×
Register Here to Apply for Jobs or Post Jobs. X

Head of InfoSec and IT Operations

Job in Austin, Travis County, Texas, 78716, USA
Listing for: ATX Venture Partners
Full Time position
Listed on 2026-05-28
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security, Data Security
Salary/Wage Range or Industry Benchmark: 150000 - 200000 USD Yearly USD 150000.00 200000.00 YEAR
Job Description & How to Apply Below

About Autonomize AI

Autonomize AI is revolutionizing healthcare by combining data and context to streamline knowledge workflows, reduce administrative burdens, and improve patient outcomes. We’re a high-velocity, mission-driven startup that values full-stack ownership, clear alignment, and customer obsession.

Role Overview

Location:

Austin, TX
• 12+ years’ experience
• Full time
• Reports to Chief Technology Officer

Autonomize AI is hiring a Head of Info Sec and IT Operations, responsible for establishing, operating, and continuously strengthening the company’s information security, cybersecurity, privacy, and AI governance programs. This role ensures that security and compliance are embedded into the company’s product architecture, cloud infrastructure, software development lifecycle, and client operations.

The Head of Info Sec and IT Operations will lead the development of a scalable, audit-ready security framework aligned with HIPAA, SOC 2 Type II, HITRUST CSF, ISO 27001 (as applicable), and evolving AI governance expectations. This role partners closely with Engineering, Product, Customer Success, and external stakeholders to protect sensitive healthcare data while enabling innovation and growth. This is a strategic and operational leadership role requiring expertise in regulated healthcare environments and modern AI-enabled platforms.

Key Responsibilities Security Strategy and Governance
  • Develop and execute a comprehensive enterprise information security strategy aligned with business growth and regulatory obligations.
  • Establish and maintain security governance structures, policies, standards, and controls.
  • Report regularly to executive leadership on cybersecurity posture, risk, and maturity.
  • Conduct risk assessments.
Healthcare Regulatory and Compliance Alignment
  • Ensure compliance with HIPAA Privacy and Security Rule, HITECH, and applicable state privacy and security laws.
  • Oversee SOC 2 Type II, HITRUST, ISO 27001, and other certification efforts as appropriate.
  • Maintain audit readiness for client security assessments and regulatory inquiries.
  • Support Business Associate Agreement (BAA) obligations and downstream vendor oversight.
  • Partner with internal stakeholders to align security guardrails with healthcare regulatory workflows (e.g., prior authorization, appeals, interoperability requirements).
Cloud and Infrastructure Security
  • Oversee cloud security architecture (e.g., Azure, AWS), including encryption, key management, data segmentation, and secure configuration.
  • Ensure implementation of least privilege and strong access controls.
  • Oversee vulnerability management, endpoint security, logging, and monitoring capabilities.
  • Maintain incident response plans and conduct regular tabletop exercises.
Secure Software Development and AI Security
  • Embed security into the Secure Software Development Lifecycle (Secure SDLC).
  • Oversee application security testing (SAST, DAST, penetration testing).
  • Establish controls for model governance, data lineage, training data protections, and AI risk management.
  • Ensure safeguards around PHI handling in AI workflows, model training, testing, and prompt experimentation.
  • Partner with Product and Engineering to ensure privacy-by-design and security-by-design principles.
Data Protection and Privacy
  • Oversee data classification, retention, minimization, and secure disposal policies.
  • Ensure encryption at rest and in transit for sensitive data.
  • Establish controls for de-identification, re-identification risk mitigation, and controlled data access.
  • Support privacy impact assessments for new products and features.
Sub-Vendor Risk Management
  • Establish and oversee vendor security due diligence processes.
  • Ensure subcontractors meet contractual and regulatory security obligations.
  • Monitor ongoing vendor risk and compliance.
Incident Response and Business Continuity
  • Lead cybersecurity incident response efforts; coordinate cross‑functional response teams.
  • Ensure regulatory breach notification readiness and procedures.
  • Oversee disaster recovery and business continuity planning.
Security Culture and Awareness
  • Build a culture of privacy and security awareness across the company.
  • Develop employee training programs…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary