Back to jobs
New

Director, Corporate Security

United States

We Breathe Life Into Data

At Komodo Health, our mission is to reduce the global burden of disease. And we believe that smarter use of data is essential to this mission. That’s why we built the Healthcare Map — the industry’s largest, most complete, precise view of the U.S. healthcare system — by combining de-identified, real-world patient data with innovative algorithms and decades of clinical experience. The Healthcare Map serves as our foundation for a powerful suite of software applications, helping us answer healthcare’s most complex questions for our partners. Across the healthcare ecosystem, we’re helping our clients unlock critical insights to track detailed patient behaviors and treatment patterns, identify gaps in care, address unmet patient needs, and reduce the global burden of disease. 

As we pursue these goals, it remains essential to us that we stay grounded in our values: be awesome, seek growth, deliver “wow,” and enjoy the ride. At Komodo, you will be joining a team of ambitious, supportive Dragons with diverse backgrounds but a shared passion to deliver on our mission to reduce the burden of disease — and enjoy the journey along the way.

The Opportunity at Komodo Health

Komodo Health needs a Director of Corporate Security who can assess the current state of our internal security environment and help drive strategic improvements across the company. This role will focus on protecting employee systems, identity, devices, endpoints, internal networks, business applications, vendor tools, and workforce-related security risk. The Director, Corporate Security will work closely with IT, Product Security, Engineering, Compliance, Legal, and business leaders to identify gaps, improve execution, and put more consistent operating practices in place.

This role reports directly to the CFO, and carries executive visibility from day one. The Director will be expected to operate at all levels — setting strategy, building the program, and getting into the details when it matters.

Looking back on your first 12 months at Komodo Health, you will have…

  • Delivered a rigorous current-state assessment of Komodo’s corporate security environment, with clear findings, ownership, and a sequenced improvement plan signed off by the CFO and CISO.
  • Stood up or significantly strengthened core capabilities: device trust, identity and access governance, offboarding discipline, internal access controls, SaaS security posture, and external-sharing safeguards.
  • Established a security program framework that can scale with the company — clear policies, documented controls, repeatable processes, and metrics that tell a real story to the board and auditors.
  • Improved day-to-day security operations: tightened monitoring with our SIEM tool, reduced MTTD/MTTR on incidents, and introduced post-mortem discipline that actually improves things.
  • Built practical AI governance guardrails for internal enterprise tools, with SSO, RBAC, approved-tool standards, and usage expectations employees will actually follow.
  • Established yourself as a trusted, credible partner to IT, Engineering, Legal, Compliance, and Procurement — someone who makes cross-functional work easier, not harder.

You will accomplish these outcomes through the following responsibilities…

  • Own corporate security strategy and execution across identity and access management, endpoint and device trust, internal SaaS security, data-sharing controls, workforce risk, and incident response for corporate assets.
  • Build and maintain a multi-year corporate security roadmap, prioritized by risk, business context, and resource constraints. Present progress and risk posture clearly to the Komodo Executive Team.
  • Lead security operations across existing tooling: Our existing EDR/MDR, email security, SIEM/monitoring  tools , and evolving vendor stack. Own response coordination, remediation tracking, and escalation.
  • Partner with IT to strengthen provisioning and deprovisioning, access reviews, device management, and internal network and application security controls. Hold the line on offboarding.
  • Establish practical guardrails for internal enterprise AI use — approved-tool standards, SSO and domain capture, RBAC, retention, redaction, logging, and usage expectations.
  • Partner with Product Security, Compliance, Procurement, and Legal on vendor security reviews, risk assessments, privacy and security questionnaires, and security requirements for strategic software and AI vendors.
  • Build and lead a high-performing corporate security team. Hire well, develop people, set clear expectations, and hold the team to a high standard of execution and accountability.
  • Represent corporate security in audits, investor diligence, customer security reviews, and regulator inquiries as needed.

