Logo for OptiMantra

Lead Cybersecurity Engineer

Role overview

Qualifications

  • 5+ years of experience in cybersecurity or information security, with increasing responsibility in security engineering
  • 2+ years of experience securing production cloud environments, preferably AWS
  • Demonstrated experience with the AWS security ecosystem, including IAM, CloudTrail, GuardDuty
  • Experience implementing, maintaining and evidencing security controls aligned with frameworks and standards such as NIST, HITRUST, ISO 27001, HIPAA, SOC 2

Responsibilities

  • Lead the Compliance Workstream, including technical implementation of SOC 2 and HIPAA requirements
  • Secure and harden production AWS environments, implementing AWS security controls and tooling
  • Establish and operate security monitoring and detection capabilities tailored to the company’s clinical SaaS environment
  • Own and maintain security policies and procedures across the organization, including endpoint security practices

Key facts

Hard skills

Other skills

  • Communication
  • Teamwork
  • Problem Solving

About the company

OptiMantra logo

OptiMantra

Digital Health & Health Tech

Unknown

Company details

IndustryDigital Health & Health Tech
Company size11 - 50

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

The Company 

Cerbo · OptiMantra is a healthcare technology company built for the practices actively changing how medicine is delivered. Our platforms serve functional, integrative, direct primary care, concierge, med spa and behavioral health practitioners who need software that keeps pace with how they work, not the other way around.  

Each platform is a purpose-built EHR and practice management solution. Cerbo is architected for clinical depth: deep configuration, protocol-specific workflows and the kind of flexibility that holistic and functional medicine practices require. OptiMantra is structured for scale: multi-modality breadth, out-of-the-box readiness and the operational infrastructure that growing practices rely on.  

Together, our two platforms form a leading presence in this rapidly expanding market. Our practitioners are redefining what a patient experience can look like. We exist to give them the technology foundation to do exactly that, at whatever size and pace they choose to grow.  

Summary 

As Lead Cybersecurity Engineer, you will lead the company’s cybersecurity program across Cerbo and OptiMantra, supporting the protection of protected health information (PHI) and the security of production platforms serving thousands of clinicians and millions of patients. This role will oversee the development, implementation, and ongoing improvement of a unified security program across both products, including security controls, policies, risk management, compliance, and security operations. The Lead Cybersecurity Engineer will serve as the technical owner of the company’s security program, establishing and advancing the security practices, standards, and processes that support both platforms. 

This position requires an individual with hands-on experience securing cloud environments, implementing security controls, and deploying and operating security tooling in production. The Lead Cybersecurity Engineer will lead the technical execution of initiatives supporting HIPAA compliance and the company’s SOC 2 Type II program, including control implementation, evidence collection, security assessments, and continuous improvement of the organization’s security posture. 

Working cross-functionally with DevOps, Engineering, IT, and other stakeholders, this role will evaluate and implement security solutions, harden cloud infrastructure, establish security standards and processes, and identify opportunities to strengthen security across both products while balancing common organizational controls with product-specific requirements. 

Reporting to the Chief Technology Officer, this is a hands-on technical leadership role for an individual who can operate effectively across security engineering, cloud security, and compliance while building and advancing the company’s cybersecurity program. 

Responsibilities 

Lead the Compliance Workstream  

  • Own the technical implementation and ongoing management of the company’s SOC 2 Trust Services Criteria and HIPAA Security Rule requirements across AWS environments supporting Cerbo and OptiMantra, including control mapping, evidence collection, policy management, and continuous monitoring.   
  • Lead compliance documentation and remediation efforts, including control narratives, system and data-flow documentation, scope determinations, and prioritization and closure of security and compliance gaps with supporting evidence.   
  • Serve as the technical point of contact for auditors and assessors and drive the compliance workstream to completion, coordinating interviews, artifact requests, demonstrations, remediation activities, dependencies, and key audit milestones across teams.  

