Head of Security

About the Role
Security and trust are fundamental to Medplum. We operate critical healthcare infrastructure, store and process sensitive health information, and support healthcare organizations ranging from startups to large enterprises.
As Medplum's Head of Security, you will own the company's security program end-to-end. This is a broad, hands-on leadership role spanning security engineering, incident response, compliance, customer security, and risk management.
One day you might be reviewing the authorization model for a new platform feature, the next leading an incident investigation, responding to a customer security assessment, working with an auditor on HITRUST controls, or helping an enterprise customer understand Medplum's security architecture.
We are looking for someone who combines deep technical judgment with the communication skills to represent Medplum confidently with customers, auditors, partners, and executive stakeholders.
This is not a governance-only role. Medplum is a small engineering-driven company, and our Head of Security should be comfortable going deep into systems, reading code and logs, investigating incidents, and working directly with engineers to solve difficult security problems.
What You Will Do
Own Medplum's Security Program
Take responsibility for Medplum's security strategy, policies, controls, risk management, and security roadmap. Identify the most important risks facing the company and work with engineering and company leadership to address them pragmatically.
Lead Security Engineering
Work directly with Medplum's engineering team on application security, cloud security, authentication and authorization, tenant isolation, vulnerability management, dependency security, secrets management, logging, and other security-sensitive areas of the platform.
Review architecture and code when appropriate, help investigate security bugs, and translate security requirements into concrete engineering work.
Lead Incident Response
Own Medplum's security incident response process. Lead investigations, coordinate technical response, preserve and analyze relevant evidence, communicate clearly with customers and company leadership, and continuously improve our ability to detect and respond to security events.
Own Security and Compliance Programs
Lead Medplum's security-related compliance programs, including SOC 2, HIPAA, HITRUST, and other healthcare security and certification requirements.
Work with auditors and assessors, maintain policies and evidence, coordinate remediation work, and help ensure that compliance activities produce meaningful security improvements rather than becoming checkbox exercises.
Work Directly With Customers
Represent Medplum in customer security reviews, enterprise diligence processes, architecture discussions, and security questionnaires.
Build trust with security engineers, CISOs, compliance teams, technical executives, and other customer stakeholders. Explain complex security topics clearly and accurately, and help customers understand how Medplum approaches security and risk.
Build a Security Culture
Help make security part of how Medplum engineers and operates the product rather than a separate review step.
Improve internal security tooling, documentation, processes, training, and engineering practices. Over time, help define and build the security team as Medplum grows.
About You
- You have deep technical experience in software, infrastructure, cloud, or application security.
- You have experience owning or leading security for production systems that handle sensitive or regulated data.
- You can investigate a complex security issue yourself rather than relying entirely on another engineering team.
- You understand modern application security concepts including authentication, authorization, OAuth, web security, APIs, networking, cloud infrastructure, databases, and secure software development.
- You have experience leading or materially participating in security incident response.
- You communicate clearly with engineers, customers, executives, auditors, and other external stakeholders.
- You are comfortable making risk-based decisions in situations where there is not a perfect or zero-risk solution.
- You are pragmatic. You look for ways to make ambitious products secure rather than defaulting to saying no.
- You enjoy operating in a fast-moving startup environment where roles are broad and important problems do not always arrive neatly packaged.
- You have 8+ years of experience in security engineering, software engineering, infrastructure security, security leadership, or related roles.
- You're based in the SF Bay Area and available for twice-weekly in-person collaboration.
Bonus
- Experience securing healthcare technology or other highly regulated software.
- Experience with HIPAA, SOC 2, HITRUST, or similar security and compliance frameworks.
- Experience with AWS, Kubernetes, PostgreSQL, or large-scale SaaS infrastructure.
- Experience securing multi-tenant SaaS platforms or developer infrastructure.
- Experience with open source software and open source security.
- Experience supporting enterprise security reviews and customer diligence.
- Experience building or scaling a security function at an early-stage or growth-stage company.
About Medplum
Medplum is redefining healthcare with our open source, API-first electronic health record (EHR) platform, trusted by leading digital health and life sciences companies. Our mission is to catalyze change in the healthcare industry by improving the access, privacy, and utility of health data. At Medplum, we have a unique opportunity to impact the lives of patients, speed medical research, and contribute to the open source ecosystem.
Benefits
- Competitive compensation package with equity
- Flexible time off
- Inclusive healthcare package
- The chance to shape the future of healthcare tech – leave your mark on this vital industry
Join us in our mission to revolutionize healthcare. If you're excited about owning security for a rapidly growing healthcare infrastructure platform and want a role that combines deep technical work with company-wide leadership, we'd love to hear from you. Reach out to careers@medplum.com.