Head Of Infrastructure Security Compliance
💼 Full-time🗓 2026-07-26
Rewrite
## About the Role
We are hiring a Head of Infrastructure, Security & Compliance to take full ownership of the reliability, scalability, security, and compliance posture of Arintra's platform.
This is a hands-on leadership role — you will architect systems, execute critical initiatives, and build a high-performing team. You will serve as the single point of accountability for cloud infrastructure, security, compliance, and observability, while partnering closely with leadership, engineering, and enterprise customers.
## Key Responsibilities
### Infrastructure & Platform
- Own and scale our GCP architecture (GKE, Cloud SQL, Pub/Sub, BigQuery, Cloud Run, VPC, IAM)
- Ensure stability across dev, staging, and production environments
- Drive cost optimization (rightsizing, committed use discounts, BigQuery governance)
- Build and enforce Infrastructure-as-Code (Terraform) standards
- Manage AI/ML infrastructure, including LLM pipelines and compute provisioning
- Define and test disaster recovery and business continuity (RTO/RPO)
### Observability & Reliability
- Build and mature observability stack (Grafana, New Relic, Loki)
- Define and track SLOs/SLAs across services
- Lead incident management, reduce MTTR, and drive RCA culture
- Create real-time dashboards for system health and business metrics
### Security
- Own end-to-end security architecture and posture
- Implement least-privilege IAM, encryption, and secrets management
- Establish policies for PHI/PII data protection
- Lead vulnerability management, pen testing, and incident response
- Drive security-by-design across the SDLC
- Ensure secure integrations (e.g., SMART on FHIR)
### Compliance
- Lead HIPAA compliance end-to-end (policies, controls, audits)
- Own and deliver SOC 2 Type II certification
- Manage internal/external audits and customer security reviews
- Build a compliance calendar and monitoring framework
- Evaluate and prepare for HITRUST certification
### IT & Vendor Management
- Own SSO/IdP, MDM, endpoint security, and access lifecycle
- Manage and evaluate third-party vendors and tools
- Maintain vendor risk register and security reviews
- Negotiate contracts and SLAs
### Leadership & Stakeholder Management
- Build and lead a high-performing infra & security team
- Define career paths and growth frameworks
- Communicate infrastructure roadmap and security posture to leadership and customers
- Partner with engineering on secure SDLC and quality gates
## What We're Looking For
### Must-Have
- 10+ years in infrastructure, DevOps, or cloud engineering with end-to-end ownership
- 3+ years in a leadership role managing teams
- Deep expertise in GCP (production-scale environments, IaC, cost optimization)
- Proven experience leading SOC 2 Type II or HIPAA audits end-to-end
- Strong fundamentals in cloud security, IAM, and data protection
- Demonstrated success in cost reduction initiatives
- Experience building or scaling observability systems
- Ability to operate hands-on and strategically
### Nice-to-Have
- Experience in healthtech or regulated environments (Series A–C startups)
- Familiarity with FHIR, EHR integrations, and clinical data systems
- Exposure to AI/ML infrastructure and LLM systems
- HITRUST experience or awareness
- Certifications (e.g., GCP Architect, CISSP, CISM)
- Experience with Java, Python, PostgreSQL, Elasticsearch, or modern AI APIs
Sourced via wellfound · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.