Cybersecurity Engineer

Iterative Health

Southlake (TX)

Hybrid

USD 140,000 - 210,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid work
Medical coverage
Mental health support
HSA/FSA options
Unlimited PTO
401(k)
Lunch benefit
Disability coverage
Wellness stipend

Job summary

Iterative Health is seeking its first dedicated cybersecurity leader to build and scale a security program across AWS, IAM, and SaaS, protecting clinical data and infrastructure while collaborating with IT, Eng, Compliance and Legal.

You will own incident response, risk management, and governance, shaping policies and controls in a fast-growing healthcare technology environment.

Qualifications

  • Bachelor's degree in IT, engineering, mathematics, or related field; certifications may substitute.
  • 5+ years of experience in cybersecurity, security engineering, cloud security, or related role.
  • Strong working knowledge of HIPAA, HITECH, SOC 2, and HITRUST.
  • Hands-on experience with AWS, Microsoft 365, and Google Workspace security tooling.
  • Experience with security tooling such as Okta, Entra ID, Microsoft Defender, and SIEM/logging tools.

Responsibilities

  • Own end-to-end security landscape including AWS, IAM, SaaS ecosystem, and cloud security posture.
  • Develop and enforce security policies, standards, runbooks, and control documentation.
  • Lead incident response, investigations, containment, remediation, and post-incident improvements.
  • Collaborate with IT, Engineering, Compliance, Legal, and business leaders to reduce risk.

Skills

Security architecture
Cloud security
RBAC
Incident response
Policy writing
Communication
PowerShell
Python
Vulnerability management
SIEM/logging tools

Education

Bachelor's degree in IT/Engineering/related

Tools

AWS Security tooling
Okta
Entra ID
Microsoft Defender
Intune
Purview
Google Workspace security
SIEM

Job description

Iterative Health is a healthcare technology and services company powering the acceleration of clinical research to transform patient outcomes.

We built a leading performance-driven network of 100+ sites across the US, Europe, India, and Australia, conducting research directly in the communities where care is delivered across gastrointestinal, hepatology, obesity, and cardiology. By combining deep clinical trial expertise with cutting-edge AI, we connect sponsors' scientific ambitions with high-performing research teams that expedite and expand access to novel therapeutics for patients in need. Today, Iterative Health is headquartered in Cambridge, Massachusetts, and New York City with 250+ employees world-wide.

As Iterative Health's first dedicated cybersecurity hire, you won't be stepping into an existing security program—you'll be building it. This is a rare opportunity to establish and lead the company's cybersecurity strategy, creating the foundation that will protect our people, technology, data, and business as we continue to scale.

In this role, you'll own the end-to-end security landscape, including our AWS cloud infrastructure, identity and access management, SaaS ecosystem, endpoint security, sensitive clinical and patient data, and the security and compliance frameworks that support our business. You'll work cross-functionally with IT, Engineering, Compliance, Legal, and business leaders to strengthen our security posture, reduce organizational risk, and embed security into every aspect of the company.

We're looking for a hands-on security leader who combines deep technical expertise with strong business judgment and a builder's mindset. You'll be equally comfortable architecting security solutions, responding to evolving threats, developing policies and controls, and influencing stakeholders across the organization. This is an opportunity to create a scalable, modern security program that grows alongside a fast-paced healthcare technology company.

Where You’ll Drive Impact
Security Program Development
  • Serve as Iterative Health's first dedicated cybersecurity resource — build, mature, and operate the company's security program from the ground up.
  • Identify security gaps, prioritize remediation, and partner with the IT Director to define security priorities, roadmap items, and risk reduction plans.
  • Develop, maintain, and enforce security policies, standards, procedures, runbooks, and control documentation.
  • Provide company-wide subject matter expertise and support related to cybersecurity awareness and compliance.
  • Work with engineering team to secure and monitor AWS environments, including IAM, logging, encryption, backups, access controls, and overall cloud security posture.
  • Configure firewalls, encryption, and access controls across cloud and corporate infrastructure.
  • Improve security controls across Okta, Entra ID, Microsoft 365, Google Workspace, Box, SharePoint, AWS, and other cloud platforms.
Identity & Access Governance
  • Maintain and improve RBAC, access reviews, privileged access controls, admin role governance, service account oversight, and joiner/mover/leaver security processes.
  • Own incident response for suspected cyberattacks, account compromise, malware, data exposure, unauthorized access, and other security events.
  • Lead incident investigation, containment, remediation, documentation, root-cause analysis, and post-incident improvement tracking.
Compliance & Risk Management
  • Own security evidence collection, control documentation, remediation tracking, and audit support for SOC 2, HIPAA/HITECH, and applicable GDPR requirements.
  • Own all vendor assessment and security questionnaire responses.
  • Support vulnerability management, penetration testing, social engineering testing, customer security reviews, vendor security questionnaires, third-party risk assessments, security awareness, and user education.
  • Performs related duties as requested.
What You Bring to the Team
  • Bachelor's degree in IT, engineering, mathematics, or a related field; candidates with extensive cybersecurity certification in lieu of a degree will be considered.
  • 5+ years of experience in cybersecurity, security engineering, cloud security, IT security, or a related technical security role.
  • Strong working knowledge of HIPAA, HITECH, SOC 2, and HITRUST frameworks.
  • Hands-on experience with AWS, Microsoft 365, and Google Workspace security tooling.
  • Experience with Bitdefender, Microsoft Defender, Intune, Entra ID, Microsoft Purview, Google Workspace security, Okta, or SIEM/logging tools.
  • Strong documentation skills, including policy and procedure writing.
  • Ability to communicate effectively with non-technical business partners.
  • Experience with PowerShell, Python, APIs, or security workflow automation.
  • Experience with vulnerability management, penetration test remediation, phishing simulation programs, or third-party risk reviews.
Preferred Qualifications
  • Knowledge of EU General Data Protection Regulation (GDPR).
  • One or more relevant certifications, including but not limited to: CompTIA Security+, CySA+, or Pen Test+; GCIH; ISC2 CCSP; AWS Certified Security Specialty (SCS-C03); Microsoft SC-200, SC-300, SC-401, SC-100, or SC-900; Google Cybersecurity Professional or Cloud Cybersecurity Certificate.
  • Experience building or maturing a security program in a high-growth or startup environment.
  • Background in healthcare technology, clinical research, or other highly regulated industries.
How We Work
  • Collaborative and low-ego team environment
  • High ownership and accountability culture
  • Fast-paced and highly iterative growth environment
  • Open communication and continuous learning mindset
  • Mission-driven organization focused on improving patient outcomes
  • Comfortable navigating evolving business priorities and opportunities
Benefits That Support You

