Head of Corporate and Information Security
Listed on 2026-09-25
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Layer Health was founded in 2023 by leading machine learning researchers from MIT and Harvard Medical School. We are building an AI layer that can accurately and scalably synthesize information from medical records, with the mission to reduce friction everywhere in healthcare. Our LLM-powered platform is solving chart review once and for all, across use cases. For health systems, our first product dramatically accelerates clinical registry abstraction in areas ranging from surgery and cardiology, to oncology.
Our long term vision is for our AI layer to safely transform patient care and minimize unnecessary heartbreak. Layer Health's diverse founding team brings expertise across machine learning, UI/UX, large language models, and medicine.
Here's a collection of articles about our product, mission, recent funding round, etc.
We're scaling up the security function at Layer Health, and we're looking for the first Head of Corporate and Information Security to own it. This is a foundational hire: we handle PHI and sensitive customer data as a core part of our product, and as we scale with health systems and enterprise partners, evolving our security and compliance program are central to our ability to grow.
You'll report directly into leadership and have the mandate to continue to build the program the right way.
- Own Layer's security strategy and risk program. Develop a comprehensive understanding of our existing security posture across our product, cloud infrastructure, corporate systems, endpoints, vendors, and operational processes. Build on existing SOC2 Type 2 compliant security program and establish a risk-based roadmap, identify gaps, and help leadership make informed decisions about where to invest on our journey towards ISO 27001.
- Define and continuously improve our existing technical security posture. Partner closely with engineering and infrastructure teams to strengthen security across our GCP environments and software development lifecycle. Depending on the risks you identify, this may include areas such as cloud IAM and service accounts, network security, secrets and key management, vulnerability management, secure configuration, CI/CD and code security, logging and monitoring, or security architecture reviews.
- Protect sensitive data throughout its lifecycle. Define and improve upon the existing controls necessary to protect PHI, customer data, credentials, and other sensitive information wherever it is stored, processed, or transmitted. Examples might include data classification and DLP capabilities, access controls, egress protections, retention policies, secrets scanning, or controls within Google Workspace and endpoints.
- Continue to build out our detection, incident response, and security operations capabilities. Ensure we have the visibility and operational processes necessary to detect, investigate, contain, and learn from security events. This may include improving centralized security telemetry and SIEM capabilities, detection and alerting strategies, incident response processes, in addition to running exercises and coordinating investigations when incidents occur.
- Own corporate security. Refine our security posture across employee identity, endpoints, SaaS applications, and other corporate systems. Work closely with Operations and IT stakeholders on areas such as identity and access management, endpoint security, device management, employee lifecycle controls, and account management.
- Strengthen our human security posture. Build upon our existing comprehensive security awareness and training program, including regular phishing simulations and social engineering exercises, to empower employees as our first line of defense against human-based threats.
- Work with the Chief Privacy Officer and other members of the leadership team to identify key security risks and establish a strategic plan that balances robust risk management with other organizational priorities.
- 7+ years of experience in information security, security engineering, or related roles, with meaningful ownership across multiple areas of a security program rather than deep experience in only one specialty.
- Experience building or materially evolving a security program in a startup, growth-stage technology company, or similarly fast-moving environment. You are comfortable starting with incomplete systems and deciding what matters most.
- Strong technical depth in modern cloud environments. You should be comfortable reasoning…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).