Full-Time

Director of Information Security

CISO

Connexure

Connexure

51-200 employees

SaaS platform for stop-loss insurance workflow

No salary listed

Atlanta, GA, USA

Hybrid

Three days on-site per week, Tuesday through Thursday; remote work is permitted as needed.

Category
Cybersecurity
Required Skills
LLM
Incident Response
Network Monitoring
SOC 2

Get referred to Connexure

See people who can refer or advise you

Requirements
  • At least 8 years of experience in information security, including at least 2–3 years in a leadership role owning a security program end to end.
  • Direct experience operating under SOC 2 Type II and/or HITRUST CSF, including working with external auditors or assessors through a full certification or renewal cycle.
  • Hands-on familiarity with a modern security tool stack spanning endpoint, network and cloud monitoring, and identity and access management, with the ability to evaluate and direct tooling decisions.
  • Experience managing high-volume client and vendor security questionnaires or due-diligence processes in a B2B software or SaaS environment.
  • Experience building or maturing security policy from a less mature baseline.
  • Strong written and verbal communication, with comfort representing security directly to clients, auditors, and executive leadership.
  • Reliable internet and familiarity with digital platforms.
Responsibilities
  • Own the information security strategy, policies, and control framework end to end, including writing, maintaining, and enforcing policies that support SOC 2 and HITRUST audits.
  • Select and maintain an internal control framework, such as NIST CSF or ISO 27001, and map controls across SOC 2, HITRUST, and client contractual requirements.
  • Maintain the risk register and drive identified remediation gaps to closure.
  • Own the security tooling roadmap across endpoint protection, cloud security posture, identity and access management, network monitoring, and email and collaboration security.
  • Evaluate, select, and manage vendor relationships for security tooling.
  • Partner with Engineering leadership on secure-by-design practices in the product development lifecycle.
  • Serve as executive owner of the SOC 2 Type II and HITRUST certification programs, set audit strategy, and act as the primary contact for auditors and assessors.
  • Direct and develop the Security Analyst responsible for day-to-day compliance monitoring, evidence collection, and control testing.
  • Ensure security certifications are maintained continuously.
  • Own the end-to-end process for client and prospect security questionnaires and due-diligence requests, including a scalable knowledge base, workflow tooling, and response service-level agreements.
  • Partner with Sales and Legal on security-related contract terms and represent the company's security posture in prospect and client calls.
  • Own third-party and vendor security risk assessments for supplier and subprocessor relationships.
  • Track the evolving artificial intelligence threat and regulatory landscape, including risks involving large language models and AI-assisted development tools, and translate it into company policy.
  • Own the acceptable-use policy for AI tools, including employee use and AI-related product functionality.
  • Build an AI vendor risk assessment process for third-party AI tools and subprocessors.
  • Own and maintain the incident response plan, including tabletop exercises with Engineering and leadership.
  • Lead responses to security incidents, including technical remediation, internal communication, and coordination of legal, customer, and regulatory notifications.
  • Report program status to the CTO and overall security posture, audit outcomes, and material risks to the CEO and/or board.
Desired Qualifications
  • Experience in a regulated vertical adjacent to healthcare, insurance, or financial services data.
  • Prior experience leading or materially contributing to breach or incident response and post-incident program remediation.
  • Working knowledge of emerging AI security frameworks and risks, including OWASP guidance for large language model applications or NIST AI risk management work, and the ability to translate them into internal policy.
  • Relevant certification such as CISSP, CISM, or CCSP.
  • Prior experience at a company of comparable size, scaling a security function from one or two people.

Connexure is a Atlanta-based SaaS platform serving the self-funded medical benefits and stop loss insurance market. It provides cloud-based tools that connect carriers, MGUs, TPAs, and brokers to streamline underwriting, policy administration, quotes, and claims management in one integrated workflow. Its core product ESLoffice handles underwriting and administration of medical stop loss and group term life policies; BenefitConnect helps brokers request and compare quotes and manage communications; and Claimpoint acts as a data warehouse for TPAs and carriers to handle claims submissions, funding notifications, and reporting. By linking these participants and their data, Connexure creates a network that reduces fragmented communication and improves data security. The company’s goal is to unify the self-funded medical sector through technology, processes, and data insights, making the end-to-end process from quote to renewal and claims management more efficient.

Company Size

51-200

Company Stage

N/A

Total Funding

N/A

Headquarters

Atlanta, Georgia

Founded

1995

Get referred to Connexure

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Connexure updated its site July 29, 2026, still calling itself market leader.
  • The March 31, 2026 ThreeFlow expansion deepens API connectivity across the stop-loss ecosystem.
  • Gradient AI integration launched October 2025, adding AI-driven underwriting and risk scoring.

What critics are saying

  • The 2024 BlackSuit breach exposed 954,177 records, fueling class-action litigation in 2026.
  • ThreeFlow and Gradient AI integrations commoditize Connexure’s workflows and squeeze pricing.
  • A data-security failure or renewal loss at a major carrier can cripple network trust.

What makes Connexure unique

  • Connexure’s XIL links brokers, carriers, MGUs, and TPAs into one workflow.
  • ESLoffice centralizes stop-loss underwriting and policy administration for carriers and MGUs.
  • BenefitConnect connects brokers to 70+ carriers and MGUs for quote comparison.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Flexible Work Hours

Remote Work Options

Hybrid Work Options

Wellness Program

Mental Health Support

Conference Attendance Budget

Professional Development Budget

Stock Options

Company Equity

401(k) Retirement Plan

401(k) Company Match

Health Insurance

Paid Vacation

Paid Holidays

Paid Sick Leave

Parental Leave

Family Planning Benefits

Fertility Treatment Support

Adoption Assistance

Childcare Support

Meal Benefits

Phone/Internet Stipend

Home Office Stipend

Gym Membership

Professional Certification Support

Tuition Reimbursement

Pet Insurance

Relocation Assistance

Commuter Benefits

Security Training Budget

Bonuses

Growth & Insights

Headcount

6 month growth

34%

1 year growth

34%

2 year growth

34%