Director Information Security

Outset Medical, Inc.

San Jose (CA)

On-site

USD 130,000 - 170,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

A leading healthcare technology company is seeking an Information Security Leader to oversee cybersecurity and compliance initiatives. You will drive security policies, monitor threats, and ensure regulatory compliance, particularly with HIPAA and FDA standards. Ideal candidates will have extensive experience in security leadership, cloud security, and a strong understanding of risk management frameworks. This role offers the opportunity to significantly impact the organization’s security posture while contributing to patient care advancements.

Qualifications

  • 10+ years in information security with leadership experience preferred.
  • Proven experience with SOC 2, HIPAA, and FIPS compliance.
  • Professional certifications such as CISSP or CISM required.

Responsibilities

  • Lead security program and enforce policies.
  • Assess and improve security posture.
  • Monitor threats and manage incident responses.
  • Conduct vendor security assessments.
  • Ensure regulatory compliance with FDA and HIPAA.

Skills

Cloud security expertise
Risk assessment
Communication skills
Problem-solving
Attention to detail

Education

B.S. or M.S. in Computer Science or Information Security

Tools

AWS tools (CloudTrail, IAM, GuardDuty)
Microsoft 365 security tools (Defender, Sentinel)

Job description

Outset is seeking a hands-on information security leader to drive our cybersecurity and technology risk management program. This individual will be responsible for developing and enforcing security policies, managing governance, risk, and compliance (GRC) activities, executing security operations, and leading strategic projects to advance our security posture. In this role, you will collaborate cross-functionally with software engineering, IT Infrastructure, quality, regulatory, legal and other key stakeholders to continuously evolve and strengthen our cybersecurity program.

This role requires a passion for protecting company assets and a strategic mindset to design and implement scalable security solutions. The ideal candidate will bring deep expertise in both on-premises and cloud security, including insights into cloud native security solutions for Microsoft 365 and AWS platforms.

We’re looking for a leader with exceptional problem-solving skills, high attention to detail, strong organizational acumen, and a proven track record of building enterprise-grade security programs. This is a high-impact opportunity to shape the security foundation of Outset’s mission-driven organization – one that is reimagining dialysis and working to catalyze change for patients who deserve better.

Essential Job Functions and Responsibilities:
  • Serve as the Security Lead and Subject Matter Expert (SME) for all environments, including cloud infrastructure, and on-premises systems.
  • Continuously assess and evolve the organization’s security posture—driving program maturity through strategic assessments, road mapping, stakeholder alignment, and project execution.
  • Monitor the external threat landscape to identify emerging attack vectors, vulnerabilities, and adversary tactics—translating threat intelligence into actionable insights that inform security strategy, initiatives and controls.
  • Ensure security practices and controls align with regulatory requirements, including FDA and HIPAA, and fulfill the requirements and obligations of the HIPAA security officer.
  • Support commercial functions by responding to customer cybersecurity due diligence questionnaires and security assessments—articulating Outset’s security posture, controls, and compliance practices directly to Customers.
  • Lead the vendor security risk assessment process—evaluating third-party partners for compliance with Outset’s security standards, identifying potential risks, and ensuring appropriate controls are in place.
  • Conduct technical evaluations of system architecture with a focus on security design and compliance, leveraging frameworks such as NIST CSF and NIST SP 800-53.
  • Provide strategic leadership in identifying, assessing, and mitigating information security risks; ensure alignment with internal policies and external standards.
  • Monitor emerging threats and lead the organization’s response to security incidents, serving as the primary control point and convening the Incident Response Team to investigate, contain, and resolve events.
  • Develop, maintain, and enforce enterprise cybersecurity policies, standards, and procedures, ensuring alignment with regulatory requirements, industry frameworks, and organizational risk tolerance.
  • Influence technology and architecture decisions as a key member of the IT leadership team.
Required Qualifications:
  • 10+ years of industry experience in an information security function; leadership experience preferred.
  • B.S. or M.S. in Computer Science, Information Security, or a related field.
  • Professional security certifications such as CISSP, CISM, CISA, CCSP, or CEH (or equivalent). Additional certifications like Microsoft Certified: Cybersecurity Architect or AWS Certified Security – Specialty are a plus.
  • Proven experience leading organizations through security certifications and audits, including SOC 2, HIPAA, FIPS, and HITRUST.
  • Demonstrated expertise with cloud security tools and telemetry platforms including experience with AWS (CloudTrail, IAM, Incognito, GuardDuty) and Microsoft 365 (Defender, Entra ID, Purview, Sentinel).
  • Strong knowledge of risk assessment tools, technologies, and methodologies.
  • Exceptional written and verbal communication skills, with the ability to influence technical and non-technical stakeholders.
  • Experience in highly regulated industries.
Desired Qualifications
  • Experience in FDA regulated industries, specifically Medical Device, is strongly preferred.
  • Experience in customer-facing technical roles, with the ability to translate complex security concepts into business-aligned recommendations.
  • Experience planning, researching, and developing security policies, standards, and procedures.
  • Hands-on experience implementing enterprise security capabilities such as identity and access management (IAM), data loss prevention (DLP), endpoint detection and response (EDR), extended detection and response (XDR), security information and event management (SIEM), and security orchestration, automation and response (SOAR).
  • Familiarity with mobile code, malware analysis, and endpoint protection technologies.
  • Proficiency in deploying logging and monitoring tools at scale, with an emphasis on automation and event-driven response.
  • Expertise in designing secure networks, systems, and application architectures.
  • Experience with disaster recovery planning, digital forensics, and incident response tools and techniques.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director, Security
Director, Security

Sequencing Inc. • Northern (KY)

Hybrid
USD 150,000 - 200,000
Head of Information Security
Head of Information Security

Grayson Search Partners • Nashville (TN)

On-site
USD 120,000 - 150,000
Security Engineer
Security Engineer

Birdirx • Plymouth (MI)

Remote
USD 90,000 - 130,000
Senior Security Architect
Senior Security Architect

RXinsider LTD. • Orlando (FL)

On-site
USD 120,000 - 180,000
Senior Manager, Information Security
Senior Manager, Information Security

Scorpion Therapeutics • Berkeley Heights (NJ)

On-site
USD 130,000 - 170,000
Medical, dental & vision
401k match and stock options
Paid time off and holidays
+1
Security Engineer
Security Engineer

Birdi • Plymouth (MI)

Remote
USD 100,000 - 130,000
Cybersecurity Engineer
Cybersecurity Engineer

Iterative Health • Southlake (TX)

Hybrid
USD 140,000 - 210,000
Hybrid work
Medical coverage
Mental health support
+6
Information Security Manager
Information Security Manager

BAE Systems OneArc USA, Inc • Orlando (FL)

Hybrid
USD 140,000 - 190,000
Information Security Engineer
Information Security Engineer

eTrepid • Mechanicsville (MD)

On-site
USD 90,000 - 130,000
Senior Security Engineer
Senior Security Engineer

Sequencing • Township X (SD)

On-site
USD 150,000 - 230,000