Director, Security Engineering
Job Description
Virta Health is on a mission to reverse metabolic disease in one billion people. Current treatment approaches aren’t working—over half of US adults have either type 2 diabetes or prediabetes, and obesity rates are at an all-time high. Virta is changing this by helping people reverse their metabolic condition through innovations in technology, personalized nutrition, and virtual care delivery reinvented from the ground up. We have raised over $350 million from top-tier investors, and partner with the largest health plans, employers, and government organizations to help their employees and members restore their health and take back their lives. Join us on our mission to reverse metabolic disease in one billion people.
As our Director of Security Engineering & Operations, you will hold a highly critical and transformative position at Virta. Leading both our Enterprise Security Engineering and Security Operations (SecOps) functions, you will serve as a visionary "player-coach" who directs a talented team of engineers while owning the operational defense of our enterprise. You will personally spearhead our Zero Trust Architecture (ZTA) transition—restricting lateral movement and containing blast radius—while simultaneously managing outsourced 24/7 Managed Detection and Response (MDR/SOC) partner. By blending deep technical engineering oversight with a robust, zero-latency incident response posture, you will ensure our systems remain resilient, our developer workflows stay frictionless, and our patient data stays meticulously protected.
RESPONSIBILITIES
- Hands-on Engineering & Operational Leadership: Direct, mentor, and grow a high-performing team of security engineers. Conduct technical sprint planning, alignment, and coaching while maintaining the technical depth to dive into configurations alongside your team.
- Architect & Champion Zero Trust Strategy: Lead the enterprise-wide transition to Zero Trust Architecture (ZTA) across IT, corporate platforms, and cloud engineering infrastructure.
Drive ZTA core pillars: establishing identity as the perimeter, inhibiting lateral movement, and prioritizing data survivability.
- Oversee 24/7 Security Operations (SecOps): Serve as the ultimate owner of Virta’s monitoring, detection engineering, and incident response program. Manage our outsourced MDR/SOC vendor relationships, ensuring seamless telemetry pipelines, rapid alert triage, and zero-latency threat containment.
- Manage and Minimize Blast Radius: Design, deploy, and maintain robust blast radius reduction solutions. This includes implementing micro-segmentation boundaries (such as GCP VPC Service Controls to prevent administrative data movement to external storage) and enforcing ephemeral Workload Identity protocols (replacing static passwords with temporary 1-hour tokens).
- Own Threat Defense & Containment Blueprints: Curate and update the primary operational artifacts that map and safeguard our environment: our Data Topology Map, Cyber Asset Attack Surface (CAA) Matrix, Workload Ledger design, and technical Containment Playbooks.
- Operationalize Risk-Based Vulnerability Management (RBVM): Evaluate both legacy stacks and modern cloud services against the Zero Trust Maturity Model (ZTMM). Define strict patching and remediation SLAs, and partner cross-functionally with IT and Foundations Engineering to drive targeted mitigation.
- Cross-Functional Collaboration: Coordinate closely with GRC, IT, and Product teams to ensure that operational security policies are seamlessly integrated into code pipelines (Secure by Design CI/CD) and that rapidly evolving enterprise AI tools operate with appropriate context-aware guardrails.
90 DAY PLAN
Within your first 90 days at Virta, we expect you will do the following:
- First 30 days: Deep dive into Virta’s cloud infrastructure (GCP) and existing IT security tools. Establish collaborative, high-trust relationships with your engineering team, IT, GRC peers, and external MDR partners. Conduct an baseline assessment of our current Zero Trust Maturity Model (ZTMM) status.
- Day 30-60: Work with your team to deliver the baseline Data Topology Map and initial CAA Matrix. Audit our external MDR ingestion pipelines, tuning high-priority alert workflows and integrating security alerting directly into team communication channels. Secure GitHub pipeline configs to expand automated secrets-detection.
- Day 60-90: Finalize the Workload Ledger design and roll out the first phase of micro-segmentation guardrails (including pilot GCP VPC-SC boundaries). Standardize technical Containment Playbooks for high-risk threat scenarios and present a clean Security Operations and ZTA maturity metrics dashboard to executive leadership.
MUST-HAVES
- 10+ years of dedicated experience in Cybersecurity, Cloud Infrastructure Security, or SecOps, with at least 3+ years managing, leading, or mentoring high-performing security teams.
- Demonstrated experience overseeing incident response programs and managing external vendors (such as 24/7 outsourced MDR/SOC partners, SIEM platforms, and EDR/XDR toolsets).
- Deep technical expertise in cloud security architecture (ideally GCP), with hands-on experience building micro-segmentation models, establishing ephemeral workload identity controls, and securing CI/CD pipelines.
- Exceptional analytical capability to map systemic relationships, formulate risk prioritization frameworks (RBVM), and apply Zero Trust Maturity Models to live corporate structures.
- Proven track record of architecting durable AI systems or automation workflows that solve cross-functional challenges, resolve operational bottlenecks, and deliver measurable improvements to business efficiency.
- Exceptional communication skills with the ability to convey complex technical security strategies to non-technical business leaders and external stakeholders.
- Successfully designed and implemented repeatable AI-enabled workflows that address team bottlenecks and improve efficiency
VALUES-DRIVEN CULTURE
Virta’s company values drive our culture, so you’ll do well if:
- You put people first and take care of yourself, your peers, and our patients equally
- You have a strong sense of ownership and take initiative while empowering others to do the same
- You prioritize positive impact over busy work
- You have no ego and understand that everyone has something to bring to the table regardless of experience
- You appreciate transparency and promote trust and empowerment through open access of information
- You are evidence-based and prioritize data and science over seniority or dogma
- You take risks and rapidly iterate
Is this role not quite what you're looking for? Join our Talent Community and follow us on Linkedin to stay connected! Join our Talent Community https://jobs.ashbyhq.com/virtahealth/form/talent-community-form | follow us on Linkedin https://www.linkedin.com/company/virta-health
Virta has a location-based compensation structure. Starting pay will be based on a number of factors and commensurate with qualifications & experience. For this role, the compensation range is $161,500 - 209,000. Information about Virta’s benefits is on our Careers page at: https://www.virtahealth.com/careers https://www.virtahealth.com/careers.
As part of your duties at Virta, you may come in contact with sensitive patient information that is governed by HIPAA. Throughout your career at Virta, you will be expected to follow Virta's security and privacy procedures to ensure our patients' information remains strictly confidential. Security and privacy training will be provided.
As a remote-first company, our team is spread across various locations with office hubs in Denver and San Francisco.
Clinical roles: We currently do not hire in the following states: AK, HI, RI
Corporate roles: We currently do not hire in the following states: AK, AR, DE, HI, ME, MS, NM, OK, SD, VT, WI.
Virta uses Ashby as its applicant tracking system, which incorporates AI-powered tools (provided by OpenAI, AWS, and Google Gemini) in certain aspects of the recruiting process, including application review, candidate screening, and interview note taking; your data is not used to train AI models, and all final hiring decisions are made by Virta Health personnel. For more information, see Ashby's AI Terms at https://www.ashbyhq.com/resources/terms-ai-features
#LI-remote
Please mention you found this job on Remote Nomad Jobs. It helps us keep sharing more great jobs!
About this job
Job Type
Full Time
Department
ITRemote Type
Fully Remote
Location
Worldwide
Specializations
Salary Range
$161,500 - $209,000 USD / year
Posted On
August 5, 2026
Skills & Technologies
More digital nomad job openings
Here are other jobs you might want to apply for.
Unlock 2,574+ hidden remote nomad jobs
Go PremiumTrusted by 10,900+ monthly job seekers


