Director of Security

Sequencing

United States

Remote

USD 180,000 - 320,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Health insurance
401(k) matching
Paid time off
Volunteer time off
Remote work stipend
Parental leave
Genome sequencing benefit

Job summary

Sequencing is hiring its first dedicated security leader to own policy, assurance, AppSec, and incident response for a fully remote company building AI-driven genomic health insights.

You will work directly with the Head of Engineering, setup security strategy from scratch, and scale a small team as the program matures. Expect hands-on work, policy drafting, and threat triage in a fast-paced, AI-first environment.

Qualifications

  • 8+ years in security, incl. as first security leader at a small company
  • Hands-on in AWS and web app security
  • Experience with SOC 2 or HIPAA programs; ISO 27001 a plus
  • Exceptional communicator; able to brief executives in plain language
  • Able to govern AI-enabled security tooling and data handling

Responsibilities

  • Own security program end-to-end: policy, assurance, incident response
  • Lead external pentest firms and drive remediation with engineering teams
  • Define and implement AI-focused security policies and governance
  • Build and coach a small security team as the program scales
  • Report security posture and roadmap to founders in business terms
  • Ensure privacy and breach obligations across HIPAA and other regs

Skills

Security leadership
AWS security
Incident response
Executive communication
AI governance

Tools

Terraform
WAF
SIEM
Cloudflare Enterprise

Job description

About Sequencing

Sequencing is the world’s largest direct-to-consumer whole genome sequencing platform, helping define the future of AI-powered personalized health.

We’re a profitable, venture-backed, fully remote company building products that turn clinical-grade whole genome sequencing into meaningful, personalized insights. Through AI and a rapidly expanding ecosystem of genomic applications, we help people better understand their health and future.

The human genome is one of the most valuable and underutilized resources in the world. Our mission is to transform it into a lifelong source of personalized guidance – and build the trusted home for every genome on Earth.

Join us in helping build the interface between humanity and its DNA!

The Opportunity

Sequencing is hiring its first dedicated security leader. Security today is owned across Engineering and Platform, backed by external penetration testing partners and an active HIPAA program. This role brings it under one owner and builds the function from the ground up.

This is a hands‑on role. You will execute the majority of the work yourself for the first year, from writing policy to triaging pentest findings to configuring controls, and hire and coach a small team as the program matures. If you are looking to direct work rather than do it, this is not the right role.

We are an AI‑first company and expect the same of our security leader. You will use AI daily in your own work, from drafting policy to triaging findings to building detections, and you will set the company's posture on AI as adopt and govern, not restrict. Security here exists to make fast AI adoption safe, not to slow it down.

You report to the Head of Engineering and work alongside Platform Engineering, which owns infrastructure security implementation, and the Bioinformatics and AI functions. The data you protect is whole genome sequences and health data for consumers, which makes this one of the more consequential first‑security‑hire roles available.

First Six Months
  • Create the security ownership map with Platform Engineering: they implement infrastructure controls, you set policy, run assurance, and own AppSec, offensive security, and incident response leadership.

  • Complete a HIPAA and HITECH review and deliver a prioritized remediation roadmap by day 45.

  • Reach SOC 2 readiness within six months, aligned with the infrastructure roadmap.

  • Formalize incident response: severity model, escalation paths, communications, executive coordination, and post‑incident review.

  • Extend security policy to AI tooling and model providers, including data classification, acceptable use, and data‑handling standards.

Ongoing
  • Run the security program: policy, risk register, security awareness and training, and the GRC tooling that keeps evidence current.

  • Run offensive security yourself: scope and manage external pentest firms, triage findings, and drive remediation with the owning teams.

  • Own security review of third‑party data flows: partner and marketplace apps, provider data sharing, marketing and analytics integrations, and AI model providers, including data‑processing terms.

  • Own security standards for contractors, agencies, and third‑party development partners across a distributed workforce, including IP protection, device management, and access lifecycle.

  • Own SaaS governance, shadow IT visibility, and identity lifecycle policy.

  • Apply AI to the security program itself: AI‑assisted detection and log triage, automated evidence collection, policy and control drafting, and code and infrastructure review. Measure and report where it moves the needle.

  • Serve as the escalation point for security incidents, including after hours when needed.

  • Report security posture, risk, and roadmap to the founder and leadership team in plain, business‑oriented language.