We believe great teams do their best work when they feel supported — professionally and personally.

  • Hybrid work environment with in-office collaboration two days per week in either our NYC or Boston office
  • Comprehensive medical, dental, and vision coverage, with up to 80% of premiums covered by Iterative Health
  • Mental health and wellness support through Spring Health
  • Health HSA or FSA options, and commuter FSA contributions supported by Iterative Health
  • Unlimited PTO, 12 company holidays, and a company-wide shutdown between Christmas and New Years
  • 401(k) program with a company match of up to 3% (up to $3,000 annually)
  • Weekly in-office lunch benefit every Tuesday
  • 100% company-paid short-term and long-term disability coverage
  • Annual wellness and professional development stipend to support your health and growth
  • And more!

At Iterative Health, we’re actively working towards creating an environment that is representative of the diversity of patients our technology serves. We are focused on building an equitable and inclusive culture, and by extension, hiring process. If you require any accommodations to make the application process or interviewing experience more accessible to you, please contact CandidateAccommodations@iterative.health.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Engineer
Cybersecurity Engineer

Iterative Scopes • Cambridge (MA)

On-site
USD 180,000 - 240,000
Hybrid work
Medical, dental, vision
Wellness benefit
+1
First Cybersecurity Lead — Health Tech & Cloud Security
First Cybersecurity Lead — Health Tech & Cloud Security

Iterative Scopes • Cambridge (MA)

Hybrid
USD 180,000 - 240,000
Hybrid work
Medical, dental, vision
Wellness benefit
+1
Clinical Data Specialist
Clinical Data Specialist

Iterative Health • New York (NY)

On-site
USD 60,000 - 80,000
Comprehensive medical, dental, and vision coverage
Mental health and wellness support
Unlimited PTO and 12 company holidays
+1
Clinical Data Specialist
Clinical Data Specialist

Iterative Health • Southlake (TX)

Hybrid
USD 60,000 - 90,000
Hybrid work environment
Medical, dental, vision
401(k) with company match
+2
Clinical Data Specialist
Clinical Data Specialist

Iterative Health • Cambridge (MA)

Hybrid
USD 70,000 - 100,000
Hybrid work arrangement with two in‑in
Medical, dental, and vision insurance
Wellness programs
+6
Clinical Data Specialist
Clinical Data Specialist

Iterative Scopes • Dallas (OR)

Hybrid
USD 55,000 - 75,000
Comprehensive medical, dental, and vision coverage
Unlimited PTO and 12 company holidays
401(k) program with company match
+1
Business Development Associate - Cardiology
Business Development Associate - Cardiology

Iterativehealth • Town of Cambridge (NY)

Hybrid
USD 75,000 - 100,000
Hybrid work environment
Unlimited PTO
401(k) match
+2
Clinical Data Specialist
Clinical Data Specialist

Iterative-Health • Cambridge (MA)

Hybrid
USD 65,000 - 90,000
Hybrid work two days in NYC or Boston
Medical, dental, vision coverage
Mental health support
+7
Director, Life Sciences
Director, Life Sciences

Iterative Health • Dallas (TX)

Hybrid
USD 180,000 - 250,000
Hybrid work environment
Medical + dental + vision
401(k) match
+2
Staff Software Engineer
Staff Software Engineer

Iterativehealth • Town of Cambridge (NY)

On-site
USD 200,000 - 325,000