Lead, Cybersecurity

Smartlinx

United States

On-site

GBP 104,000 - 127,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Remote environment
Medical, Dental, Vision
FSA & HSA
Life Insurance
Pet Insurance
401(k)

Job summary

Smartlinx is seeking a Lead, Cybersecurity to define and operate our comprehensive security program across its multi-tenant SaaS products, cloud infrastructure, and data platforms. This leadership role partners with Product, Engineering, Compliance, and Legal to embed security throughout design, development, and operations.

The successful candidate will own SOC 2 Type II readiness, IAM, vulnerability management, incident response, and third‑party risk, ensuring compliance while enabling reliable

Qualifications

  • Bachelor's degree in Cybersecurity or related field.
  • 8+ years in security disciplines with leadership role.
  • Experience securing multi-tenant B2B SaaS in healthcare or regulated environments.
  • Lead SOC 2 Type II audits end-to-end.
  • Strong Azure security experience across cloud and apps.
  • Knowledge of SOC 2, NIST, CIS, ISO 27001, and HITRUST.
  • Ability to balance security with product delivery and communicate to executives.

Responsibilities

  • Define and operate cybersecurity strategy and roadmaps.
  • Lead product, cloud, and data security across multi-tenant SaaS.
  • Oversee incident response, vulnerability management, and third‑party risk.
  • Collaborate with cross‑functional teams for secure software delivery.
  • Drive audit readiness and governance with auditors and execs.
  • Establish security metrics and reporting.

Skills

Security leadership
Cloud security
Threat modeling
SOC 2 readiness

Education

Bachelor's degree in Cybersecurity or related field

Tools

Azure
Entra ID
CI/CD tooling
SIEM

Job description

Description

Since 2000, Smartlinx has been redefining how senior care organizations manage their workforce. Our modern, purpose-built solutions from dynamic scheduling and compliance to integrated payroll and real-time analytics give providers the agility and intelligence needed to thrive in today's healthcare environment.

Since 2000, Smartlinx has been redefining how senior care organizations manage their workforce. Our modern, purpose-built solutions from dynamic scheduling and compliance to integrated payroll and real-time analytics give providers the agility and intelligence needed to thrive in today's healthcare environment.

As the parent company of BekTek (HostedTime) and StafferLink, Smartlinx brings together a wide range of solutions for managing both full-time and contingent staff. Together, these capabilities give Smartlinx the most comprehensive workforce management solution set in senior care.

We are driven by one mission: to power exceptional senior care through smarter workforce management. Join us as we shape the future of work in long-term care.

About The Role

Reporting to the Head of IT, the Lead, Cybersecurity is responsible for defining and operating Smartlinx's cybersecurity program across its multi-tenant SaaS products, cloud infrastructure, corporate technology environment, data platforms, integrations, and third-party services.

This leader owns SaaS product and application security, cloud and infrastructure security, identity and access management, vulnerability management, security monitoring, incident response, third-party risk, and SOC 2 Type II readiness and audit execution. The role is accountable for protecting sensitive healthcare workforce, payroll, personally identifiable information, and customer data while enabling reliable and timely product delivery.

The Lead, Cybersecurity will partner closely with Product, Engineering, Architecture, Quality Assurance, DevOps, Data Engineering, Corporate IT, Compliance, Legal, Customer Support, and Customer Success to integrate security into design, development, deployment, operations, and customer commitments.

Success in this role requires a hands‑on, pragmatic security leader who can translate business and regulatory requirements into effective technical controls, personally investigate risk and incidents, drive remediation to closure, and communicate clearly with executives, auditors, customers, and technical teams.

Key Responsibilities

SaaS Product and Application Security

  • Own the product-security strategy and operating model across the Smartlinx, BekTek (HostedTime), and StafferLink product portfolio.
  • Embed security throughout the product development lifecycle, including requirements, architecture, design, development, testing, release, and production operation.
  • Lead threat modeling, security architecture reviews, abuse‑case analysis, and risk assessments for new products, features, APIs, integrations, mobile applications, and material platform changes.
  • Establish secure coding standards and engineering guidance based on OWASP, CWE, API security, and relevant industry practices.
  • Integrate automated security testing into CI/CD pipelines, including static application security testing, dynamic application security testing, software composition analysis, secrets scanning, infrastructure‑as‑code scanning, container scanning, and software bill of materials generation.
  • Review and strengthen authentication, authorization, role‑based access control, session management, tenant isolation, API security, file handling, encryption, audit logging, and secure data‑export capabilities.
  • Plan and coordinate independent application and API penetration testing, validate findings, assign risk‑based remediation deadlines, and confirm closure through retesting.
  • Assess AI‑enabled product capabilities and third‑party AI services for prompt injection, data leakage, tenant isolation, model access, sensitive‑data handling, human oversight, and other emerging risks.
  • Define proportionate release‑security gates and exception processes that protect customers without creating unnecessary friction for engineering delivery.

