Head of Security

Medplum

San Francisco, Northern (CA, KY)

Hybrid

USD 230,000 - 320,000

Full time

5 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Competitive equity package
Flexible time off
Impact on healthcare tech

Job summary

Medplum is seeking a hands-on Head of Security to own the security program end-to-end for healthcare infrastructure. This role spans security engineering, incident response, compliance, customer security, and risk management, with deep technical work alongside engineers.

You will review architectures, investigate security issues, and lead cross-functional security initiatives to protect sensitive information and ensure regulatory compliance across SOC 2, HIPAA, and HITRUST.

Qualifications

  • Deep technical experience in security for production systems handling sensitive data.
  • Experience owning or leading security programs end-to-end.
  • Ability to investigate complex security issues independently and with engineers.

Responsibilities

  • Own Medplum's security program, strategy, policies, controls and roadmap.
  • Lead security engineering across application and cloud security, IAM, logging, and secrets management.

Skills

Security leadership
Security engineering
Incident response
Compliance
Cloud security
Risk management
Communication with stakeholders
Security incident response

Tools

AWS
Kubernetes
PostgreSQL

Job description

Security and trust are fundamental to Medplum. We operate critical healthcare infrastructure, store and process sensitive health information, and support healthcare organizations ranging from startups to large enterprises.

As Medplum's Head of Security, you will own the company's security program end-to-end. This is a broad, hands-on leadership role spanning security engineering, incident response, compliance, customer security, and risk management.

One day you might be reviewing the authorization model for a new platform feature, the next leading an incident investigation, responding to a customer security assessment, working with an auditor on HITRUST controls, or helping an enterprise customer understand Medplum's security architecture.

We are looking for someone who combines deep technical judgment with the communication skills to represent Medplum confidently with customers, auditors, partners, and executive stakeholders.

This is not a governance-only role. Medplum is a small engineering-driven company, and our Head of Security should be comfortable going deep into systems, reading code and logs, investigating incidents, and working directly with engineers to solve difficult security problems.

What You Will Do
Own Medplum's Security Program

Take responsibility for Medplum's security strategy, policies, controls, risk management, and security roadmap. Identify the most important risks facing the company and work with engineering and company leadership to address them pragmatically.

Lead Security Engineering

Work directly with Medplum's engineering team on application security, cloud security, authentication and authorization, tenant isolation, vulnerability management, dependency security, secrets management, logging, and other security-sensitive areas of the platform.

Review architecture and code when appropriate, help investigate security bugs, and translate security requirements into concrete engineering work.

Own Medplum's security incident response process. Lead investigations, coordinate technical response, preserve and analyze relevant evidence, communicate clearly with customers and company leadership, and continuously improve our ability to detect and respond to security events.

Own Security and Compliance Programs

Lead Medplum's security-related compliance programs, including SOC 2, HIPAA, HITRUST, and other healthcare security and certification requirements.

Work with auditors and assessors, maintain policies and evidence, coordinate remediation work, and help ensure that compliance activities produce meaningful security improvements rather than becoming checkbox exercises.

Work Directly With Customers

Represent Medplum in customer security reviews, enterprise diligence processes, architecture discussions, and security questionnaires.

Build trust with security engineers, CISOs, compliance teams, technical executives, and other customer stakeholders. Explain complex security topics clearly and accurately, and help customers understand how Medplum approaches security and risk.

Build a Security Culture

Help make security part of how Medplum engineers and operates the product rather than a separate review step.

Improve internal security tooling, documentation, processes, training, and engineering practices. Over time, help define and build the security team as Medplum grows.

About You
  • You have deep technical experience in software, infrastructure, cloud, or application security.
  • You have experience owning or leading security for production systems that handle sensitive or regulated data.
  • You can investigate a complex security issue yourself rather than relying entirely on another engineering team.
  • You understand modern application security concepts including authentication, authorization, OAuth, web security, APIs, networking, cloud infrastructure, databases, and secure software development.
  • You have experience leading or materially participating in security incident response.
  • You communicate clearly with engineers, customers, executives, auditors, and other external stakeholders.
  • You are comfortable making risk-based decisions in situations where there is not a perfect or zero-risk solution.
  • You are pragmatic. You look for ways to make ambitious products secure rather than defaulting to saying no.
  • You enjoy operating in a fast-moving startup environment where roles are broad and important problems do not always arrive neatly packaged.
  • You have 8+ years of experience in security engineering, software engineering, infrastructure security, security leadership, or related roles.
  • You're based in the SF Bay Area and available for twice-weekly in-person collaboration.
Bonus
  • Experience securing healthcare technology or other highly regulated software.
  • Experience with HIPAA, SOC 2, HITRUST, or similar security and compliance frameworks.
  • Experience with AWS, Kubernetes, PostgreSQL, or large-scale SaaS infrastructure.
  • Experience securing multi-tenant SaaS platforms or developer infrastructure.
  • Experience with open source software and open source security.
  • Experience supporting enterprise security reviews and customer diligence.
  • Experience building or scaling a security function at an early-stage or growth-stage company.
About Medplum

Medplum is redefining healthcare with our open source, API-first electronic health record (EHR) platform, trusted by leading digital health and life sciences companies. Our mission is to catalyze change in the healthcare industry by improving the access, privacy, and utility of health data. At Medplum, we have a unique opportunity to impact the lives of patients, speed medical research, and contribute to the open source ecosystem.

  • Competitive compensation package with equity
  • Flexible time off
  • The chance to shape the future of healthcare tech – leave your mark on this vital industry
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

Medplum • San Francisco (CA), Northern (KY)

Hybrid
USD 150,000 - 210,000
Equity
Flexible time off
Head of Security & Trust for Healthcare Tech
Head of Security & Trust for Healthcare Tech

Medplum • San Francisco (CA), Northern (KY)

Hybrid
USD 230,000 - 320,000
Competitive equity package
Flexible time off
Impact on healthcare tech
VP of Engineering
VP of Engineering

SupportFinity™ • California (MO)

On-site
USD 260,000 - 380,000
Equity
Flexible time off
Healthcare package
+1
Security Engineer: Build Secure Healthcare Infra & Tools
Security Engineer: Build Secure Healthcare Infra & Tools

Medplum • San Francisco (CA), Northern (KY)

Hybrid
USD 150,000 - 210,000
Equity
Flexible time off
Head of Security
Head of Security

RXinsider LTD. • San Francisco (CA), Northern (KY)

Hybrid
USD 300,000 - 380,000
Healthcare Coverage
401(k) with Company Match
Equity
+5
Developer Experience Engineer
Developer Experience Engineer

SupportFinity™ • San Francisco (CA)

On-site
USD 120,000 - 160,000
Sr Director, IT Head of Security Operations
Sr Director, IT Head of Security Operations

CyberJobs.Com • San Francisco (CA)

On-site
USD 250,000 - 450,000
Healthcare Coverage
401(k) with Company Match
Equity
+5
Cloud Security Operations Engineer (GCP/AWS) - Remote
Cloud Security Operations Engineer (GCP/AWS) - Remote

Medable • United States

Remote
USD 140,000 - 175,000
Remote from start
Stock options
Annual performance-based bonus
+1
Head of Security Engineering
Head of Security Engineering

Candid Health • San Francisco (CA)

On-site
USD 180,000 - 280,000
Head of Security
Head of Security

Verse Medical, Inc. • New York (NY), Northern (KY)

Hybrid
USD 140,000 - 190,000
Competitive compensation
100% health insurance coverage
401(k) with no matching at this time
+1