Job Opportunities API

The Public Ledger of Openings

← Back to the ledger

Director, Security Engineering

Virtahealth
CompanyVirtahealth
CategoryEngineering
LocationRemote
RemoteRemote
EmploymentNot stated
LevelDirector
SalaryUSD 162k–209k
Posted5 Aug 2026
Last verified6 Aug 2026
SourceEmployer ATS (ashby)
Applications are handled by the employer, not by us.Apply on the employer's site →
Description
Virta Health is on a mission to reverse metabolic disease in one billion people. Current treatment approaches aren’t working—over half of US adults have either type 2 diabetes or prediabetes, and obesity rates are at an all-time high. Virta is changing this by helping people reverse their metabolic condition through innovations in technology, personalized nutrition, and virtual care delivery reinvented from the ground up. We have raised over $350 million from top-tier investors, and partner with the largest health plans, employers, and government organizations to help their employees and members restore their health and take back their lives. Join us on our mission to reverse metabolic disease in one billion people. As our Director of Security Engineering & Operations, you will hold a highly critical and transformative position at Virta. Leading both our Enterprise Security Engineering and Security Operations (SecOps) functions, you will serve as a visionary "player-coach" who directs a talented team of engineers while owning the operational defense of our enterprise. You will personally spearhead our Zero Trust Architecture (ZTA) transition—restricting lateral movement and containing blast radius—while simultaneously managing outsourced 24/7 Managed Detection and Response (MDR/SOC) partner. By blending deep technical engineering oversight with a robust, zero-latency incident response posture, you will ensure our systems remain resilient, our developer workflows stay frictionless, and our patient data stays meticulously protected. RESPONSIBILITIES - Hands-on Engineering & Operational Leadership: Direct, mentor, and grow a high-performing team of security engineers. Conduct technical sprint planning, alignment, and coaching while maintaining the technical depth to dive into configurations alongside your team. - Architect & Champion Zero Trust Strategy: Lead the enterprise-wide transition to Zero Trust Architecture (ZTA) across IT, corporate platforms, and cloud engineering infrastructure. Drive ZTA core pillars: establishing identity as the perimeter, inhibiting lateral movement, and prioritizing data survivability. - Oversee 24/7 Security Operations (SecOps): Serve as the ultimate owner of Virta’s monitoring, detection engineering, and incident response program. Manage our outsourced MDR/SOC vendor relationships, ensuring seamless telemetry pipelines, rapid alert triage, and zero-latency threat containment. - Manage and Minimize Blast Radius: Design, deploy, and maintain robust blast radius reduction solutions. This includes implementing micro-segmentation boundaries (such as GCP VPC Service Controls to prevent administrative data movement to external storage) and enforcing ephemeral Workload Identity protocols (replacing static passwords with temporary 1-hour tokens). - Own Threat Defense & Containment Blueprints: Curate and update the primary operational artifacts that map and safeguard our environment: our Data Topology Map, Cyber Asset Attack Surface (CAA) Matrix, Workload Ledger design, and technical Containment Playbooks. - Operationalize Risk-Based Vulnerability Management (RBVM): Evaluate both legacy stacks and modern cloud services against the Zero Trust Maturity Model (ZTMM). Define strict patching and remediation SLAs, and partner cross-functionally with IT and Foundations Engineering to drive targeted mitigation. - Cross-Functional Collaboration: Coordinate closely with GRC, IT, and Product teams to ensure that operational security policies are seamlessly integrated into code pipelines (Secure by Design CI/CD) and that rapidly evolving enterprise AI tools operate with appropriate context-aware guardrails. 90 DAY PLAN Within your first 90 days at Virta, we expect you will do the following: - First 30 days: Deep dive into Virta’s cloud infrastructure (GCP) and existing IT security tools. Establish collaborative, high-trust relationships with your engineering team, IT, GRC peers, an