Smartlinx Solutions LLC logo

Lead, Cybersecurity

Smartlinx Solutions LLC
Posted 2 hours ago
United StatesRemoteEngineering & Development
Is this job info correct?
Description

Since 2000, Smartlinx has been redefining how senior care organizations manage their workforce. Our modern, purpose-built solutions from dynamic scheduling and compliance to integrated payroll and real-time analytics give providers the agility and intelligence needed to thrive in today's healthcare environment.

As the parent company of BekTek (HostedTime) and StafferLink, Smartlinx brings together a wide range of solutions for managing both full-time and contingent staff. Together, these capabilities give Smartlinx the most comprehensive workforce management solution set in senior care.

We are driven by one mission: to power exceptional senior care through smarter workforce management. Join us as we shape the future of work in long-term care.


About the Role

Reporting to the Head of IT, the Lead, Cybersecurity is responsible for defining and operating Smartlinx's cybersecurity program across its multi-tenant SaaS products, cloud infrastructure, corporate technology environment, data platforms, integrations, and third-party services.

This leader owns SaaS product and application security, cloud and infrastructure security, identity and access management, vulnerability management, security monitoring, incident response, third-party risk, and SOC 2 Type II readiness and audit execution. The role is accountable for protecting sensitive healthcare workforce, payroll, personally identifiable information, and customer data while enabling reliable and timely product delivery.

The Lead, Cybersecurity will partner closely with Product, Engineering, Architecture, Quality Assurance, DevOps, Data Engineering, Corporate IT, Compliance, Legal, Customer Support, and Customer Success to integrate security into design, development, deployment, operations, and customer commitments.

Success in this role requires a hands-on, pragmatic security leader who can translate business and regulatory requirements into effective technical controls, personally investigate risk and incidents, drive remediation to closure, and communicate clearly with executives, auditors, customers, and technical teams.


Key Responsibilities


SaaS Product and Application Security

  • Own the product-security strategy and operating model across the Smartlinx, BekTek (HostedTime), and StafferLink product portfolio.
  • Embed security throughout the product development lifecycle, including requirements, architecture, design, development, testing, release, and production operation.
  • Lead threat modeling, security architecture reviews, abuse-case analysis, and risk assessments for new products, features, APIs, integrations, mobile applications, and material platform changes.
  • Establish secure coding standards and engineering guidance based on OWASP, CWE, API security, and relevant industry practices.
  • Integrate automated security testing into CI/CD pipelines, including static application security testing, dynamic application security testing, software composition analysis, secrets scanning, infrastructure-as-code scanning, container scanning, and software bill of materials generation.
  • Review and strengthen authentication, authorization, role-based access control, session management, tenant isolation, API security, file handling, encryption, audit logging, and secure data-export capabilities.
  • Plan and coordinate independent application and API penetration testing, validate findings, assign risk-based remediation deadlines, and confirm closure through retesting.
  • Assess AI-enabled product capabilities and third-party AI services for prompt injection, data leakage, tenant isolation, model access, sensitive-data handling, human oversight, and other emerging risks.
  • Define proportionate release-security gates and exception processes that protect customers without creating unnecessary friction for engineering delivery.


Cloud and Infrastructure Security

  • Lead security architecture and control implementation for Smartlinx's Microsoft Azure cloud environments, production and non-production infrastructure, corporate systems, endpoints, networks, and remote-work capabilities.
  • Establish secure cloud baselines using recognized frameworks and vendor guidance; continuously identify and remediate configuration drift, exposed services, excessive permissions, unsupported software, and insecure defaults.
  • Strengthen network security through segmentation, private connectivity, firewall and security-group governance, DDoS protection, secure administrative access, and controlled ingress and egress.
  • Implement and govern secrets management, certificate management, encryption, key rotation, secure service identities, and protection of privileged credentials across applications and infrastructure.
  • Partner with DevOps and Corporate IT to maintain effective patching, endpoint protection, malware defense, vulnerability scanning, cloud security posture management, and secure configuration management.
  • Review the security of databases, data lakes, warehouses, analytics platforms, ETL and ELT pipelines, customer data exchanges, backups, and disaster-recovery environments.
  • Ensure logging, telemetry, alerting, and forensic data are available across cloud resources, applications, identities, endpoints, networks, and data platforms to support timely detection and investigation.
  • Assess resilience to destructive cyber events, including ransomware and credential compromise, and validate recoverability through protected backups, restoration tests, and cyber-recovery exercises.


