Full-Time

Director of IT & Security

CISO

Redox

Redox

51-200 employees

Interoperability platform linking EHRs, providers, payers

Compensation Overview

$224k - $260k/yr

Remote in USA

Remote

Must reside and work in the continental U.S.; U.S. work eligibility required.

Category
Engineering Management (2)
,
Required Skills
Threat modeling
Infrastructure as Code (IaC)
Vulnerability Analysis
SOC 2
AWS
penetration testing
DevOps
Requirements
  • 10+ years in information security, IT, or related technical leadership roles, including 5+ years of people management, ideally in healthcare technology SaaS
  • Proven experience leading security engineering, security operations, and corporate IT in a cloud-native SaaS environment
  • Direct experience in healthcare or other highly regulated industries
  • Track record of successfully implementing DevSecOps practices
  • Deep hands-on experience securing AWS environments
  • Strong understanding of endpoint security, identity systems, and modern SaaS IT stacks
  • Practical knowledge of tools such as CrowdStrike, Okta, Flashpoint, RAD, and related platforms
  • Strong foundation in application security, cloud security, and infrastructure as code
  • Strong collaborator with engineering, platform, and operations teams
  • Clear, direct communicator who can articulate risk without theatrics
  • Comfortable making tradeoffs and prioritizing based on real-world risk
  • Builder mindset with a bias toward automation and scale
  • CrowdStrike
  • AWS
  • Okta
  • Vanta
Responsibilities
  • Security Strategy & Leadership: Own end-to-end information security strategy across cloud, application, infrastructure, and corporate environments. Define a pragmatic security roadmap aligned to business risk, regulatory requirements, and engineering velocity. Serve as the executive owner for security posture, risk management, and incident response. Act as a trusted advisor to the CTO and executive team on security, risk, and operational tradeoffs.
  • Security Engineering & DevSecOps: Drive a DevSecOps-first operating model, embedding security into CI/CD pipelines, infrastructure as code, and developer workflows. Partner deeply with engineering leadership to make security scalable, automated, and measurable. Lead threat modeling, secure design reviews, and risk assessments for new platform initiatives. Champion policy-as-code, guardrails, and automation over manual process.
  • Cloud, Application & Infrastructure Security: Own security architecture and operations for a primarily AWS-based environment. Lead application security programs, including secure SDLC, dependency scanning, SAST/DAST, penetration testing, and vulnerability management. Own identity and access management strategy with Okta as the backbone. Ensure strong detection, alerting, and response across endpoints and cloud workloads (e.g., CrowdStrike, RAD).
  • Security Operations & Incident Response: Build and run effective security operations, including monitoring, investigation, incident response, and post-incident learning. Lead incident response for both security and IT incidents, serving as the calm point of accountability. Run tabletop exercises and continuously improve response playbooks. Manage vendor relationships, including CrowdStrike, Flashpoint, RAD, and Okta.
  • Corporate IT & Enterprise Systems: Own corporate IT strategy and execution, focused on reliability, security, and employee productivity. Lead end-user computing, device management, endpoint security, identity lifecycle management, and access controls. Oversee IT systems, including identity, email, collaboration tools, endpoint management, and SaaS access governance. Drive automation and standardization across onboarding, offboarding, access management, and device lifecycle. Partner with People Ops, Legal, and Finance on IT processes, audits, and vendor management.
  • Compliance, Risk & Healthcare Context: Own healthcare-related security and compliance programs (e.g., HIPAA, SOC 2). Translate regulatory requirements into practical, engineering-friendly controls. Lead third-party risk management and vendor security reviews. Support customer security reviews and serve as an executive point of contact on security matters.
  • Team Leadership & Culture: Build, lead, and mentor a high-performing team spanning security engineering, security operations, and IT. Create a culture where security and IT are seen as enablers, not blockers. Establish clear ownership, measurable outcomes, and high operational standards. Be visible, decisive, and calm under pressure.
Desired Qualifications
  • Proven experience securing autonomous agentic loops and tool-calling frameworks. Deep understanding of Indirect Prompt Injection and designing "Human-in-the-Loop" guardrails for agent-driven actions.
  • Technical expertise in securing the Model Context Protocol (MCP), specifically regarding context isolation, sandboxing, and identity propagation between LLMs and private data sources.
  • Direct experience migrating security programs to Vanta or similar automated GRC platforms. Ability to architect "continuous compliance" by integrating cloud, identity, and developer tools for automated evidence collection.
  • Hands-on application of the NIST AI RMF, OWASP Top 10 for LLMs, etc within a production environment.

Redox Engine provides a platform-as-a-service for healthcare interoperability, connecting electronic health records, providers, payers, and healthcare products to share data across the ecosystem. It acts as a data exchange layer where products connect to EHRs, providers, and payers through standardized APIs (including FHIR), with Redox handling data routing, normalization, and secure access. The service is vendor-agnostic to reduce the complexity and cost of linking diverse systems, enabling scalable data access for many applications. Its goal is to enable seamless, standards-based data sharing that supports better patient care and speeds the use of AI and machine learning in healthcare.

