Head of Corporate and Information Security
Core
Own Layer's security strategy and risk program, building a comprehensive security posture for a healthcare AI platform handling PHI and sensitive customer data.
Role type
Head of Corporate and Information Security
Builds
Security strategy, risk program, technical controls, and compliance frameworks (SOC2, ISO 27001) for a healthcare AI startup.
Domain
Healthcare technology, Cloud Security, Information Security
Deliverable
production ML models | infrastructure | dashboards & analysis
Required skills
Security strategy and risk management, Cloud security (GCP), Data protection (PHI/PII), Security operations (SOC/SIEM), Incident response, Compliance frameworks (SOC2, ISO 27001), Identity and access management, Vulnerability management, Security architecture review, Human security training
Preferred skills
Healthcare industry experience (HIPAA), ISO 27001 certification leadership, AWS/Azure experience
Technologies
GCP, SIEM, Google Workspace
Responsibilities
Develop security strategy and risk roadmap; strengthen technical security posture across cloud and SDLC; protect sensitive data throughout lifecycle; build detection and incident response capabilities; manage corporate security (endpoints, SaaS, identity); lead security awareness and training programs; collaborate with leadership on risk balancing.
Seniority
Senior, hands-on IC with strategic mandate