Director, Security

Posted Yesterday
Be an Early Applicant
32 Locations
In-Office or Remote
Expert/Leader
Big Data • Healthtech • Software • Biotech
The Role
Lead and build the company's end-to-end security program for a genomics and AI platform: governance, compliance (HIPAA, HITECH, SOC 2, ISO 27001), AI governance, offensive security, incident response, third-party and SaaS security, and cross-functional security embedding. Manage senior offensive personnel and external partners, present to executives, and deliver SOC 2 readiness and a prioritized HIPAA remediation roadmap quickly.
Summary Generated by Built In
Sequencing is building the interface between humanity and its DNA.

Using clinical-grade whole genome sequencing, AI, and a rapidly expanding ecosystem of genomic applications, we help people better understand themselves, their health, and their future through their DNA.

The human genome is one of the most valuable and underutilized resources in the world. Our mission is to transform the human genome into a lifelong source of personalized guidance and build the trusted home for every genome on Earth.

As the world’s largest direct-to-consumer whole genome sequencing platform, Sequencing is helping define the future of AI-powered personalized health.

We’re a profitable, venture-backed, fully remote company building category-defining products that help people better understand themselves through their DNA.

The opportunity

Sequencing is hiring a Director of Security to build and lead a modern security program for a rapidly scaling genomics and AI platform. This is the company’s first dedicated security leadership hire and a chance to shape the long term security foundation for a platform that handles highly sensitive consumer genomic and health data. This is a Director level role on the Engineering team, reporting to the Head of Engineering, and leading the security function as it scales, including oversight of senior offensive security personnel and external security partners. Your success helps protect the human genome, build customer trust, and make personalized health insights from whole genome sequencing safer and more accessible for everyone.

What you'll own

  • Own the company’s security program end to end, including policies, procedures, playbooks, runbooks, training, governance, and security documentation.
  • Build the governance layer that turns ad hoc security work into a repeatable, measurable, and auditable security program.
  • Lead ongoing HIPAA and HITECH compliance review, security gap assessment, and remediation initiatives, while driving SOC 2 and ISO 27001 certification efforts from roadmap through audit completion.
  • Serve as the primary point of contact for auditors, regulators, customers, and external compliance partners.
  • Partner closely with Engineering, DevOps, Bioinformatics, Product, and Operations to embed security into every system that touches customer genomic and health data.
  • Establish and enforce AI governance policies covering company wide use of AI tools, including specific platforms such as ChatGPT, Claude, Cursor, and similar tools, or equivalent, along with data classification standards, acceptable use policies, prompt handling practices, and Data Loss Prevention controls.
  • Define and enforce security standards for contractors, agencies, consultants, and third party development partners, including intellectual property protection requirements, controlled access policies, device management expectations, and secure handling of customer data.
  • Build and maintain centralized visibility into company SaaS tools, shadow IT usage, third party integrations, identity and access management, and organizational data exposure risks.
  • Lead offensive security initiatives, including management of senior offensive security personnel, external penetration testing firms, vulnerability assessments, and remediation tracking.
  • Effectively manage offensive security workstreams even when the hands on technical work extends beyond the Director’s direct technical specialization.
  • Stand up and operationalize the company’s incident response program, including severity classification, escalation paths, communications, executive coordination, forensic readiness, and post incident review procedures.
  • Serve as a senior escalation point during security incidents and maintain availability for critical after hours incident response, breach investigation, and executive coordination when necessary.
  • Present security posture, organizational risk, compliance status, and security roadmap updates to executive leadership in clear, business oriented language.
  • Lead company wide security awareness and training programs covering secure coding, phishing resistance, AI tool usage, handling of sensitive genomic data, and operational security best practices.
  • Translate complex security findings into practical actions engineering teams can implement without unnecessarily slowing product velocity.
  • Complete an initial HIPAA and HITECH security review and deliver a prioritized remediation roadmap within the first 45 days.
  • Reach SOC 2 readiness within 6 months aligned with the company’s infrastructure modernization roadmap.
  • Establish a recurring external penetration testing cadence with measurable remediation tracking and executive visibility.

Who you are

  • 10+ years of experience in security engineering, application security, cloud security, security management, or CISO level roles, including 3+ years in a senior leadership or director level position.
  • Proven experience building or significantly maturing security programs at rapidly growing consumer technology, ecommerce, SaaS, healthcare, or direct to consumer platforms.
  • Demonstrated experience protecting highly sensitive customer data, including protected health information, personally identifiable information, financial data, or genomic data.
  • Proven track record leading SOC 2, HIPAA, and ISO 27001 certification efforts from planning through successful audit completion.
  • Strong understanding of modern cloud and application security practices across AWS based infrastructure and modern web application environments.
  • Experience operating in fast moving startup or scale up environments with evolving systems, incomplete processes, and rapidly changing priorities.
  • Strong understanding of modern AI security risks, including AI governance, prompt and data leakage risks, AI assisted software development workflows, and developer AI tooling controls.
  • Experience managing SaaS governance, shadow IT risk, vendor security reviews, identity and access lifecycle management, and third party access controls.
  • Experience managing offensive security initiatives, external penetration testing vendors, red team exercises, vulnerability management programs, and remediation prioritization.
  • Strong cross functional leadership skills with the ability to influence Engineering, DevOps, Bioinformatics, Product, and Operations teams without direct authority.
  • Ability to balance strong security standards with startup speed, product velocity, and practical operational realities.
  • Experience presenting security posture, organizational risk, incident summaries, and compliance status to founders, executives, boards, auditors, or enterprise customers.
  • Hands on familiarity with governance, risk, and compliance platforms such as Vanta, Drata, or equivalent, security information and event management tooling, endpoint and identity management systems, Google Workspace or equivalent productivity suite security administration, SaaS access governance tools, Jira, Confluence, and AWS security services including CloudTrail, GuardDuty, and Security Hub or equivalent cloud security services.
  • Experience with modern edge and cloud security platforms such as Cloudflare Enterprise or equivalent, including web application firewall management, distributed denial of service protection, bot mitigation, Zero Trust access controls, API security, and internet facing application protection.
  • Experience in healthcare, consumer healthtech, or HIPAA regulated environments strongly preferred.
  • Based in the United States and able to work fully remotely.

Skills Required

  • 10+ years experience in security engineering, application security, cloud security, security management, or CISO-level roles
  • 3+ years in a senior leadership or director-level position
  • Proven experience building or maturing security programs at rapidly growing consumer technology, ecommerce, SaaS, healthcare, or direct-to-consumer platforms
  • Demonstrated experience protecting highly sensitive customer data including PHI, PII, financial data, or genomic data
  • Proven track record leading SOC 2, HIPAA, and ISO 27001 readiness and certification from planning through audit completion
  • Strong understanding of modern cloud and application security practices across AWS-based infrastructure and modern web application environments
  • Strong understanding of modern AI security risks, AI governance, prompt and data leakage risks, and developer AI tooling controls
  • Experience managing SaaS governance, shadow IT risk, vendor security reviews, identity and access lifecycle management, and third-party access controls
  • Experience managing offensive security initiatives, external penetration testing vendors, red team exercises, vulnerability management, and remediation prioritization
  • Hands-on familiarity with GRC platforms (Vanta, Drata, or equivalent), SIEM tooling, endpoint and identity management systems, Google Workspace security administration, SaaS access governance tools, Jira, Confluence, and AWS security services (CloudTrail, GuardDuty, Security Hub)
  • Experience with edge and cloud security platforms such as Cloudflare Enterprise including WAF, DDoS protection, bot mitigation, Zero Trust, and API security
  • Ability to serve as senior incident escalation, maintain after-hours availability for incident response and breach investigations
  • Based in the United States and able to work fully remotely
  • Experience in healthcare, consumer healthtech, or HIPAA-regulated environments
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
39 Employees
Year Founded: 2017

What We Do

Sequencing.com is a genomics platform that provides clinical-grade whole genome sequencing, at-home DNA kits, and free lifetime DNA data storage. The company offers an app/report marketplace, AI-enabled interpretation, and personalized health, wellness, and ancestry reports produced from WGS data, with emphasis on privacy and ongoing updates to drive actionable insights for prevention and personalized care.

Similar Jobs

Zcash Open Development Lab (ZODL) Logo Zcash Open Development Lab (ZODL)

Director of Security

Blockchain • Fintech • Payments • Cryptocurrency
Remote
7 Locations
30 Employees
185K-230K Annually

Deepgram Logo Deepgram

Senior Solutions Architect

Artificial Intelligence • Machine Learning • Natural Language Processing • Software • Conversational AI
Remote
3 Locations
150 Employees

Pfizer Logo Pfizer

HCE

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
In-Office or Remote
5 Locations
121990 Employees

Domino Data Lab Logo Domino Data Lab

Senior Director, Solutions Engineering

Artificial Intelligence • Machine Learning
Remote or Hybrid
East Coast, NZL
200 Employees
300K-350K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account