Stedi logo

Head of Security (Remote)

Stedi
Remote
Remote· about 3 hours ago

Straight from Stedi’s careers page. Apply on the company site — no recruiter, no middleman.

Head of Security

Department: Engineering

Location: Remote in the USA

Employment Type: FullTime

Were building a new healthcare clearinghouse

Stedi is building the first new healthcare clearinghouse in decades. In the healthcare sector, the Health Insurance Portability and Accountability Act of 1996 (HIPAA) requires that all insurance payers exchange transactions such as claims, eligibility checks, prior authorizations, and remittances using a standardized EDI format called X12 HIPAA. Clearinghouses process the majority of these transactions, offering consolidated connectivity to carriers and providers. Until Stedi, the space was occupied entirely by a small group of legacy players, built on outdated, often pre-internet technology.

Stedi is the worlds only programmable healthcare clearinghouse. By offering modern API interfaces alongside traditional real-time and batch EDI processes, we enable both healthcare technology businesses and established players to exchange mission-critical transactions. Our clearinghouse product and customer-first approach have set us apart. Stedi was ranked by Ramp as one of the fastest-growing SaaS vendors.

We have lightning in a bottle: engineers and designers shipping products week in and week out; a lean business team supporting the company’s infrastructure; passion for automation and eliminating toil; $142 million in funding from top investors like Stripe, Addition, USV, Bloomberg Beta, First Round Capital, and more. To learn more about how we work, watch our founder Zack’s interview with First Round Capital.

What we’re looking for

We are hiring a Head of Security to take full ownership of security at Stedi, reporting directly to the CEO and working at the intersection of engineering, legal, product, and more.

At Stedi, security is job zero. There is nothing more important than securing our systems. This role exists to operationalize that principle across every function of the company.

You won’t be building from scratch. We already have SOC 2 Type 2 and HIPAA certifications and will soon have HITRUST R2 certification. We view these compliance items as a baseline starting point and not the final destination. We have invested heavily in security from the earliest days. We have extensive controls across our engineering and IT infrastructure (from SCPs to DLP and everything in between), and 100% of our customer data is processed within AWS without exception. We work extensively with AWS’s native tools as well as with AWS teams, including on an IAM access vulnerability that we discovered.

You will own our security function end-to-end: incident readiness, regulatory obligations, customer trust, and the day-to-day fundamentals that enable everything else. You will be the bridge between engineering and legal, working closely with leadership from both teams and the CEO. You’ll inherit a strong foundation to scale in our next phase of growth – building out the team, programs, and processes that let a lean company move fast while maintaining a world-class security posture.

What you’ll do

  • Own and build Stedis security program end-to-end, including policies, controls, procedures, security tooling, training, vulnerability management, vendor risk, and more.

  • Be a strong hands-on contributor from day 1 while also building a roadmap for scaling the security function as the company continues to grow. We have a culture where leaders are contributors and are deeply involved in the technical details.

  • Advise on security risk tied to product decisions, architecture, and partnerships.

  • Leverage our best-in-category security posture to unlock new customers and strategic relationships.

  • Partner with Engineering to maintain security excellence while minimizing development friction.

  • Lead breach preparedness and incident response: build, test, and own the Security Incident Response Plan, Disaster Recovery, and Business Continuity programs so Stedi can detect, contain, and recover rapidly in the unlikely event of a significant issue.

  • Represent Stedi in conversations with customer and partner security leadership teams, and provide clear, regular reporting on security posture and risk to the executive team and board.

  • Partner with Legal on regulatory obligations, breach notification requirements, and the legal dimensions of security incidents - be ready to engage directly with regulators should the need ever arise.

  • Build mechanisms for continuous security improvement, and establish practical, role-appropriate security training across the company.

Who you are

  • Significant experience owning security programs in cloud-native environments.

  • Deep technical ability in the security domain and enough working knowledge to have high-bandwidth discussions with application engineers.

  • Strong legal and regulatory instincts – you have the ability to understand legal issues and can speak credibly with regulators; healthcare or HIPAA experience is a strong plus.

  • Opinionated but pragmatic, with strong judgment about where rigor matters most and a bias toward solutions over problems.

  • Exceptional communicator: you can explain security risk clearly to engineers, executives, customers, and regulators, in writing and in person.

  • You’re excited to use automation and modern tooling to eliminate toil and raise the bar, not to build bureaucracy.

We’ve been made aware of individuals impersonating the Stedi recruiting team. Please note:

  • All official communication about roles at Stedi will only come from an @stedi.com email address, or from our official identification verification partner, Persona, @frompersona.com.

  • If you’re unsure whether a message is legitimate or have any concerns, feel free to contact us directly at [email protected].

We appreciate your attention to this and your interest in joining Stedi.

At Stedi, were looking for people who are deeply curious and aligned to our ways of working. Youre encouraged to apply even if your experience doesnt perfectly match the job description.

Similar remote jobs

More like this →
Stedi logo

Stedi

Product Designer (Remote)

Remote
✓ From careers page· about 3 hours ago
Stedi logo

Stedi

Security Engineer

Remote
✓ From careers page· about 3 hours ago
Stedi logo

Stedi

Software Development Manager (Remote)

Remote
✓ From careers page· about 3 hours ago
Stedi logo

Stedi

Backend Engineer (Remote)

Remote
✓ From careers page· about 3 hours ago

Discover More than 100,000 Hidden Remote Jobs Before Everyone Else

Unlock All Remote Jobs Today

Simple pricing. Big savings on Quarterly and Yearly.

Monthly Access

$19/month
  • Instant access to fresh remote jobs from 500+ companies
  • New opportunities added hourly, often 3-7 days before anywhere else
  • Advanced filtering by role type, stack, pay, and location
  • Priority customer support
Start 7-day trial — $2.95
Most Popular

Yearly Access

$59/year
  • Everything in Monthly
  • Save $169 (~74%) vs paying monthly
  • Average job search takes ~6 months - get covered for the whole journey
  • Less than the cost of one lunch per month for competitive advantage
  • Equivalent to just ~$4.92/month
Start 7-day trial — $2.95