Cloud and Infrastructure Security

  • Lead security architecture and control implementation for Smartlinx's Microsoft Azure cloud environments, production and non‑production infrastructure, corporate systems, endpoints, networks, and remote‑work capabilities.
  • Establish secure cloud baselines using recognized frameworks and vendor guidance; continuously identify and remediate configuration drift, exposed services, excessive permissions, unsupported software, and insecure defaults.
  • Strengthen network security through segmentation, private connectivity, firewall and security‑group governance, DDoS protection, secure administrative access, and controlled ingress and egress.
  • Implement and govern secrets management, certificate management, encryption, key rotation, secure service identities, and protection of privileged credentials across applications and infrastructure.
  • Partner with DevOps and Corporate IT to maintain effective patching, endpoint protection, malware defense, vulnerability scanning, cloud security posture management, and secure configuration management.
  • Review the security of databases, data lakes, warehouses, analytics platforms, ETL and ELT pipelines, customer data exchanges, backups, and disaster‑recovery environments.
  • Ensure logging, telemetry, alerting, and forensic data are available across cloud resources, applications, identities, endpoints, networks, and data platforms to support timely detection and investigation.
  • Assess resilience to destructive cyber events, including ransomware and credential compromise, and validate recoverability through protected backups, restoration tests, and cyber‑recovery exercises.

SOC 2, Healthcare Compliance, and Audit Readiness

  • Lead Smartlinx's SOC 2 Type II readiness, control design, evidence collection, auditor coordination, remediation, management responses, and annual attestation cycle.
  • Build a continuous‑control‑monitoring program that keeps the organization audit‑ready throughout the year rather than relying on a point‑in‑time preparation effort.
  • Define, document, test, and improve controls across access management, change management, secure software development, vulnerability management, incident response, vendor risk, data protection, and business continuity.
  • Maintain the control matrix, security policies, standards, procedures, risk register, evidence repository, exception records, remediation plans, and executive compliance reporting.
  • Apply healthcare security and privacy requirements, including HIPAA and HITECH, to product, infrastructure, operational, vendor, and data‑handling decisions; support business associate and customer contractual obligations.
  • Evaluate alignment with NIST, CIS Controls, ISO 27001, and HITRUST expectations where they strengthen the security program or support customer and market requirements.
  • Coordinate effectively with external auditors, penetration‑testing providers, legal counsel, cyber‑insurance partners, customers, and other independent assessors.
  • Lead or support responses to customer security questionnaires, due‑diligence reviews, contractual security requirements, and customer audit requests with accurate, consistent, and timely information.

Vulnerability, Risk, and Third‑Party Security

  • Establish a unified vulnerability‑management program covering SaaS applications, APIs, cloud infrastructure, endpoints, containers, databases, open‑source components, and third‑party software.
  • Prioritize remediation using severity, exploitability, exposure, asset criticality, data sensitivity, customer impact, compensating controls, and active‑threat intelligence rather than relying on CVSS scores alone.
  • Define measurable remediation service‑level targets for critical, high, medium, and low‑risk findings; monitor aging, exceptions, recurrence, and closure quality.
  • Own formal security‑risk acceptance, exception, escalation, and expiration processes, ensuring material risks receive appropriate executive visibility and approval.
  • Conduct periodic enterprise, product, cloud, and data‑security risk assessments and translate findings into prioritized, funded remediation roadmaps.
  • Evaluate vendors, subprocessors, managed services, technology partners, and AI providers for security, privacy, resilience, data handling, incident notification, and contractual risk before onboarding and throughout the relationship.
  • Monitor changes in the threat landscape, exploited vulnerabilities, attack techniques, and healthcare‑sector risks; convert relevant intelligence into actionable protections and tests.