SOC 2, Healthcare Compliance, and Audit Readiness

  • Lead Smartlinx's SOC 2 Type II readiness, control design, evidence collection, auditor coordination, remediation, management responses, and annual attestation cycle.
  • Build a continuous-control-monitoring program that keeps the organization audit-ready throughout the year rather than relying on a point-in-time preparation effort.
  • Define, document, test, and improve controls across access management, change management, secure software development, vulnerability management, incident response, vendor risk, data protection, and business continuity.
  • Maintain the control matrix, security policies, standards, procedures, risk register, evidence repository, exception records, remediation plans, and executive compliance reporting.
  • Apply healthcare security and privacy requirements, including HIPAA and HITECH, to product, infrastructure, operational, vendor, and data-handling decisions; support business associate and customer contractual obligations.
  • Evaluate alignment with NIST, CIS Controls, ISO 27001, and HITRUST expectations where they strengthen the security program or support customer and market requirements.
  • Coordinate effectively with external auditors, penetration-testing providers, legal counsel, cyber-insurance partners, customers, and other independent assessors.
  • Lead or support responses to customer security questionnaires, due-diligence reviews, contractual security requirements, and customer audit requests with accurate, consistent, and timely information.


Vulnerability, Risk, and Third-Party Security

  • Establish a unified vulnerability-management program covering SaaS applications, APIs, cloud infrastructure, endpoints, containers, databases, open-source components, and third-party software.
  • Prioritize remediation using severity, exploitability, exposure, asset criticality, data sensitivity, customer impact, compensating controls, and active-threat intelligence rather than relying on CVSS scores alone.
  • Define measurable remediation service-level targets for critical, high, medium, and low-risk findings; monitor aging, exceptions, recurrence, and closure quality.
  • Own formal security-risk acceptance, exception, escalation, and expiration processes, ensuring material risks receive appropriate executive visibility and approval.
  • Conduct periodic enterprise, product, cloud, and data-security risk assessments and translate findings into prioritized, funded remediation roadmaps.
  • Evaluate vendors, subprocessors, managed services, technology partners, and AI providers for security, privacy, resilience, data handling, incident notification, and contractual risk before onboarding and throughout the relationship.
  • Monitor changes in the threat landscape, exploited vulnerabilities, attack techniques, and healthcare-sector risks; convert relevant intelligence into actionable protections and tests.


Security Operations, Incident Response, and Resilience

  • Define and operate security monitoring across applications, cloud infrastructure, identities, endpoints, networks, databases, and data platforms using SIEM, EDR, WAF, and related capabilities.
  • Develop high-value detection use cases for account compromise, privilege escalation, anomalous access, data exfiltration, malicious application activity, insecure configuration changes, and other material threats.
  • Own the cybersecurity incident-response plan, severity model, escalation paths, on-call expectations, investigation procedures, communications protocols, evidence handling, and post-incident review process.
  • Lead or coordinate containment, eradication, recovery, forensic analysis, customer-impact assessment, regulatory and contractual notification support, and executive communication during security incidents.
  • Conduct regular tabletop exercises involving executive leadership, Engineering, DevOps, IT, Legal, Compliance, Customer Support, Customer Success, and Communications; document gaps and drive corrective actions to closure.
  • Track and improve security operational measures such as mean time to detect, acknowledge, contain, recover, and permanently remediate incidents and recurring control failures.
  • Establish relationships and operating procedures with external incident-response, forensic, legal, insurance, and specialized security partners before an incident occurs.


Identity, Data Protection, and Privacy by Design

  • Establish an identity-first security model based on least privilege, multifactor authentication, privileged access management, separation of duties, conditional access, and periodic access certification.
  • Strengthen joiner, mover, and leaver processes for employees, contractors, service accounts, customer support access, production access, and privileged roles.
  • Define and govern security controls for Microsoft Entra ID, application identities, API credentials, machine accounts, emergency access, and third-party access.
  • Partner with data owners, Product, Legal, Compliance, and Engineering to implement data classification, minimum-necessary access, encryption, masking, retention, deletion, and secure disposal.
  • Protect sensitive healthcare workforce, payroll, tax, financial, personally identifiable, and authentication data throughout collection, processing, storage, transmission, sharing, export, backup, and disposal.
  • Implement data-loss-prevention controls and monitoring appropriate to corporate systems, SaaS products, data platforms, collaboration tools, endpoints, and customer data-sharing workflows.
  • Incorporate privacy and security by design into product decisions, integration patterns, analytics, AI use cases, customer implementations, and vendor engagements.


