Engineering
Head of Information Security
Help at Home
Full-Time
Lead
$220k – $250k/yr
United States
Posted 2d ago
Who can apply
United States
The listing asks for applicants in the United States. Confirm on the employer's page before applying.
Imported Oct 8, 2026 and not yet rechecked against the employer page. Roles can close without notice.
Source: indeed.com
Skills & tools
AWSGCPAzure
Job Description
Overview:
*Help at Home is the leading national provider of in\-home personal care services, where our mission is to enable individuals to live with independence and dignity at home. Our team supports 66,000 clients monthly with the help of 50,000 compassionate caregivers across 12 states. We’re looking for people who care about others, who are willing to listen, lean in and make impactful change. Each role at Help at Home can have a positive impact in supporting our caregivers and clients. If you are someone who leads with passion and integrity and are looking to join a rapidly growing, industry leading team, Help at Home may be a good fit for you.*
The **Head of Information Security** is responsible for leading and advancing Help at Home’s enterprise\-wide information security program. This hands\-on leadership role oversees security operations, cybersecurity strategy execution, risk management, and regulatory compliance initiatives to protect company systems, data, and business operations. The Head of Information Security partners closely with Information Technology, Finance, Legal, Compliance, Privacy, Procurement, Internal Audit, and senior business leaders to strengthen security controls, enhance organizational resilience, and foster a culture of security awareness. This position serves as a trusted advisor to executive leadership, providing strategic guidance on emerging threats, risk mitigation, and the continued maturity of the organization’s cybersecurity program.
Our Benefits:* Comprehensive medical, dental, and vision coverage
* 401(k) retirement plan
* Paid time off and holidays
* Employee assistance programs and wellness initiatives
* Flexible options to support a balanced life
Responsibilities:
***Essential Duties and Responsibilities:***
============================================
* **Program Leadership**
+ Own execution of the enterprise security strategy and roadmap, translating strategic direction into operating plans, priorities, and measurable outcomes.
+ Lead and operate the day\-to\-day security program, including governance, risk management, security operations, and program metrics.
+ Establish and maintain meaningful security metrics, key risk indicators, and reporting to support decision\-making and transparency.
+ Monitor emerging threats, legislation, and industry developments; assess risk exposure and drive timely mitigation.
* **Security Operations and Team Leadership**
+ Own day\-to\-day security operations, including monitoring and detection, vulnerability management, security engineering, and incident response.
+ Lead, hire, and develop the security team, including resource planning, coaching, and prioritization of work against business\-critical objectives.
+ Manage relationships with MSSPs, tooling partners, and other third\-party security providers and ensure vendor performance meets expectations.
+ Oversee identity and access management, cloud security, application security, and data protection programs.
+ Ensure security participation in the software development lifecycle and embed security requirements into products, platforms, and vendor relationships.
* **Policy and AI Governance**
+ Maintain and update security policies, standards, and procedures, including policies governing the responsible use of AI.
+ Participate in enterprise AI governance, partnering with IT, Legal, Compliance, and business leaders to assess AI use cases, define acceptable use, and manage data, model, and third\-party AI risk.
* **SOX, Audit, and Compliance**
+ Partner with Finance, IT, and Internal Audit to remediate material weaknesses and strengthen IT general controls, including access management and change management.
+ Own the security\-related control environment and evidence and support internal and external audit, certification, and customer assurance activities.
+ Ensure alignment with applicable regulatory requirements, including HIPAA and SOX, and recognized frameworks such as NIST CSF, ISO 27001, SOC 2, or CIS Controls.
* **Cyber Resilience and Business Continuity**
+ Lead business continuity planning (BCP) and disaster recovery alignment, working directly with business stakeholders to define critical processes, recovery objectives, and response plans.
+ Lead incident response and crisis management readiness, including tabletop exercises and post\-incident improvement.
* **Risk and Third\-Party Management**
+ Support enterprise cyber risk management, including risk identification, assessment, mitigation, and monitoring.
+ Oversee third\-party and vendor security risk assessments.
+ Support security due diligence for mergers, acquisitions, and integrations.
* **Stakeholder and Leadership Communication**
+ Act as a trusted security resource for business and technology leaders, translating technical risk into clear, practical recommendations.
+ Prepare and help present security materials for executive leadership and, as needed, the Board.
+ Build working relationships with regulators, industry groups, and external security partners as needed.
+ Lead cybersecurity awareness, education, and culture initiatives across the enterprise.
