SlipstreamJobsFresh Startup & VC-Backed Jobs

Head of Corporate and Information Security

Layer Health - Boston, MA, United States - Hybrid - posted 2026-09-14

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 180,000 - 230,000 / annual

Layer Health, founded in 2023 by machine learning researchers from MIT and Harvard Medical School, is building an AI-powered platform to synthesize information from medical records and reduce friction in healthcare. The platform uses LLMs to solve chart review at scale, with initial focus on clinical registry abstraction for health systems across surgery, cardiology, oncology, and other specialties. You will be the first Head of Corporate and Information Security, reporting directly to leadership with a mandate to build and scale the security function from the ground up. This is a foundational hire critical to the company's ability to grow with enterprise health system partners while handling PHI and sensitive customer data securely. Key responsibilities include: • Own Layer's overall security strategy and risk program. Develop comprehensive understanding of current security posture across product, cloud infrastructure, corporate systems, endpoints, vendors, and operations. Build on the existing SOC2 Type 2 compliant program and establish a risk-based roadmap toward ISO 27001 certification. • Define and improve technical security posture. Partner with engineering and infrastructure teams to strengthen security across GCP environments and the software development lifecycle, including cloud IAM, network security, secrets management, vulnerability management, secure configuration, CI/CD security, logging, monitoring, and architecture reviews. • Protect sensitive data throughout its lifecycle. Define and enhance controls for PHI, customer data, credentials, and other sensitive information across storage, processing, and transmission. Examples include data classification, DLP capabilities, access controls, egress protections, retention policies, secrets scanning, and Google Workspace/endpoint controls. • Build detection, incident response, and security operations capabilities. Establish visibility and operational processes to detect, investigate, contain, and learn from security events. Improve centralized security telemetry, SIEM capabilities, detection and alerting strategies, incident response processes, and coordinate security exercises and investigations. • Own corporate security. Refine security posture across employee identity, endpoints, SaaS applications, and corporate systems. Work with Operations and IT on identity and access management, endpoint security, device management, employee lifecycle controls, and account management. • Strengthen human security posture. Build upon existing security awareness and training programs, including phishing simulations and social engineering exercises, to empower employees as the first line of defense. • Collaborate with the Chief Privacy Officer and leadership team to identify key security risks and establish a strategic plan balancing robust risk management with organizational priorities. REQUIREMENTS: • 7+ years of experience in information security, security engineering, or related roles, with meaningful ownership across multiple areas of a security program (not deep experience in only one specialty). • Experience building or materially evolving a security program in a startup, growth-stage technology company, or similarly fast-moving environment. Comfortable starting with incomplete systems and prioritizing what matters most. • Strong technical depth in modern cloud environments. Comfortable reasoning about cloud IAM, networking, application and infrastructure security, data protection, secrets management, logging and detection, vulnerability management, and endpoint or identity security. Hands-on GCP experience strongly preferred; equivalent AWS or Azure experience relevant. • Experience working closely with software engineering and infrastructure teams with sufficient technical fluency to evaluate architecture, investigate security issues, and implement or meaningfully contribute to technical controls. • Strong understanding of security operations and incident response, including building useful telemetry, detection, investigation, escalation, and response capabilities. SIEM and related security tooling experience valuable, but overall capability design prioritized over specific product familiarity. • Experience protecting sensitive data in regulated environments. Healthcare experience—particularly HIPAA and PHI handling—strongly preferred; experience in other highly regulated industries may be relevant. • Experience with security and compliance frameworks such as SOC 2 and ISO 27001, including translating framework requirements into effective operational and technical controls. Experience leading ISO 27001 certification is a plus. • Strong risk judgment. Ability to distinguish between theoretical issues and meaningful business risk, prioritize accordingly, and explain tradeoffs behind recommendations. • Builder's mindset. Comfortable moving between strategy, architecture, tooling, policy, investigation, and implementation, particularly while the security team is small. • Clear and credible communicator able to discuss technical security issues with engineers, explain risk and investment decisions to executives, and represent Layer effectively with customers' security and compliance teams.

Similar roles