  • Translate security findings into practical actions engineering teams can implement without slowing product velocity.

Who You Are
  • 8+ years in security, including at least one stretch as the first or only security leader at a company under a few hundred people. Building from zero matters more here than years or title.

  • Have taken a company through SOC 2 or built a HIPAA program from scratch. ISO 27001 is a plus.

  • Hands‑on in AWS and web application security. You can read a Terraform PR, triage a pentest finding, and tune a WAF rule yourself.

  • Still hands‑on and want to stay that way. You have run pentests through vendors, triaged the findings yourself, and closed them with engineers.

  • Have secured a consumer‑facing product at scale, including identity and account security, MFA, credential stuffing defense, session and account recovery abuse.

  • Understand privacy and breach obligations beyond HIPAA

  • Already work AI‑first. You use coding assistants and LLMs daily and can show us how they changed your security workflow. You believe the answer to "should we block this AI tool" is almost always "no, here is how we govern it."

  • Exceptional communicator under pressure. You have briefed a board, founder, or executive team during a live incident, and you can explain risk and tradeoffs to non‑technical leaders in plain language, in writing and in the room.

Nice to have:

healthcare or genomics experience; familiarity with state genetic privacy laws, the FTC Health Breach Notification Rule, and state breach notification requirements; ecommerce or payment‑processing security; ISO 27001; PCI DSS; Drupal security; GDPR and international data transfers; mobile application security; Vanta or Drata; SIEM; Cloudflare Enterprise; and Zero Trust.

Why Sequencing?

For decades, the human genome has been one of the world’s richest sources of health information—but most people have never been able to truly understand or use it.

We’re changing that.

At Sequencing, we’re transforming billions of genetic variants, decades of scientific research, and constantly evolving genomic knowledge into technology people can interact with naturally and trust when making decisions about their health.

This isn’t about building another health application. It’s about creating an entirely new category of technology that brings together bioinformatics, genetics, and consumer health to improve and extend millions of lives.

Your work won’t just help build Sequencing—it will help redefine how people understand themselves through their DNA for decades to come.

Benefits
  • Comprehensive medical, dental, and vision insurance coverage

  • 401(k) with company matching

  • Paid time off

  • Paid volunteer time off

  • Fully remote work with a home office stipend

  • Parental bonding leave

  • Private and confidential clinical‑grade whole genome sequencing for you and your family

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Director of Security
Director of Security

Namely • United States

Remote
USD 180,000 - 250,000
Comprehensive medical, dental, vision
401(k) with company matching
Paid time off
+4
Senior Product Manager, Consumer
Senior Product Manager, Consumer

Sequencing • United States

Remote
USD 120,000 - 180,000
Comprehensive health insurance
401(k) with company matching
Paid time off
+2
Head of Product & Customer Experience
Head of Product & Customer Experience

Namely • United States

Remote
USD 180,000 - 240,000
Medical, dental, vision insurance
401(k) with company matching
Paid time off
+4
Head of Product & Customer Experience
Head of Product & Customer Experience

Sequencing • United States

On-site
USD 180,000 - 240,000
Health insurance
401(k) matching
Paid time off
+4
Senior Lifecycle Marketing Manager
Senior Lifecycle Marketing Manager

Sequencing • United States

Remote
USD 140,000 - 210,000
Medical Insurance
Dental Insurance
Vision Insurance
+6
Senior Product Manager, Consumer
Senior Product Manager, Consumer

Namely • United States

Remote
USD 140,000 - 190,000
Medical insurance
401(k) with company matching
Paid time off
+4
Associate Creative Director
Associate Creative Director

Sequencing • United States

Remote
USD 120,000 - 210,000
Fully remote work
Home office stipend
Paid time off
+2
Senior Marketing Designer
Senior Marketing Designer

Sequencing • United States

Remote
USD 120,000 - 180,000
Medical, dental, vision coverage
401(k) with company match
Paid time off
+4
Systems R&D Engineer
Systems R&D Engineer

Complete Genomics • San Jose (CA)

On-site
USD 100,000 - 120,000
Gym membership reimbursement
Employee discount program
Comprehensive benefits package
Systems Administrator III
Systems Administrator III

myDNA, Inc. • Houston (TX)

On-site
USD 90,000 - 120,000
Medical & Health Benefits
HSA contributions
401(k) matching
+1