Qualifications:
***Required Skills/Abilities:***
================================
* Strong business acumen and the ability to frame information security as a business issue.
* Hands\-on leadership style with strong technical depth.
* Ability to lead a team through rapid change and competing priorities.
* Ability to influence others where there is no direct authority.
* Ability to propose creative, practical solutions to security\-specific business problems.
* Proven record of meeting operational objectives and earning the respect of the organization through results.
* Ability to translate cyber risk and technical concepts into clear recommendations for business and technology leaders.
* Strong communication skills with technical and non\-technical audiences.
* Demonstrated ownership, accountability, teamwork, and cross\-functional collaboration.
***Security Responsibilities***
===============================
All employees must follow Help at Home cybersecurity and privacy policies, protect sensitive data, complete required training, and report suspected incidents. They must also follow acceptable use and access requirements and use only authorized systems.
***Education and Experience:***
===============================
* Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field, or equivalent relevant experience required.
* 12\+ years of experience in information security, including 3\+ years leading security teams, programs, or cross\-functional security initiatives required.
* Hands\-on experience running security operations, including incident response and vulnerability management, and managing MSSP or vendor partners required.
* Experience remediating SOX / ITGC control deficiencies or material weaknesses required.
* Experience developing and running BCP/DR programs with non\-technical business stakeholders required.
* Experience maintaining and updating security policy, including emerging areas such as AI usage required.
* Working knowledge of security and compliance frameworks such as NIST, ISO 27001, SOC 2, or CIS Controls required.
* Security certification such as CISSP, CISM, CISA, CRISC, or CCSP preferred.
* Healthcare or other highly regulated industry experience preferred.
* Experience in a public\-company or SOX\-regulated environment preferred.
* Experience with AI governance frameworks, such as NIST AI RMF, preferred.
* Experience with cloud security (AWS, Azure, GCP, or hybrid) and enterprise security technologies such as SIEM, EDR/XDR, IAM, and DLP preferred.
* Experience supporting M\&A security integration preferred.
* Experience leading tabletop exercises, penetration testing, or red team/blue team activities preferred.
Pay Range: USD $220,000\.00 \- USD $250,000\.00 /Yr.
Get jobs like this by email
New listings that match your roles and regions, weekly or daily. Salary and who-can-apply shown for every job.
Before you apply
Similar Jobs
Staff Software Engineer, Enterprise Platform
DiscordDiscord · OregonFull-Time · OregonDirect
PythonTypeScriptTerraform
$248k – $279kYesterdayView details$248k – $279kYesterday
Data Visualization & Full Stack Developer (Palantir Foundry)
IPT AssociatesIPT Associates · United StatesFull-Time · United StatesDirect
ReactPythonTypeScript
$85k – $95kYesterdayView details$85k – $95kYesterday
Senior Application Engineer [Remote-US]
QuanataQuanata · United StatesFull-Time · United StatesDirect
Node.jsPythonJavaScript
$232k – $379kYesterdayView details$232k – $379kYesterday
Software Engineer II, Fullstack (Ads Platform)
AffirmAffirm · CaliforniaFull-Time · CaliforniaDirect
ReactPython
$146k – $225kYesterdayView details$146k – $225kYesterday
Senior Software Engineer, Fullstack (App Experience)
AffirmAffirm · CaliforniaFull-Time · CaliforniaDirect
ReactVuePython
$173k – $255kYesterdayView details$173k – $255kYesterday
Senior DevOps Engineer
EncouraEncoura · United StatesFull-Time · United StatesDirect
PythonPostgreSQLMongoDB
$140k – $155kYesterdayView details$140k – $155kYesterday
Software Engineer II, Backend (Batch Developer Experience)
AffirmAffirm · CaliforniaFull-Time · CaliforniaDirect
PythonMySQLAWS
$146k – $225kYesterdayView details$146k – $225kYesterday
Power Apps Developer
General Dynamics Information TechnologyGeneral Dynamics Information Technology · United States · EST hoursFull-Time · United States · EST hoursDirect
ReactNode.jsPython
$81k – $109kYesterdayView details$81k – $109kYesterday
Senior Software Engineer, Full Stack
momo · United StatesFull-Time · United StatesDirect
Next.jsJavaREST
$140k – $158kYesterdayView details$140k – $158kYesterday
IT
Senior Platform Engineer (AI Applications)
Improvix TechnologiesImprovix Technologies · Washington or District of ColumbiaFull-Time · Washington or District of ColumbiaDirect
PythonTypeScriptJava
$180k – $220kYesterdayView details$180k – $220kYesterday