What you bring to Komodo Health:

  • 7+ years of experience operating at the Director level or equivalent in corporate security, IT security, or security operations — with demonstrated accountability for program ownership, team leadership, and executive stakeholder management.
  • Experience across both mature, compliance-minded environments (public company, regulated industry, or enterprise scale) and high-growth startups where you had to build from scratch.
  • 5+ years of experience leading, managing, or developing high-performing teams.
  • Proven track record building or significantly maturing a corporate security program at a startup or scale-up, where you owned the roadmap, made prioritization calls with limited resources, and shipped durable results.
  • Deep fluency in corporate security fundamentals: identity and access management, endpoint security, device trust, internal network security, SaaS security posture, incident response, and access governance.
  • Hands-on experience with enterprise security tooling — SIEM tools, modern EDR/MDR, modern email security, IAM platforms, and device management.
  • Experience running a security program in an environment subject to external audits, SOC 2, or similar compliance frameworks. Comfort with auditor-ready documentation, evidence collection, and control testing.
  • Strong cross-functional leadership. You have worked effectively across IT, Engineering, Compliance, Legal, Procurement, People, and business teams — and you know how to get things done through influence, not just authority.
  • Clear, confident communicator at the executive level. You can translate technical risk into business language and present a credible security posture to CFOs, boards, and enterprise customers.
  • Experience in healthcare, life sciences, or other sensitive-data environments handling PHI, PII, or proprietary clinical/commercial data.
  • Experience communicating risks, gaps, progress, and recommended actions clearly to leaders and stakeholders with different technical backgrounds.
  • Experience supporting audits, internal investigations, vendor reviews, security questionnaires, and environments that handle sensitive data.
  • Strong judgment, leadership presence, and execution discipline, with the ability to stay calm under pressure and move work forward consistently.

Expectations of AI Use in This Role

  • Drive secure enterprise AI adoption by owning governance for approved tools — SSO, domain capture, RBAC, retention controls — that reduce shadow IT without slowing the business.
  • Establish practical, enforceable controls for internal AI use cases: data handling standards, logging, redaction, access review, and a process for evaluating new tools before they proliferate.
  • Use AI in your own workflow to improve IT Security operations, documentation, risk prioritization, and incident triage. Maintain clear human accountability for every decision.

Additional skills and experience we’d prioritize (nice to have)…

  • Experience scaling a security program through a Series C–E or pre-IPO stage, with direct exposure to investor diligence, SOC 2 Type II, or early public-company readiness.
  • Familiarity with Apple device management and mixed-device enterprise environments.
  • Experience with security automation and tooling that improves team efficiency, detection quality, and response times.
  • Background in offboarding and access governance at distributed organizations with significant SaaS sprawl.
  • Experience evaluating, selecting, and managing enterprise security vendors through procurement cycles.

#LI-Remote

The pay range for each job posting reflects a minimum and maximum range of annual base pay that we reasonably expect to pay for this position within the US. We carefully consider multiple business-related factors when determining compensation, including job-related skills, work experience, geographic work location, relevant training and certifications, business needs and market demands.

 

The starting annual base pay for this role is listed below. This position may be eligible for performance-based bonuses as determined in the Company’s sole discretion and in accordance with a written agreement or plan. This role may also be eligible for equity awards. In addition, this role is eligible for benefits including, but not limited to, comprehensive health, dental, and vision insurance; flexible time off and holidays; 401(k) with company match; disability insurance and life insurance; and leaves of absence in accordance with applicable state and local laws and regulations and company policy. 

San Francisco Bay Area and New York City:

$237,000 - $290,000 USD

All Other US Locations:

$206,000 - $260,000 USD

Komodo's AI Standard

At Komodo, we're not just witnessing the AI revolution – we're leading it. This is a pivotal moment in time, where being first to market with AI transforms industries and sets the bar. We've already established industry leadership in leveraging AI to revolutionize healthcare, and we expect every team member to contribute. AI here isn't optional; it's foundational. We expect you to integrate AI into your daily work – from summarizing documents to automating workflows and uncovering insights. This isn't just about efficiency; it's about making every moment more meaningful, building on trust in AI, and driving our collective success.

Join us in shaping the future of healthcare intelligence.

Where You’ll Work

Komodo Health has a hybrid work model with hubs in San Francisco, New York City, and Chicago. Roles vary — some can be performed from anywhere in the country, others are scoped to a specific region, and some are based near one of our hubs. For hub-based Dragons, we're building intentional in-office rhythms alongside the flexibility that's core to how we work. Whatever your setup, expectations will always be clear before you join.

Equal Opportunity Statement

Komodo Health provides equal employment opportunities to all applicants and employees. We prohibit discrimination and harassment of any type with regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws. 

By submitting your application, you acknowledge that you have read and understand Komodo Health’s Privacy Notice for Employees and Contractors.

This notice explains how we collect, use, and retain applicant data.

Create a Job Alert

Interested in building your career at Komodo Health? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...
Select...

Please select your preference:

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Komodo Health’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.


We use Greenhouse’s AI-powered Talent Matching tool to compare your application against our job requirements.

Learn more