This job post is closed and the position is probably filled. Please do not apply.
🤖 Automatically closed by a robot after apply link
was detected as broken.
Description:
Truemed is a payments processing company that partners with health and wellness enterprises to handle sensitive payment and health data.
Security is a core focus, requiring SOC2 Type II compliance and rigorous security programs.
The Senior Security Engineer role involves formalizing existing security programs and building a best-in-class security foundation.
The position offers the opportunity to shape security at a fast-growing startup, ideal for those who thrive in autonomous environments and enjoy building programs from scratch.
Responsibilities include leading SOC2 Type II compliance, governance, risk, and compliance (GRC), security tooling and implementation, incident response and risk mitigation, and cross-team collaboration with engineering, sales, and customer success teams.
Requirements:
Candidates must have 5+ years of experience in security engineering, compliance, or security operations.
Hands-on experience with SOC2 Type II audits is required, either leading them or playing a significant role.
A strong background in vulnerability management, endpoint security, and secure software development practices is necessary.
Familiarity with MDMs, antivirus tools, SIEMs, and web security best practices is essential.
Experience working with GRC teams and responding to enterprise security questionnaires is required.
Candidates must demonstrate the ability to work autonomously and drive initiatives without excessive oversight.
Bonus points for experience in payments, fintech, or healthcare security.
Benefits:
The position offers the chance to get in on the ground floor and build security at a company that prioritizes it from day one.
High autonomy is provided, allowing the individual to own security initiatives and define how security is implemented at scale.
There are growth opportunities as the first dedicated security hire, with the potential to advance into a leadership role.
The role involves working on impactful problems, protecting sensitive payment and health data while assisting in closing high-value enterprise deals.
The position is remote-friendly, allowing work from anywhere in the US while collaborating with top-tier engineers.