Head of IT & Security

NexHealthSan Francisco, CaliforniaPosted August 7, 2026

Want this job? Aria tailors your résumé to this role and submits the application on the employer's own platform — on your behalf. Free to start.

About this role

About NexHealth

Our healthcare system remains frustratingly analog. When you live in a world of one-tap car rides, instant meal delivery, and unlimited streaming, why do you still have to call to schedule a doctor’s appointment and fill out a clipboard in the waiting room?

NexHealth’s mission is to accelerate innovation in healthcare by connecting patients, providers, and developers. We’re building the infrastructure layer for modern healthcare, connecting thousands of fragmented, on-premise, and closed EHR systems into a single, modern platform that powers software, APIs, payments, and patient experiences across the ecosystem.

• Founded: 2017

• Headquarters: San Francisco, CA

• Funding: $177M Series C

• Employees: 200+

• Trusted by tens of thousands of providers and hundreds of health-tech developers — forging the infrastructure layer that modern healthcare needs

About the Role

NexHealth is a technology company building infrastructure that's reshaping how patient data moves and how the HealthTech ecosystem connects. We're looking for a Security Lead to own our security governance, compliance, IT operations, vendor security, and incident response — establishing the function, embedding strong practices, and partnering closely with engineering, legal, and leadership.

This is a player-coach role with real hands-on expectation in year one. You'll drive the next phase of our security and compliance program, and build your team.

What You'll Do

• Own NexHealth's security governance, compliance, and IT programs end-to-end.

• Serve as named Information Security Officer and Privacy Officer for SOC 2 and HIPAA — own the policy manual (40+ documents), audit liaison relationship with A-LIGN, control mapping across overlapping regimes, and evidence collection pipelines.

• Set security standards across application security, vulnerability management, cloud security (AWS), audit logging, and access controls — driving the technical program through Engineering via influence, not direct authority.

• Build, hire, and develop the IT and workforce security program: endpoints, identity, SaaS administration, phishing simulations, role-specific training modules, and facilities security.

• Own vendor security: intake, classification, assessment, BAA execution, ongoing oversight, and customer-facing trust artifacts including Trust Center and subprocessor disclosure.

• Lead incident response in Officer capacity; partner with outside counsel on breach determinations, own IR tracking, and run annual tabletop exercises.

• Own the risk register, risk acceptance decisions, privacy operations (DSARs, data subject rights, privacy complaints), BC/DR plan, and cyber insurance relationship.

• Hire a Staff-level IT IC within year one and grow the function from there.

What You'll Bring

Experience

• 8+ years of relevant security experience, including 3+ years in a security leadership role where you were materially building the program, not maintaining it.

• Has built (not inherited) a security program from a near-zero baseline at least once.

• Has owned a recurring external audit cycle end-to-end (e.g., SOC 2, ISO, PCI, HITRUST) — designed evidence collection, mapped controls, ran the auditor relationship, and made the next cycle materially easier than the last.

• Software engineering background.

Stop filling out applications one by one.