Back to jobs
New

Director, Security & Compliance

Hybrid - Palo Alto, CA | Remote - US

Transform healthcare with us.

At Qualified Health, we're redefining what's possible with Generative AI in healthcare. Our infrastructure provides the guardrails for safe AI governance, healthcare-specific agent creation, and real-time algorithm monitoring — working alongside leading health systems to drive real change.

This is more than just a job. It's an opportunity to build the future of AI in healthcare, solve complex challenges, and make a lasting impact on patient care. If you're ambitious, innovative, and ready to move fast, we'd love to have you on board.

Join us in shaping the future of healthcare.

Job Summary:

The Director of Security & Compliance will own the security and compliance program for a growing health tech company that handles protected health information across 15+ health system partners. This is the most consequential security leadership role you'll find at a company this size.

Let's be direct about what you're walking into: we're building a security program that matches the scale and ambition of our business. The operational security work — vendor intakes, IAM, MDM, compliance certification — needs a dedicated leader who can drive it with the urgency and rigor it deserves. The board and our health system partners expect a security posture that matches the trust they place in us.

You'll drive HITRUST certification, build the ongoing compliance program, manage a small but growing security team, and represent the company's security posture to the board, investors, partners, and regulators. This is a build role — you're creating program infrastructure from the ground up, not inheriting a mature program. If you've spent your career wanting to own a security program at a mission-driven company where security actually matters (not just compliance theater), this is it.

Key Responsibilities:

  • Own the end-to-end security and compliance program: strategy, roadmap, execution
  • Drive HITRUST certification and establish the ongoing recertification program
  • Build and manage a security team
  • Own the company's security posture in all external contexts: board reporting, investor due diligence, partner audits, client security questionnaires
  • Manage IAM strategy and governance across company systems
  • Own the vendor security intake and assessment program
  • Publish and maintain security policies, procedures, and incident response plans
  • Drive the security scan and remediation coordination process with core engineering
  • Manage the relationship with our outsourced IT support vendor
  • Own MDM/device management strategy and compliance

Required Qualifications:

  • Bachelor's degree in Computer Science, Engineering, Data Science, Mathematics, or related technical field
  • 8+ years in information security, with 3+ years in a leadership role
  • Healthcare security experience required: HIPAA, HITRUST (i1 or r2), understanding of PHI handling requirements
  • Hands-on GRC experience — you've built compliance programs, not just advised on them
  • Enough technical depth to guide a security engineer on vulnerability management, infrastructure security, and secure architecture

Preferred Skills:

  • Experience with IAM platforms (Okta, Azure AD/Entra), MDM solutions, and endpoint security
  • Board and executive communication experience — you can present security posture to non-technical investors
  • Prior experience in a growth-stage startup or fast-scaling company where the security program was being built, not maintained
  • CISSP, CISM, or HCISPP certification
  • Experience managing vendor security assessments at scale (dozens of vendors across a growing company)
  • Builder Mentality: You're excited by the prospect of creating a security program from the ground up — writing the first version of policies, standing up the first compliance automation, building the first incident response plan
  • Pragmatic Risk Management: You know how to prioritize security investments based on actual risk, not just compliance checklists — and you can articulate that prioritization to a board
  • Executive Communication: You translate security posture into business language that resonates with investors, board members, and health system partners
  • Team Development: You'll build and develop a small security team — your ability to hire, develop, and retain these team members is critical
  • Healthcare Sensibility: You understand that in healthcare, security isn't about protecting the company — it's about protecting patients whose data we handle. That responsibility is personal to you.

 

Technical Environment:

Our data infrastructure is built on modern cloud technologies including:

  • Azure Databricks + Data Factory (plus Fabric and Snowflake integrations)
  • PySpark for distributed data processing
  • GitHub Actions + Terraform for CI/CD and Infrastructure as Code
  • Python with type-safe patterns and modern frameworks
  • Healthcare data formats including FHIR, Epic Clarity, and other EHR schemas

 

Why Join Qualified Health?

This is an opportunity to join a fast-growing company and a world-class team, that is poised to change the healthcare industry. We are a passionate, mission-driven team that is building a category-defining product. We are backed by premier investors and are looking for founding team members who are excited to do the best work of their careers.

Our employees are integral to achieving our goals so we are proud to offer competitive salaries with equity packages, robust medical/dental/vision insurance, flexible working hours, hybrid work options and an inclusive environment that fosters creativity and innovation.

Our Commitment to Diversity

Qualified Health is an equal opportunity employer. We believe that a diverse and inclusive workplace is essential to our success, and we are committed to building a team that reflects the world we live in. We encourage applications from all qualified individuals, regardless of race, color, religion, gender, sexual orientation, gender identity or expression, age, national origin, marital status, disability, or veteran status.

Pay & Benefits: The pay range for this role is between $190,000 and $235,000, and will depend on your skills, qualifications, experience, and location. This role is also eligible for equity and benefits.

Join our mission to revolutionize healthcare with AI. To apply, please send your resume through the application below.

Create a Job Alert

Interested in building your career at Qualified Health? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...

U.S. Standard Demographic Questions

We invite applicants to share their demographic background. If you choose to complete this survey, your responses may be used to identify areas of improvement in our hiring process.
Select...
Select...
Select...
Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Qualified Health’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.