preferred Qualifications:

  • Industry certifications such as CISSP, CCSP, AWS Security Specialty, or similar.
  • Familiarity with AI and ML security concepts, including governance, model access, data protection, and third-party AI risk.
  • Experience in healthcare, health tech, or another highly regulated industry.
  • Knowledge of container and orchestration security, including Kubernetes or EKS.
  • Experience with policy-as-code or automated compliance validation in cloud environments.

This range represents the low and high end of the anticipated base salary range. The actual base salary will depend on several factors such as: experience, knowledge, skills, and location of the job.

Remote, US Salary Range

$184,000 - $240,000 USD

All employees are responsible for adherence to the Capital Rx Code of Conduct including the reporting of non-compliance. This position description is designed to be flexible, allowing management the opportunity to assign or reassign duties and responsibilities as needed to best meet organizational goals.

Judi Health values a diverse workplace and celebrates the diversity that each employee brings to the table. We are proud to provide equal employment opportunities to all employees and applicants for employment and prohibit discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, medical condition, genetic information, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. 

By submitting an application, you agree to the retention of your personal data for consideration for a future position at Judi Health. More details about Judi Health's privacy practices can be found at https://www.judi.health/legal/privacy-policy.

Create a Job Alert

Interested in building your career at Judi Health? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Judi Health’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.