Anduril IndustriesLexington, Massachusetts, United States$191k-$253k
Virta HealthPosted 1mo ago
Director, Security Engineering at Virta Health scores 0 out of 100 on AI centrality, which makes it AI Level 1 of 4 (Little AI) on this board. The level measures how much of the work is AI, not seniority.
AI in this role
Lead enterprise security engineering, zero-trust architecture transition, and security operations.
Virta Health is on a mission to reverse metabolic disease in one billion people. Current treatment approaches aren’t working—over half of US adults have either type 2 diabetes or prediabetes, and obesity rates are at an all-time high. Virta is changing this by helping people reverse their metabolic condition through innovations in technology, personalized nutrition, and virtual care delivery reinvented from the ground up. We have raised over $350 million from top-tier investors, and partner with the largest health plans, employers, and government organizations to help their employees and members restore their health and take back their lives. Join us on our mission to reverse metabolic disease in one billion people.
As our Director of Security Engineering & Operations, you will hold a highly critical and transformative position at Virta. Leading both our Enterprise Security Engineering and Security Operations (SecOps) functions, you will serve as a visionary "player-coach" who directs a talented team of engineers while owning the operational defense of our enterprise. You will personally spearhead our Zero Trust Architecture (ZTA) transition—restricting lateral movement and containing blast radius—while simultaneously managing outsourced 24/7 Managed Detection and Response (MDR/SOC) partner. By blending deep technical engineering oversight with a robust, zero-latency incident response posture, you will ensure our systems remain resilient, our developer workflows stay frictionless, and our patient data stays meticulously protected.
ResponsibilitiesHands-on Engineering & Operational Leadership: Direct, mentor, and grow a high-performing team of security engineers. Conduct technical sprint planning, alignment, and coaching while maintaining the technical depth to dive into configurations alongside your team.
Champion Zero Trust Strategy: Lead the enterprise-wide transition to Zero Trust Architecture (ZTA) across IT, corporate platforms, and partner with engineering to drive ZTA core pillars: establishing identity as the perimeter, inhibiting lateral movement, and prioritizing data survivability.
Oversee 24/7 Security Operations (SecOps): Serve as the ultimate owner of Virta’s security monitoring, detection engineering, and security incident response program. Manage our outsourced MDR/SOC vendor relationships, ensuring seamless telemetry pipelines and rapid alert triage.
Manage and Minimize Blast Radius: Build and evolve automated detection and response capabilities—leveraging threat models and SOAR orchestration—to neutralize threats before they spread.
Curate operational artifacts that map and safeguard our environment: Maintain Data Topology Map, Cyber Asset Attack Surface (CAA) Matrix and Workload Ledger design.
Lead Security Tooling Strategy: Own the security stack, ensuring platforms are maintained and continuously tuned to the evolving threat landscape—delivering comprehensive coverage and visibility across our systems.
Manage our Cloud Access Security Broker (CASB) solution and user behavior analytics, translating signal from SaaS usage, identity activity, and data movement into actionable detections and enforceable policy, fully integrated with SOC monitoring and incident response.
Deploying and tuning DLP controls on endpoints, email, and SaaS collaboration tools to detect and prevent sensitive data from leaving the organization through unsanctioned channels.
Within your first 90 days at Virta, we expect you will do the following:
First 30 days: Deep dive into Virta’s cloud systems and existing IT security tools. Establish collaborative, high-trust relationships with your engineering team, IT, GRC peers, and external MDR partners. Conduct a baseline assessment of our current Zero Trust Maturity Model (ZTMM) status.P-
Day 30-60: Work with your team to deliver the baseline Data Topology Map and initial CAA Matrix. Audit our external MDR ingestion pipelines, tuning high-priority alert workflows and integrating security alerting directly into team communication channels.
Day 60-90: Finalize the Workload Ledger design, standardize technical containment playbooks for high-risk threat scenarios and present a clean Security Operations and ZTA maturity metrics dashboard to executive leadership.