Security Operations, Incident Response, and Resilience

  • Define and operate security monitoring across applications, cloud infrastructure, identities, endpoints, networks, databases, and data platforms using SIEM, EDR, WAF, and related capabilities.
  • Develop high‑value detection use cases for account compromise, privilege escalation, anomalous access, data exfiltration, malicious application activity, insecure configuration changes, and other material threats.
  • Own the cybersecurity incident‑response plan, severity model, escalation paths, on‑call expectations, investigation procedures, communications protocols, evidence handling, and post‑incident review process.
  • Lead or coordinate containment, eradication, recovery, forensic analysis, customer‑impact assessment, regulatory and contractual notification support, and executive communication during security incidents.
  • Conduct regular tabletop exercises involving executive leadership, Engineering, DevOps, IT, Legal, Compliance, Customer Support, Customer Success, and Communications; document gaps and drive corrective actions to closure.
  • Track and improve security operational measures such as mean time to detect, acknowledge, contain, recover, and permanently remediate incidents and recurring control failures.
  • Establish relationships and operating procedures with external incident‑response, forensic, legal, insurance, and specialized security partners before an incident occurs.

Identity, Data Protection, and Privacy by Design

  • Establish an identity‑first security model based on least privilege, multifactor authentication, privileged access management, separation of duties, conditional access, and periodic access certification.
  • Strengthen joiner, mover, and leaver processes for employees, contractors, service accounts, customer support access, production access, and privileged roles.
  • Define and govern security controls for Microsoft Entra ID, application identities, API credentials, machine accounts, emergency access, and third‑party access.
  • Partner with data owners, Product, Legal, Compliance, and Engineering to implement data classification, minimum‑necessary access, encryption, masking, retention, deletion, and secure disposal.
  • Protect sensitive healthcare workforce, payroll, tax, financial, personally identifiable, and authentication data throughout collection, processing, storage, transmission, sharing, export, backup, and disposal.
  • Implement data‑loss‑prevention controls and monitoring appropriate to corporate systems, SaaS products, data platforms, collaboration tools, endpoints, and customer data‑sharing workflows.
  • Incorporate privacy and security by design into product decisions, integration patterns, analytics, AI use cases, customer implementations, and vendor engagements.

Security Governance, Leadership, and Performance Management

  • Develop and execute a practical, risk‑based cybersecurity strategy, annual operating plan, budget, staffing model, and multiyear roadmap aligned with Smartlinx's product and business priorities.
  • Define clear security ownership, decision rights, standards, escalation paths, and measurable objectives across Product, Engineering, DevOps, Data Engineering, Corporate IT, and business functions.
  • Create executive and Board‑level security reporting that clearly communicates material risks, incidents, audit readiness, remediation progress, control effectiveness, investment needs, and business tradeoffs.
  • Establish a concise cybersecurity scorecard covering critical exposure, remediation aging, secure‑development adoption, privileged access, control performance, incidents, vendor risk, audit findings, and security‑awareness outcomes.
  • Select, manage, and rationalize security tools and platforms; ensure investments produce measurable risk reduction and operational value.
  • Build a culture of accountability and partnership in which teams understand their security responsibilities and raise risks early without fear of blame.
  • Deliver role‑based security education for engineers, administrators, support teams, executives, and the broader workforce, including phishing resistance and incident‑reporting readiness.
  • Recruit, coach, and develop security employees or contractors as the function grows, while remaining personally engaged in architecture, investigation, remediation, and audit execution.
Requirements
Qualifications
  • Bachelor's degree in Cybersecurity, Computer Science, Engineering, Information Systems, or a related field, or equivalent practical experience.
  • 8+ years of progressive experience across product, application, cloud, infrastructure, or security‑operations disciplines, including 3+ years in a lead, principal, architect, or security‑program ownership role.
  • Demonstrated experience securing multi‑tenant B2B SaaS products in healthcare, payroll, HR technology, or another regulated environment and protecting PHI, PII, financial, or other sensitive data.
  • Direct, hands‑on experience leading at least one successful SOC 2 Type II audit cycle, including control design, evidence collection, auditor coordination, remediation, management responses, and continuous control operation.
  • Strong Microsoft Azure security experience across cloud networking, identity, compute, storage, databases, containers, Kubernetes, infrastructure as code, secrets, logging, monitoring, backup, and recovery.
  • Deep knowledge of secure software development, threat modeling, web, mobile, and API security, authentication, authorization, tenant isolation, OWASP risks, and DevSecOps practices.
  • Hands‑on experience with SAST, DAST, SCA, SBOM, secrets scanning, SIEM, EDR, DLP, WAF, CSPM, vulnerability scanning, penetration testing, and related security capabilities.
  • Proven ability to manage vulnerabilities, security findings, and incidents through risk assessment, containment or remediation, retesting, exception management, post‑incident review, and executive reporting.
  • Strong knowledge of the SOC 2 Trust Services Criteria, NIST Cybersecurity Framework, CIS Controls, ISO 27001, and HITRUST.
  • Demonstrated ability to make sound risk‑based decisions, balance security with product delivery, influence cross‑functional stakeholders, and explain technical risks clearly to executives, auditors, customers, and engineers.
  • Relevant certifications such as CISSP, CCSP, CISM, CISA, CSSLP, OSCP, GIAC, HITRUST CCSFP, or Microsoft Azure Security Engineer are preferred; experience with Entra ID, Defender, Sentinel, Azure DevOps, Snowflake, or Microsoft Fabric is also preferred.
Additional Information
  • Position Type: Full-Time
  • Work Location: Remote
  • Travel Requirements: Occasional travel, up to 15%

