FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates extensive experience in cybersecurity, application security, and security operations, with a strong focus on leading security teams and integrating security practices into CI/CD pipelines. Proficient in managing vulnerabilities, incident response, and compliance with healthcare security frameworks such as HIPAA and SOC 2.
Highest-signal resume keywords
Cybersecurity LeadershipApplication SecurityVulnerability ManagementAWS SecurityIncident Response
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Application SecurityVulnerability ManagementThreat ModelingSecure Architecture ReviewsPenetration TestingCI/CD Security IntegrationInfrastructure as CodeCloud SecuritySecurity AutomationIncident Response
Soft Skills
Exceptional CommunicationStrong Judgment
Tools & Technologies
AWSKubernetesCI/CD PipelinesAI/ML PlatformsContainer Security
Certifications & Qualifications
HITRUST CertificationCISSPCISMCCSPGIAC
Industry Keywords
SOC 2HIPAASecurity ComplianceHealthcare SecurityMulti-Tenant Systems
Tech Stack
Tools & technologiesAWSCloudCyber SecurityDistributed SystemsKubernetesPythonTypeScript
About the role
Key responsibilities & impact- Define and execute a pragmatic security roadmap aligned with Plenful's product and business priorities
- Lead a small security team and coordinate security work across Engineering, Product, IT, Legal, and Compliance
- Personally own and execute critical security work while building scalable processes and automation
- Prioritize security risks based on exploitability, business impact, customer commitments, and regulatory requirements
- Establish and mature secure software development lifecycle practices
- Identify, reproduce, prioritize, and remediate application vulnerabilities with engineers
- Review application code and architecture and validate security-related code changes
- Lead threat modeling, secure architecture reviews, penetration testing, vulnerability management, and remediation tracking
- Integrate SAST, DAST, software composition analysis, secrets detection, and other controls into CI/CD pipelines
- Define security standards for AI-powered products and machine learning systems
- Build and operate monitoring, detection, logging, alerting, and incident response capabilities
- Lead incident investigations, containment, remediation, postmortems, and tabletop exercises
- Operate a risk-based vulnerability-management program and drive issues through closure
- Strengthen security across AWS infrastructure, IAM, secrets management, endpoint security, and network security
- Review Infrastructure as Code, Kubernetes, containers, and cloud architecture for security risks
- Lead security compliance strategy, including SOC 2, HIPAA, HITRUST, and future certifications
- Maintain security policies, standards, and controls and support vendor risk management
- Represent Security in enterprise customer reviews and technical security discussions
- Support enterprise deals, security questionnaires, and customer due diligence
- Communicate security posture, risks, incidents, investments, and priorities to executive leadership and the Board
- Build a security-first culture through education and practical guidance
Requirements
What you’ll need- 12+ years of progressive experience in cybersecurity, application security, security engineering, security operations, cloud security, or infrastructure security
- 2+ years leading security teams, programs, or major cross-functional security initiatives
- Deep, hands-on experience in application security and security operations
- Ability to investigate and remediate vulnerabilities in modern web applications, APIs, and distributed systems
- Ability to read application code, reason about security flaws, and work directly with engineers on effective fixes
- Experience with threat modeling, secure architecture reviews, penetration-test remediation, vulnerability management, and incident response
- Experience integrating and operating security tooling across CI/CD pipelines and developer workflows
- Strong technical background in modern cloud environments, preferably AWS, including IAM, logging, network security, secrets management, and Infrastructure as Code
- Experience securing enterprise SaaS platforms and multi-tenant systems
- Experience with healthcare security and compliance frameworks, including HIPAA and SOC 2
- Strong judgment in prioritizing security work in a fast-moving environment with limited resources
- Exceptional communication skills with engineers, executives, customers, auditors, Legal, Compliance, and Sales
- Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or equivalent practical experience
- Preferred: early security hire experience at a startup or high-growth technology company
- Preferred: Python, TypeScript, or similar modern application languages
- Preferred: HITRUST certification
- Preferred: AI/ML platforms, agentic systems, and modern data infrastructure security
- Preferred: Kubernetes, container security, Infrastructure as Code, and cloud-native architectures
- Preferred: security automation and internal security tooling
- Preferred: CISSP, CISM, CCSP, GIAC, or comparable certifications
Benefits
Comp & perks- Full medical, dental, and vision insurance for you and participation for your family
- 401(k) with company match: Plenful matches 50% of your first 3% contributed
- Equity for every full-time employee
- Unlimited PTO
- Daily lunch stipend of $100/week
- Wellness stipend of $100/month
- Commuter benefits of $100/month for San Francisco and New York-based employees
- Paid parental leave
- Flexible hybrid work environment
- Opportunities for growth and professional development
