Logo for Stedi

Head of Security

Role overview

Qualifications

  • Significant experience owning security programs in cloud-native environments
  • Deep technical ability in the security domain with the ability to engage in high-bandwidth discussions with application engineers
  • Strong legal and regulatory instincts with healthcare or HIPAA experience considered a strong plus
  • Exceptional communicator with a pragmatic approach and a track record of using automation and modern tooling to reduce toil

Responsibilities

  • Own and scale Stedi's security program end-to-end, including policies, controls, procedures, security tooling, training, vulnerability management, and vendor risk
  • Lead breach preparedness, incident response, disaster recovery, and business continuity programs to detect, contain, and recover rapidly from significant security events
  • Advise on security risk for product decisions, architecture, and partnerships, and collaborate with Engineering to minimize development friction
  • Represent Stedi's security posture to customers, partners, regulators, and the executive team; coordinate with Legal on regulatory obligations and reporting

About the company

Stedi logo

Stedi

Digital Health & Health Tech

Stedi allows developers to instantly automate real-time eligibility checks and claims processing with APIs that support thousands of payers.We’ve raised $71 million from Addition, Stripe, Union Square Ventures, First Round Capital, Bloomberg Beta, and other top investors.

Company details

Company typeStartup
IndustryDigital Health & Health Tech
Company size11 - 50

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

We're building a new healthcare clearinghouse

Stedi is building the first new healthcare clearinghouse in decades. In the healthcare sector, the Health Insurance Portability and Accountability Act of 1996 (HIPAA) requires that all insurance payers exchange transactions such as claims, eligibility checks, prior authorizations, and remittances using a standardized EDI format called X12 HIPAA. Clearinghouses process the majority of these transactions, offering consolidated connectivity to carriers and providers. Until Stedi, the space was occupied entirely by a small group of legacy players, built on outdated, often pre-internet technology.

Stedi is the world's only programmable healthcare clearinghouse. By offering modern API interfaces alongside traditional real-time and batch EDI processes, we enable both healthcare technology businesses and established players to exchange mission-critical transactions. Our clearinghouse product and customer-first approach have set us apart. Stedi was ranked by Ramp as one of the fastest-growing SaaS vendors.

We have lightning in a bottle: engineers and designers shipping products week in and week out; a lean business team supporting the company’s infrastructure; passion for automation and eliminating toil; $142 million in funding from top investors like Stripe, Addition, USV, Bloomberg Beta, First Round Capital, and more. To learn more about how we work, watch our founder Zack’s interview with First Round Capital.

What we’re looking for

We are hiring a Head of Security to take full ownership of security at Stedi, reporting directly to the CEO and working at the intersection of engineering, legal, product, and more.

At Stedi, security is job zero. There is nothing more important than securing our systems. This role exists to operationalize that principle across every function of the company.

You won’t be building from scratch. We already have SOC 2 Type 2 and HIPAA certifications and will soon have HITRUST R2 certification. We view these compliance items as a baseline starting point and not the final destination. We have invested heavily in security from the earliest days. We have extensive controls across our engineering and IT infrastructure (from SCPs to DLP and everything in between), and 100% of our customer data is processed within AWS without exception. We work extensively with AWS’s native tools as well as with AWS teams, including on an IAM access vulnerability that we discovered.

You will own our security function end-to-end: incident readiness, regulatory obligations, customer trust, and the day-to-day fundamentals that enable everything else. You will be the bridge between engineering and legal, working closely with leadership from both teams and the CEO. You’ll inherit a strong foundation to scale in our next phase of growth – building out the team, programs, and processes that let a lean company move fast while maintaining a world-class security posture.

What you’ll do

  • Own and build Stedi's security program end-to-end, including policies, controls, procedures, security tooling, training, vulnerability management, vendor risk, and more.

  • Be a strong hands-on contributor from day 1 while also building a roadmap for scaling the security function as the company continues to grow. We have a culture where leaders are contributors and are deeply involved in the technical details.

  • Advise on security risk tied to product decisions, architecture, and partnerships.

  • Leverage our best-in-category security posture to unlock new customers and strategic relationships.

  • Partner with Engineering to maintain security excellence while minimizing development friction.

  • Lead breach preparedness and incident response: build, test, and own the Security Incident Response Plan, Disaster Recovery, and Business Continuity programs so Stedi can detect, contain, and recover rapidly in the unlikely event of a significant issue.

  • Represent Stedi in conversations with customer and partner security leadership teams, and provide clear, regular reporting on security posture and risk to the executive team and board.

  • Partner with Legal on regulatory obligations, breach notification requirements, and the legal dimensions of security incidents - be ready to engage directly with regulators should the need ever arise.

  • Build mechanisms for continuous security improvement, and establish practical, role-appropriate security training across the company.

Who you are

  • Significant experience owning security programs in cloud-native environments.

  • Deep technical ability in the security domain and enough working knowledge to have high-bandwidth discussions with application engineers.

  • Strong legal and regulatory instincts – you have the ability to understand legal issues and can speak credibly with regulators; healthcare or HIPAA experience is a strong plus.

  • Opinionated but pragmatic, with strong judgment about where rigor matters most and a bias toward solutions over problems.

  • Exceptional communicator: you can explain security risk clearly to engineers, executives, customers, and regulators, in writing and in person.

  • You’re excited to use automation and modern tooling to eliminate toil and raise the bar, not to build bureaucracy.

We’ve been made aware of individuals impersonating the Stedi recruiting team. Please note:

  • All official communication about roles at Stedi will only come from an @stedi.com email address, or from our official identification verification partner, Persona, @frompersona.com.

  • If you’re unsure whether a message is legitimate or have any concerns, feel free to contact us directly at careers@stedi.com.

We appreciate your attention to this and your interest in joining Stedi.

At Stedi, we're looking for people who are deeply curious and aligned to our ways of working. You're encouraged to apply even if your experience doesn't perfectly match the job description.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Related jobs

Other jobs at Stedi

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.