Back to jobs
New

Head of Corporate and Information Security

Boston, Massachusetts, United States, New York, New York, United States

Layer Health was founded in 2023 by leading machine learning researchers from MIT and Harvard Medical School. We are building an AI layer that can accurately and scalably synthesize information from medical records, with the mission to reduce friction everywhere in healthcare. Our LLM-powered platform is solving chart review once and for all, across use cases. For health systems, our first product dramatically accelerates clinical registry abstraction in areas ranging from surgery and cardiology, to oncology. Our long term vision is for our AI layer to safely transform patient care and minimize unnecessary heartbreak. Layer Health's diverse founding team brings expertise across machine learning, UI/UX, large language models, and medicine.

Here's a collection of articles about our product, mission, recent funding round, etc.

We're scaling up the security function at Layer Health, and we're looking for the first Head of Corporate and Information Security to own it. This is a foundational hire: we handle PHI and sensitive customer data as a core part of our product, and as we scale with health systems and enterprise partners, evolving our security and compliance program are central to our ability to grow. You'll report directly into leadership and have the mandate to continue to build the program the right way.

THE OPPORTUNITY

  • Own Layer's security strategy and risk program. Develop a comprehensive understanding of our existing security posture across our product, cloud infrastructure, corporate systems, endpoints, vendors, and operational processes. Build on existing SOC2 Type 2 compliant security program and establish a risk-based roadmap, identify gaps, and help leadership make informed decisions about where to invest on our journey towards ISO 27001.
  • Define and continuously improve our existing technical security posture. Partner closely with engineering and infrastructure teams to strengthen security across our GCP environments and software development lifecycle. Depending on the risks you identify, this may include areas such as cloud IAM and service accounts, network security, secrets and key management, vulnerability management, secure configuration, CI/CD and code security, logging and monitoring, or security architecture reviews.
  • Protect sensitive data throughout its lifecycle. Define and improve upon the existing controls necessary to protect PHI, customer data, credentials, and other sensitive information wherever it is stored, processed, or transmitted. Examples might include data classification and DLP capabilities, access controls, egress protections, retention policies, secrets scanning, or controls within Google Workspace and endpoints.
  • Continue to build out our detection, incident response, and security operations capabilities. Ensure we have the visibility and operational processes necessary to detect, investigate, contain, and learn from security events. This may include improving centralized security telemetry and SIEM capabilities, detection and alerting strategies, incident response processes, in addition to running exercises and coordinating investigations when incidents occur.
  • Own corporate security. Refine our security posture across employee identity, endpoints, SaaS applications, and other corporate systems. Work closely with Operations and IT stakeholders on areas such as identity and access management, endpoint security, device management, employee lifecycle controls, and account management.
  • Strengthen our human security posture. Build upon our existing comprehensive security awareness and training program, including regular phishing simulations and social engineering exercises, to empower employees as our first line of defense against human-based threats.
  • Work with the Chief Privacy Officer and other members of the leadership team to identify key security risks and establish a strategic plan that balances robust risk management with other organizational priorities.

YOUR BACKGROUND

  • 7+ years of experience in information security, security engineering, or related roles, with meaningful ownership across multiple areas of a security program rather than deep experience in only one specialty.
  • Experience building or materially evolving a security program in a startup, growth-stage technology company, or similarly fast-moving environment. You are comfortable starting with incomplete systems and deciding what matters most.
  • Strong technical depth in modern cloud environments. You should be comfortable reasoning about areas such as cloud IAM, networking, application and infrastructure security, data protection, secrets management, logging and detection, vulnerability management, and endpoint or identity security. Hands-on GCP experience is strongly preferred; equivalent AWS or Azure experience is relevant.
  • Experience working closely with software engineering and infrastructure teams and enough technical fluency to evaluate architecture, investigate security issues, and implement or meaningfully contribute to technical controls yourself.
  • Strong understanding of security operations and incident response, including how to build useful telemetry, detection, investigation, escalation, and response capabilities. Experience with SIEM and related security tooling is valuable, but we care more about your ability to design the overall capability than familiarity with a particular product.
  • Experience protecting sensitive data in regulated environments. Healthcare experience — particularly HIPAA and PHI handling — is strongly preferred, although experience in other highly regulated industries may also be relevant.
  • Experience with security and compliance frameworks such as SOC 2 and ISO 27001, including translating framework requirements into effective operational and technical controls. Experience leading an organization through ISO 27001 certification is a plus.
  • Strong risk judgment. You can distinguish between theoretical issues and meaningful business risk, prioritize accordingly, and explain the tradeoffs behind your recommendations.
  • A builder's mindset. You are comfortable moving between strategy, architecture, tooling, policy, investigation, and implementation, particularly while the security team is small.
  • A clear and credible communicator who can discuss technical security issues with engineers, explain risk and investment decisions to executives, and represent Layer effectively with customers' security and compliance teams.

 

Expected compensation range for this role is $180,000–$230,000. Compensation is dependent on experience and overall fit to our role. Expected compensation ranges for this role may change over time. If your compensation requirement is greater than our posted salary ranges, please still consider applying to our role. We will make a determination as to whether an exception can be made.

If you are excited about this role, we encourage you to apply even if you don't feel that you meet every single requirement. We're eager to meet people that believe in our mission and can contribute to our team in a variety of ways. We welcome diverse perspectives, rigorous thinking, and fearlessness in challenging the status quo.

Layer Health is committed to fostering an environment of inclusion that is free from discrimination. We are an Equal Opportunity Employer where employment is decided on the basis of qualifications, merit, and business need. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected Veteran status, or any other characteristic protected by law.

Join us and help us transform healthcare with AI.

Create a Job Alert

Interested in building your career at Layer Health? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf