JobBobsReal-time global job discoveryLive

Director, Security Engineering

Virtahealth · Remote · 2026-08-05

FullTimeexecutiveRemote
Apply on the employer's site

About this role

Virta Health is on a mission to reverse metabolic disease in one billion people. Current treatment approaches aren’t working—over half of US adults have either type 2 diabetes or prediabetes, and obesity rates are at an all-time high. Virta is changing this by helping people reverse their metabolic condition through innovations in technology, personalized nutrition, and virtual care delivery reinvented from the ground up. We have raised over $350 million from top-tier investors, and partner with the largest health plans, employers, and government organizations to help their employees and members restore their health and take back their lives. Join us on our mission to reverse metabolic disease in one billion people.

As our Director of Security Engineering & Operations, you will hold a highly critical and transformative position at Virta. Leading both our Enterprise Security Engineering and Security Operations (SecOps) functions, you will serve as a visionary "player-coach" who directs a talented team of engineers while owning the operational defense of our enterprise. You will personally spearhead our Zero Trust Architecture (ZTA) transition—restricting lateral movement and containing blast radius—while simultaneously managing outsourced 24/7 Managed Detection and Response (MDR/SOC) partner. By blending deep technical engineering oversight with a robust, zero-latency incident response posture, you will ensure our systems remain resilient, our developer workflows stay frictionless, and our patient data stays meticulously protected.

RESPONSIBILITIES

- Hands-on Engineering & Operational Leadership: Direct, mentor, and grow a high-performing team of security engineers. Conduct technical sprint planning, alignment, and coaching while maintaining the technical depth to dive into configurations alongside your team.

- Architect & Champion Zero Trust Strategy: Lead the enterprise-wide transition to Zero Trust Architecture (ZTA) across IT, corporate platforms, and cloud engineering infrastructure. Drive ZTA core pillars: establishing identity as the perimeter, inhibiting lateral movement, and prioritizing data survivability.

- Oversee 24/7 Security Operations (SecOps): Serve as the ultimate owner of Virta’s monitoring, detection engineering, and incident response program. Manage our outsourced MDR/SOC vendor relationships, ensuring seamless telemetry pipelines, rapid alert triage, and zero-latency threat containment.

- Manage and Minimize Blast Radius: Design, deploy, and maintain robust blast radius reduction solutions. This includes implementing micro-segmentation boundaries (such as GCP VPC Service Controls to prevent administrative data movement to external storage) and enforcing ephemeral Workload Identity protocols (replacing static passwords with temporary 1-hour tokens).

- Own Threat Defense & Containment Blueprints: Curate and update the primary operational artifacts that map and safeguard our environment: our Data Topology Map, Cyber Asset Attack Surface (CAA) Matrix, Workload Ledger design, and technical Containment Playbooks.

- Operationalize Risk-Based Vulnerability Management (RBVM): Evaluate both legacy stacks and modern cloud services against the Zero Trust Maturity Model (ZTMM). Define strict patching and remediation SLAs, and partner cross-functionally with IT and Foundations Engineering to drive targeted mitigation.

- Cross-Functional Collaboration: Coordinate closely with GRC, IT, and Product teams to ensure that operational security policies are seamlessly integrated into code pipelines (Secure by Design CI/CD) and that rapidly evolving enterprise AI tools operate with appropriate context-aware guardrails.

90 DAY PLAN

Within your first 90 days at Virta, we expect you will do the following:

- First 30 days: Deep dive into Virta’s cloud infrastructure (GCP) and existing IT security tools. Establish collaborative, high-trust relationships with your engineering team, IT, GRC peers, and external MDR partners. Conduct an baseline assessment of our current Zero Trust Maturity Model (ZTMM) status.

- Day 30-60: Work with your team to deliver the baseline Data Topology Map and initial CAA Matrix. Audit our external MDR ingestion pipelines, tuning high-priority alert workflows and integrating security alerting directly into team communication channels. Secure GitHub pipeline configs to expand automated secrets-detection.

- Day 60-90: Finalize the Workload Ledger design and roll out the first phase of micro-segmentation guardrails (including pilot GCP VPC-SC boundaries). Standardize technical Containment Playbooks for high-risk threat scenarios and present a clean Security Operations and ZTA maturity metrics dashboard to executive leadership.

MUST-HAVES

- 10+ years of dedicated experience in Cybersecurity, Cloud Infrastructure Security, or SecOps, with at least 3+ years managing, leading, or mentoring high-performing security teams.

- Demonstrated experience overseeing incident response programs and managing external vendors (such as 24/7 outsourced MDR/SOC partners, SIEM platforms, and EDR/XDR toolsets).

- Deep technical expertise in cloud security architecture (ideally GCP), with hands-on experience building micro-segmentation models, establishing ephemeral workload identity controls, and securing CI/CD pipelines.

- Exceptional analytical capability to map systemic relationships, formulate risk prioritization frameworks (RBVM), and apply Zero Trust Maturity Models to live corporate structures.

- Proven track record of architecting durable AI systems or automation workflows that solve cross-functional challenges, resolve operational bottlenecks, and deliver measurable improvements to business efficiency.

- Exceptional communication skills with the ability to convey complex technical security strategies to non-technical business leaders and external stakeholders.

- Successfully designed and implemented repeatable AI-enabled workflows that…

Skills asked for

Similar jobs

Apply on the employer's site

Your next role is already in here.

Search live openings from thousands of employers, save the ones worth a second look, and let JobBob keep watch for the rest.