SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Virta Health is seeking a Director of Security Engineering & Operations to lead both enterprise security engineering and security operations functions. This is a hands-on leadership role where you will direct a talented team of security engineers while owning the operational defense of the enterprise.
Key responsibilities include:
- Lead and mentor a high-performing security engineering team, conducting technical sprint planning and maintaining hands-on technical depth.
- Architect and champion an enterprise-wide Zero Trust Architecture (ZTA) transition across IT, corporate platforms, and cloud infrastructure, focusing on identity-based perimeter, lateral movement inhibition, and data survivability.
- Own Virta's 24/7 security operations program, including monitoring, detection engineering, and incident response. Manage relationships with outsourced MDR/SOC vendors and ensure seamless telemetry pipelines and rapid threat containment.
- Design and deploy blast radius reduction solutions, including micro-segmentation (GCP VPC Service Controls) and ephemeral workload identity protocols with temporary token-based authentication.
- Develop and maintain critical operational artifacts: Data Topology Maps, Cyber Asset Attack Surface matrices, Workload Ledgers, and technical containment playbooks.
- Operationalize risk-based vulnerability management (RBVM) by evaluating infrastructure against Zero Trust Maturity Models, defining patching SLAs, and driving cross-functional mitigation efforts.
- Collaborate with GRC, IT, and Product teams to integrate security policies into CI/CD pipelines and ensure AI tools operate with appropriate guardrails.
Within 90 days, you will conduct a baseline Zero Trust Maturity assessment, deliver foundational security artifacts (Data Topology Map, CAA Matrix), optimize MDR alert workflows, implement initial micro-segmentation guardrails, and present security maturity metrics to leadership.
Required qualifications: 10+ years in cybersecurity, cloud infrastructure security, or SecOps with 3+ years managing security teams. Demonstrated experience overseeing incident response and managing external MDR/SOC vendors. Deep technical expertise in cloud security architecture (preferably GCP), micro-segmentation, ephemeral identity controls, and CI/CD pipeline security. Strong analytical capability for risk prioritization and Zero Trust Maturity modeling. Proven track record architecting AI-enabled automation workflows. Exceptional communication skills for translating complex security strategies to non-technical stakeholders.