10+ years of dedicated experience in Cybersecurity, Cloud Infrastructure Security, or SecOps, with at least 3+ years managing, leading, or mentoring high-performing security teams.
Demonstrated experience overseeing incident response programs and managing external vendors (such as 24/7 outsourced MDR/SOC partners, SIEM platforms, and EDR/XDR toolsets).
Deep technical expertise in cloud security architecture (ideally GCP), with hands-on experience building micro-segmentation models, establishing ephemeral workload identity controls, and securing CI/CD pipelines.
Exceptional analytical capability to map systemic relationships, formulate risk prioritization frameworks (RBVM), and apply Zero Trust Maturity Models to live corporate structures.
Proven track record of architecting durable AI systems or automation workflows that solve cross-functional challenges, resolve operational bottlenecks, and deliver measurable improvements to business efficiency.
Exceptional communication skills with the ability to convey complex technical security strategies to non-technical business leaders and external stakeholders.
Successfully designed and implemented repeatable AI-enabled workflows that address team bottlenecks and improve efficiency
Virta’s company values drive our culture, so you’ll do well if:
You put people first and take care of yourself, your peers, and our patients equally
You have a strong sense of ownership and take initiative while empowering others to do the same
You prioritize positive impact over busy work
You have no ego and understand that everyone has something to bring to the table regardless of experience
You appreciate transparency and promote trust and empowerment through open access of information
You are evidence-based and prioritize data and science over seniority or dogma
You take risks and rapidly iterate
Is this role not quite what you're looking for? Join our Talent Community and follow us on Linkedin to stay connected! Join our Talent Community | follow us on Linkedin
Virta has a location-based compensation structure. Starting pay will be based on a number of factors and commensurate with qualifications & experience. For this role, the compensation range is $161,500 - 209,000. Information about Virta’s benefits is on our Careers page at: https://www.virtahealth.com/careers.
As part of your duties at Virta, you may come in contact with sensitive patient information that is governed by HIPAA. Throughout your career at Virta, you will be expected to follow Virta's security and privacy procedures to ensure our patients' information remains strictly confidential. Security and privacy training will be provided.
As a remote-first company, our team is spread across various locations with office hubs in Denver and San Francisco.
Clinical roles: We currently do not hire in the following states: AK, HI, RI
Corporate roles: We currently do not hire in the following states: AK, AR, DE, HI, ME, MS, NM, OK, SD, VT, WI.
Virta uses Ashby as its applicant tracking system, which incorporates AI-powered tools (provided by OpenAI, AWS, and Google Gemini) in certain aspects of the recruiting process, including application review, candidate screening, and interview note taking; your data is not used to train AI models, and all final hiring decisions are made by Virta Health personnel. For more information, see Ashby's AI Terms at https://www.ashbyhq.com/resources/terms-ai-features
#LI-remote
Prepare for this job
A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.
Skills and AI tools this role asks for
Questions you could be asked
- Tell me about a project where security engineering was part of your work. What did you do?
- Tell me about a project where zero trust was part of your work. What did you do?
- Tell me about a project where secops was part of your work. What did you do?
- Tell me about a project where incident response was part of your work. What did you do?
- Tell me about a project where leadership was part of your work. What did you do?
Adapt your resume
- List these exact terms on your resume: Security Engineering, Zero Trust, Secops, Incident Response, and Leadership. An applicant tracking system matches the wording, not the idea.
- Attach one line of real, concrete experience to at least one of them — a tool named with nothing behind it rarely survives a human read.
Want your resume actually rewritten for this job?
The free preview above is everything we have today. A full resume rewrite is not live yet and has no price set. Join the waitlist and we will email you if we open it.
Similar roles
Software Engineering roles rated AI Level 1 at other companies.
MongoDBGurugram
SingleStoreUnited States
PelotonTaichung City, Taiwan
Planet LabsBerlin, Germany€38k-€48k
Thought MachinePortugal, Lisbon€50k-€75k