Cloud Security Engineering (AWS)  

  • Secure and harden production AWS environments across Cerbo and OptiMantra, including cloud infrastructure, Kubernetes and container environments, databases, networking, web application security, and disaster recovery environments.   
  • Implement and operate AWS security controls and tooling, including IAM and privileged access management, MFA, least-privilege access, security monitoring, encryption and key management, vulnerability management, and audit logging.   
  • Strengthen security across both platforms by establishing and advancing common standards for access, tenant isolation, data protection, backup and disaster recovery, and other cloud security controls, partnering with Engineering, DevOps, IT, and Product to implement and maintain these controls.  

Security Operations & Detection  

  • Establish and operate security monitoring and detection capabilities, including centralized logging, alerting, threat detection, and response processes tailored to the company’s clinical SaaS environment.   
  • Own the security incident response and vulnerability management programs, including playbooks, tabletop exercises, breach assessment, vulnerability scanning, remediation tracking, and coordination with Engineering and external security providers.   
  • Lead security testing and continuous improvement efforts, including penetration testing, DAST, security assessments, findings remediation, and retesting.  

Endpoint, Identity & Corporate Security  

  • Own and maintain security policies, procedures, and workforce security programs across the combined organization, including security awareness, phishing simulations, HIPAA training, and compliance tracking.   
  • Lead identity and endpoint security practices to protect corporate systems, users, and sensitive data, partnering with IT and Engineering to implement and continuously improve security controls.   
  • Manage third-party security and vendor risk, including security assessments, business associate agreements, subprocessor diligence, and ongoing oversight of vendors that access or process PHI.  

Customer-Facing Security  

  • Serve as the technical security partner for customers and strategic partners, leading security questionnaires, architecture reviews, and security discussions with clinic IT and enterprise security teams.   
  • Support customer and partner security requirements throughout the sales and contracting process, including security terms related to incident notification, data retention and export, backup and disaster recovery, AI, and subprocessors. 

Required Qualifications  

  • 5+ years of experience in cybersecurity or information security, with increasing responsibility in security engineering  
  • 2+ years of experience securing production cloud environments, preferably AWS, including cloud identity and access management, network security, logging/monitoring, and security controls  
  • Demonstrated experience with the AWS security ecosystem, including IAM, CloudTrail, GuardDuty, Security Hub, KMS, VPC security and related AWS security services  
  • Experience implementing, maintaining and evidencing security controls aligned with frameworks and standards such as NIST, HITRUST, ISO 27001, HIPAA, SOC 2, or similar  
  • Experience securing Kubernetes and containerized production environments, including identity, network security, image security, and runtime controls  
  • Experience serving as a technical owner during a third-party security audit, assessment, or certification  
  • Experience deploying, configuring, and operating cybersecurity tools in production, such as EDR, SIEM/log management, vulnerability management, WAF, or similar technologies  
  • Demonstrated ability to lead complex cybersecurity initiatives, establish security standards and processes, and serve as a technical subject-matter expert across the organization  

Preferred Qualifications  

  • Bachelor’s degree in cybersecurity, information security or relevant field  
  • Experience working in a PE-backed, high-growth, or rapidly scaling organization   
  • Experience working with healthcare technology, SaaS or other technology-enabled B2B businesses  
  • Experience securing multi-tenant SaaS environments, including tenant isolation, access controls, and shared infrastructure  
  • Experience working across cloud, DevOps, SRE, or application security environments, with exposure to infrastructure as code, CI/CD, Kubernetes, secure code practices, or vulnerability remediation  

Compensation & Benefits 

  • Competitive compensation based on experience 
  • Paid Time Off and company holidays 
  • Comprehensive health, dental and vision benefits 
  • Short-term and long-term disability Insurance 
  • 401k plan with matching company contribution 
  • Real ownership and impact in a fast-growing health tech company 

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Cybersecurity Engineer Related jobs

Other jobs at OptiMantra

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.