Smartlinx values and celebrates diversity, equity, inclusion and belonging and evaluate qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other protected characteristic. We value your hard work, integrity, and commitment to make things better, and we put people first by offering you benefits that support your life and well-being including remote environments as applicable, Medical, Dental, Vision, FSA & HSA, Life Insurance, Pet Insurance and 401(k). Join us and you’ll develop your skills and expertise to rise to the very highest levels, working in an environment for a company known for brilliance and innovation.

Salary Description

$150K + 10% bonus eligible

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Engineer, Managed Services
Senior Cybersecurity Engineer, Managed Services

Critical-Start- • Washington

On-site
USD 120,000 - 140,000
Competitive salary with bonuspotential
Comprehensive health benefits
Unlimited PTO
+3
Staff DevSecOps Engineer (Health 100)
Staff DevSecOps Engineer (Health 100)

9025 CVS Shared Services Resources LLC • Massachusetts

Hybrid
USD 130,000 - 260,000
Senior Cybersecurity Engineer, Managed Services
Senior Cybersecurity Engineer, Managed Services

Critical Start • Austin (TX)

On-site
USD 120,000 - 140,000
Unlimited PTO
Health benefits
401(k) with matching
Implementation Project Manager
Implementation Project Manager

SmartLinx Solutions, LLC • New Jersey

On-site
USD 75,000 - 100,000
Medical, Dental, and Vision insurance
FSA & HSA
Life Insurance
+2
Client Payroll Services Manager
Client Payroll Services Manager

Smartlinx, LLC. • Hackensack (NJ)

On-site
USD 110,000 - 170,000
Medical
Dental
Vision
+4
Senior Cloud Security Engineer (Remote Ontario)
Senior Cloud Security Engineer (Remote Ontario)

Smile Digital Health • United States

Remote
USD 130,000 - 140,000
Remote Work Environment
Flexible Time Away From Work Policy
Competitive Salary and Health Benefits
+5
Senior Manager, Security & IT Ops
Senior Manager, Security & IT Ops

Hazelcast • Northern (KY)

Hybrid
USD 120,000 - 160,000
Unlimited PTO
Medical/Dental/Vision Insurance
HSA/FSA
+3
IT Security & Compliance Lead (Healthcare)
IT Security & Compliance Lead (Healthcare)

Premium Health Center • New York (NY)

On-site
USD 140,000 - 210,000
Paid time off
Medical, dental, and vision plans
Retirement plans
+1
Sr. Cloud Security Engineer (Remote)
Sr. Cloud Security Engineer (Remote)

Inspira Financial • Oak Brook (IL)

On-site
USD 125,000 - 155,000
Healthcare
401(k)
Paid time off
+2
Senior Staff Engineer - DevSecOps
Senior Staff Engineer - DevSecOps

Exelixis Inc • Alameda (CA)

On-site
USD 154,500 - 220,500
401(k) plan with company contributions
Group medical, dental, and vision coverage
Flexible spending accounts
+1