Director of Security @Sequencing
All Others
Salary unspecified
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 2wks ago

[Hiring] Director of Security @Sequencing

2wks ago - Sequencing is hiring a remote Director of Security. πŸ’Έ Salary: unspecified πŸ“Location: USA

Role Description

Sequencing is hiring its first dedicated security leader. Security today is owned across Engineering and Platform, backed by external penetration testing partners and an active HIPAA program. This role brings it under one owner and builds the function from the ground up.

This is a hands-on role. You will execute the majority of the work yourself for the first year, from writing policy to triaging pentest findings to configuring controls, and hire and coach a small team as the program matures. If you are looking to direct work rather than do it, this is not the right role.

We are an AI-first company and expect the same of our security leader. You will use AI daily in your own work, from drafting policy to triaging findings to building detections, and you will set the company's posture on AI as adopt and govern, not restrict. Security here exists to make fast AI adoption safe, not to slow it down.

You report to the Head of Engineering and work alongside Platform Engineering, which owns infrastructure security implementation, and the Bioinformatics and AI functions. The data you protect is whole genome sequences and health data for consumers, which makes this one of the more consequential first-security-hire roles available.

First Six Months

  • Create the security ownership map with Platform Engineering: they implement infrastructure controls, you set policy, run assurance, and own AppSec, offensive security, and incident response leadership.
  • Complete a HIPAA and HITECH review and deliver a prioritized remediation roadmap by day 45.
  • Reach SOC 2 readiness within six months, aligned with the infrastructure roadmap.
  • Formalize incident response: severity model, escalation paths, communications, executive coordination, and post-incident review.
  • Extend security policy to AI tooling and model providers, including data classification, acceptable use, and data-handling standards.

Ongoing

  • Run the security program: policy, risk register, security awareness and training, and the GRC tooling that keeps evidence current.
  • Run offensive security yourself: scope and manage external pentest firms, triage findings, and drive remediation with the owning teams.
  • Own security review of third-party data flows: partner and marketplace apps, provider data sharing, marketing and analytics integrations, and AI model providers, including data-processing terms.
  • Own security standards for contractors, agencies, and third-party development partners across a distributed workforce, including IP protection, device management, and access lifecycle.
  • Own SaaS governance, shadow IT visibility, and identity lifecycle policy.
  • Apply AI to the security program itself: AI-assisted detection and log triage, automated evidence collection, policy and control drafting, and code and infrastructure review. Measure and report where it moves the needle.
  • Serve as the escalation point for security incidents, including after hours when needed.
  • Report security posture, risk, and roadmap to the founder and leadership team in plain, business-oriented language.
  • Translate security findings into practical actions engineering teams can implement without slowing product velocity.

Qualifications

  • 8+ years in security, including at least one stretch as the first or only security leader at a company under a few hundred people. Building from zero matters more here than years or title.
  • Have taken a company through SOC 2 or built a HIPAA program from scratch. ISO 27001 is a plus.
  • Hands-on in AWS and web application security. You can read a Terraform PR, triage a pentest finding, and tune a WAF rule yourself.
  • Still hands-on and want to stay that way. You have run pentests through vendors, triaged the findings yourself, and closed them with engineers.
  • Have secured a consumer-facing product at scale, including identity and account security, MFA, credential stuffing defense, session and account recovery abuse.
  • Understand privacy and breach obligations beyond HIPAA.
  • Already work AI-first. You use coding assistants and LLMs daily and can show us how they changed your security workflow. You believe the answer to "should we block this AI tool" is almost always "no, here is how we govern it."
  • Exceptional communicator under pressure. You have briefed a board, founder, or executive team during a live incident, and you can explain risk and tradeoffs to non-technical leaders in plain language, in writing and in the room.

Nice to have

  • Healthcare or genomics experience; familiarity with state genetic privacy laws, the FTC Health Breach Notification Rule, and state breach notification requirements.
  • Ecommerce or payment-processing security; ISO 27001; PCI DSS; Drupal security; GDPR and international data transfers; mobile application security; Vanta or Drata; SIEM; Cloudflare Enterprise; and Zero Trust.

Benefits

  • Comprehensive medical, dental, and vision insurance coverage.
  • 401(k) with company matching.
  • Paid time off.
  • Paid volunteer time off.
  • Fully remote work with a home office stipend.
  • Parental bonding leave.
  • Private and confidential clinical-grade whole genome sequencing for you and your family.
Before You Apply
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Director of Security @Sequencing
All Others
Salary unspecified
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 2wks ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 126,939+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later