Lead Cybersecurity Engineer @Cerbo OptiMantra
All Others
Salary unspecified
Remote Location
🇺🇸 USA Only
Employment Type full-time
Posted YDay

[Hiring] Lead Cybersecurity Engineer @Cerbo OptiMantra

YDay - Cerbo OptiMantra is hiring a remote Lead Cybersecurity Engineer. 💸 Salary: unspecified 📍Location: USA

Role Description

As Lead Cybersecurity Engineer, you will lead the company’s cybersecurity program across Cerbo and OptiMantra, supporting the protection of protected health information (PHI) and the security of production platforms serving thousands of clinicians and millions of patients. This role will oversee the development, implementation, and ongoing improvement of a unified security program across both products, including:

  • Security controls
  • Policies
  • Risk management
  • Compliance
  • Security operations

The Lead Cybersecurity Engineer will serve as the technical owner of the company’s security program, establishing and advancing the security practices, standards, and processes that support both platforms.

This position requires an individual with hands-on experience securing cloud environments, implementing security controls, and deploying and operating security tooling in production. The Lead Cybersecurity Engineer will lead the technical execution of initiatives supporting HIPAA compliance and the company’s SOC 2 Type II program, including:

  • Control implementation
  • Evidence collection
  • Security assessments
  • Continuous improvement of the organization’s security posture

Working cross-functionally with DevOps, Engineering, IT, and other stakeholders, this role will evaluate and implement security solutions, harden cloud infrastructure, establish security standards and processes, and identify opportunities to strengthen security across both products while balancing common organizational controls with product-specific requirements.

Reporting to the Chief Technology Officer, this is a hands-on technical leadership role for an individual who can operate effectively across security engineering, cloud security, and compliance while building and advancing the company’s cybersecurity program.

Responsibilities

  • Lead the Compliance Workstream
    • Own the technical implementation and ongoing management of the company’s SOC 2 Trust Services Criteria and HIPAA Security Rule requirements across AWS environments supporting Cerbo and OptiMantra, including control mapping, evidence collection, policy management, and continuous monitoring.
    • Lead compliance documentation and remediation efforts, including control narratives, system and data-flow documentation, scope determinations, and prioritization and closure of security and compliance gaps with supporting evidence.
    • Serve as the technical point of contact for auditors and assessors and drive the compliance workstream to completion, coordinating interviews, artifact requests, demonstrations, remediation activities, dependencies, and key audit milestones across teams.
  • Cloud Security Engineering (AWS)
    • Secure and harden production AWS environments across Cerbo and OptiMantra, including cloud infrastructure, Kubernetes and container environments, databases, networking, web application security, and disaster recovery environments.
    • Implement and operate AWS security controls and tooling, including IAM and privileged access management, MFA, least-privilege access, security monitoring, encryption and key management, vulnerability management, and audit logging.
    • Strengthen security across both platforms by establishing and advancing common standards for access, tenant isolation, data protection, backup and disaster recovery, and other cloud security controls, partnering with Engineering, DevOps, IT, and Product to implement and maintain these controls.
  • Security Operations & Detection
    • Establish and operate security monitoring and detection capabilities, including centralized logging, alerting, threat detection, and response processes tailored to the company’s clinical SaaS environment.
    • Own the security incident response and vulnerability management programs, including playbooks, tabletop exercises, breach assessment, vulnerability scanning, remediation tracking, and coordination with Engineering and external security providers.
    • Lead security testing and continuous improvement efforts, including penetration testing, DAST, security assessments, findings remediation, and retesting.
  • Endpoint, Identity & Corporate Security
    • Own and maintain security policies, procedures, and workforce security programs across the combined organization, including security awareness, phishing simulations, HIPAA training, and compliance tracking.
    • Lead identity and endpoint security practices to protect corporate systems, users, and sensitive data, partnering with IT and Engineering to implement and continuously improve security controls.
    • Manage third-party security and vendor risk, including security assessments, business associate agreements, subprocessor diligence, and ongoing oversight of vendors that access or process PHI.
  • Customer-Facing Security
    • Serve as the technical security partner for customers and strategic partners, leading security questionnaires, architecture reviews, and security discussions with clinic IT and enterprise security teams.
    • Support customer and partner security requirements throughout the sales and contracting process, including security terms related to incident notification, data retention and export, backup and disaster recovery, AI, and subprocessors.

Qualifications

  • 5+ years of experience in cybersecurity or information security, with increasing responsibility in security engineering.
  • 2+ years of experience securing production cloud environments, preferably AWS, including cloud identity and access management, network security, logging/monitoring, and security controls.
  • Demonstrated experience with the AWS security ecosystem, including IAM, CloudTrail, GuardDuty, Security Hub, KMS, VPC security and related AWS security services.
  • Experience implementing, maintaining and evidencing security controls aligned with frameworks and standards such as NIST, HITRUST, ISO 27001, HIPAA, SOC 2, or similar.
  • Experience securing Kubernetes and containerized production environments, including identity, network security, image security, and runtime controls.
  • Experience serving as a technical owner during a third-party security audit, assessment, or certification.
  • Experience deploying, configuring, and operating cybersecurity tools in production, such as EDR, SIEM/log management, vulnerability management, WAF, or similar technologies.
  • Demonstrated ability to lead complex cybersecurity initiatives, establish security standards and processes, and serve as a technical subject-matter expert across the organization.

Preferred Qualifications

  • Bachelor’s degree in cybersecurity, information security or relevant field.
  • Experience working in a PE-backed, high-growth, or rapidly scaling organization.
  • Experience working with healthcare technology, SaaS or other technology-enabled B2B businesses.
  • Experience securing multi-tenant SaaS environments, including tenant isolation, access controls, and shared infrastructure.
  • Experience working across cloud, DevOps, SRE, or application security environments, with exposure to infrastructure as code, CI/CD, Kubernetes, secure code practices, or vulnerability remediation.

Compensation & Benefits

  • Competitive compensation based on experience.
  • Paid Time Off and company holidays.
  • Comprehensive health, dental and vision benefits.
  • Short-term and long-term disability Insurance.
  • 401k plan with matching company contribution.
  • Real ownership and impact in a fast-growing health tech company.
Before You Apply
️
🇺🇸 Be aware of the location restriction for this remote position: USA Only
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Lead Cybersecurity Engineer @Cerbo OptiMantra
All Others
Salary unspecified
Remote Location
🇺🇸 USA Only
Employment Type full-time
Posted YDay
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 130,000+ Remote Jobs
️
🇺🇸 Be aware of the location restriction for this remote position: USA Only
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 130,000+ Remote Jobs
×
Apply to the best remote jobs
before everyone else

Access 130,000+ vetted remote jobs and get daily alerts.

4.9 ★★★★★ from 500+ reviews

⚡ 131,063+ remote jobs, refreshed hourly

🔔 Real-time alerts: Apply first, direct to employer

🛡️ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later