Security Governance, Leadership, and Performance Management

  • Develop and execute a practical, risk-based cybersecurity strategy, annual operating plan, budget, staffing model, and multiyear roadmap aligned with Smartlinx's product and business priorities.
  • Define clear security ownership, decision rights, standards, escalation paths, and measurable objectives across Product, Engineering, DevOps, Data Engineering, Corporate IT, and business functions.
  • Create executive and Board-level security reporting that clearly communicates material risks, incidents, audit readiness, remediation progress, control effectiveness, investment needs, and business tradeoffs.
  • Establish a concise cybersecurity scorecard covering critical exposure, remediation aging, secure-development adoption, privileged access, control performance, incidents, vendor risk, audit findings, and security-awareness outcomes.
  • Select, manage, and rationalize security tools and platforms; ensure investments produce measurable risk reduction and operational value.
  • Build a culture of accountability and partnership in which teams understand their security responsibilities and raise risks early without fear of blame.
  • Deliver role-based security education for engineers, administrators, support teams, executives, and the broader workforce, including phishing resistance and incident-reporting readiness.
  • Recruit, coach, and develop security employees or contractors as the function grows, while remaining personally engaged in architecture, investigation, remediation, and audit execution.
Requirements

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Engineering, Information Systems, or a related field, or equivalent practical experience.
  • 8+ years of progressive experience across product, application, cloud, infrastructure, or security-operations disciplines, including 3+ years in a lead, principal, architect, or security-program ownership role.
  • Demonstrated experience securing multi-tenant B2B SaaS products in healthcare, payroll, HR technology, or another regulated environment and protecting PHI, PII, financial, or other sensitive data.
  • Direct, hands-on experience leading at least one successful SOC 2 Type II audit cycle, including control design, evidence collection, auditor coordination, remediation, management responses, and continuous control operation.
  • Strong Microsoft Azure security experience across cloud networking, identity, compute, storage, databases, containers, Kubernetes, infrastructure as code, secrets, logging, monitoring, backup, and recovery.
  • Deep knowledge of secure software development, threat modeling, web, mobile, and API security, authentication, authorization, tenant isolation, OWASP risks, and DevSecOps practices.
  • Hands-on experience with SAST, DAST, SCA, SBOM, secrets scanning, SIEM, EDR, DLP, WAF, CSPM, vulnerability scanning, penetration testing, and related security capabilities.
  • Proven ability to manage vulnerabilities, security findings, and incidents through risk assessment, containment or remediation, retesting, exception management, post-incident review, and executive reporting.
  • Strong knowledge of the SOC 2 Trust Services Criteria, NIST Cybersecurity Framework, CIS Controls, ISO 27001, and HITRUST.
  • Demonstrated ability to make sound risk-based decisions, balance security with product delivery, influence cross-functional stakeholders, and explain technical risks clearly to executives, auditors, customers, and engineers.
  • Relevant certifications such as CISSP, CCSP, CISM, CISA, CSSLP, OSCP, GIAC, HITRUST CCSFP, or Microsoft Azure Security Engineer are preferred; experience with Entra ID, Defender, Sentinel, Azure DevOps, Snowflake, or Microsoft Fabric is also preferred.


Additional Information

  • Position Type: Full-Time
  • Work Location: Remote
  • Travel Requirements: Occasional travel, up to 15%


Smartlinx values and celebrates diversity, equity, inclusion and belonging and evaluate qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other protected characteristic. We value your hard work, integrity, and commitment to make things better, and we put people first by offering you benefits that support your life and well-being including remote environments as applicable, Medical, Dental, Vision, FSA & HSA, Life Insurance, Pet Insurance and 401(k). Join us and you’ll develop your skills and expertise to rise to the very highest levels, working in an environment for a company known for brilliance and innovation.

Salary Description
$150K + 10% bonus eligible

Similar jobs