Company Size

51-200

Company Stage

Series D

Total Funding

$96M

Headquarters

Madison, Wisconsin

Founded

2014

Simplify Jobs

Simplify's Take

What believers are saying

  • Creyos partnership embeds cognitive assessments into EHRs via Redox's 90+ EHR network.
  • CommonWell membership accelerates TEFCA onboarding with real-time writeback capabilities.
  • Snowflake integration streams unified data for AI/ML analytics in life sciences.

What critics are saying

  • InterSystems HealthShare erodes Redox's network via superior FHIR integrations.
  • Philips dominates RPM cardiology with end-to-end platforms bypassing middleware.
  • TEFCA QHINs commoditize exchange, rendering Redox's paid platform obsolete.

What makes Redox unique

  • Redox's hub-and-spoke architecture enables single API integration across 95+ EHRs.
  • Real-time FHIR R4 data translation and webhooks support bidirectional clinical workflows.
  • Platform expansions like Config Modifiers and Log Inspector empower self-service data control.

Help us improve and share your feedback! Did you find this helpful?

Your Connections

People at Redox who can refer or advise you

Benefits

Flexible Work Hours

Growth & Insights and Company News

Headcount

6 month growth

-1%

1 year growth

0%

2 year growth

0%
Health Technology Insights
May 13th, 2025
Creyos Partners with Redox to Eliminate Barriers to Cognitive Health Data in EHRs

Creyos partners with Redox to eliminate barriers to cognitive health data in EHRs.

HIT Consultant
May 13th, 2025
Creyos, Redox Partner To Integrate Cognitive Assessments Into Ehrs

What You Should Know:– Creyos, an online platform for objective cognitive and behavioral health assessments, today announced a strategic partnership with Redox, a prominent provider of healthcare data interoperability solutions.– The collaboration is set to enable large health systems and integrated delivery networks to seamlessly embed Creyos’ validated cognitive testing tools directly into their existing electronic health records (EHRs), effectively dismantling one of the most significant barriers to scaling proactive brain health care.The Growing Imperative for Proactive Brain HealthThe need for accessible and efficient cognitive assessment tools is becoming increasingly critical. With over 55 million people worldwide currently living with dementia—a figure projected to soar to 139 million by 2050—early and accurate screening is paramount. Such screenings enable timely intervention, personalized care planning, and ultimately, improved patient outcomes. As healthcare systems increasingly shift towards value-based care models, Creyos is focused on helping providers integrate cognitive health as a core component of routine and preventive care, utilizing tools that are both clinically proven and straightforward to implement.Overcoming Implementation Hurdles with Seamless IntegrationA common challenge for new health technologies is gaining traction within large health systems, often due to poor alignment with existing clinical workflows and complex integration processes. This new Creyos-Redox partnership directly addresses these issues. By leveraging Redox’s expansive EHR network, which supports interoperability across more than 90 EHR systems including major platforms like Cerner, eClinicalWorks, and Allscripts, Creyos can deliver seamless data integration and platform access

HIT Consultant
Apr 2nd, 2025
Redox Joins Commonwell Health Alliance For Healthcare Data Interoperability

Redox Joins CommonWell Health Alliance for Healthcare Data Interoperability. by Jasmine Pennic 04/02/2025 Leave a Comment. What You Should Know: – Redox, a provider of healthcare data interoperability solutions, has announced its membership in CommonWell Health Alliance, a Qualified Health Information Network™ (QHIN™). – Redox brings a key advantage to CommonWell’s QHIN participants: real-time writeback for direct connections. This capability enhances data exchange and workflow efficiency.Expanding Access to Critical Healthcare Data:By joining CommonWell, Redox aims to empower a wide range of healthcare organizations, including:ProvidersPayersDigital health vendors/independent service providersEHRs (Electronic Health Records)Life Science companiesThis partnership will provide these organizations with broader and deeper access to real-time, critical healthcare data, facilitating improved care coordination and decision-making.Redox’s API: A User-Friendly Interoperability SolutionRedox offers a user-friendly and developer-friendly API, which presents an attractive alternative for customers who utilize network connections as part of their integration strategy. This API simplifies the process of connecting various healthcare systems.Streamlining TEFCA OnboardingOrganizations across the healthcare ecosystem can leverage Redox’s expertise in its 9,600+ healthcare integrations to facilitate quick onboarding to The Trusted Exchange Framework and Common Agreement™ (TEFCA™). Redox’s experience simplifies the complexities of TEFCA participation.“Our partnership with CommonWell provides an easier path forward for Redox customers who want to participate in TEFCA,” said Trip Hofer, CEO of Redox

Redox
Jan 16th, 2025
Take control of your data mappings with Config Modifiers

Redox, Inc. is excited to introduce Config Modifiers, the latest addition to its growing toolkit aimed at empowering you with robust self-service options.

Redox
Sep 24th, 2024
Enhancing flexibility with updates to translation sets

Redox, Inc. is excited to announce the latest updates to its translation sets feature-a key tool in the Redox dashboard that gives you more control and flexibility in managing codes and values.