Director, Security Operations & Infrastructure
Other Jobs To Apply
No other job posts for this day.
<p style="text-align:left"><b>Job Description:</b></p><div><div><div><div><p><b><span>Position Summary</span></b><span> </span></p></div></div><div><div><p><span><span>Phreesia is looking for a<span> </span></span></span><b><span>Director, Security Operations & Infrastructure</span></b><span><span><span> </span>to serve as a senior member of the CISO’s leadership team and own the operational backbone of our security program. This role<span> </span></span><span>provides</span><span><span> </span></span></span><b><span>leadership, oversight, and hands-on guidance</span></b><span><span><span> </span>for two critical sub-teams:<span> </span></span></span><b><span>Threat Response</span></b><span><span><span> </span>and<span> </span></span></span><b><span>Security Infrastructure</span></b><span><span>.</span></span><span> </span></p><p></p></div><div><p><span><span>The<span> </span></span></span><b><span>Threat Response</span></b><span><span><span> </span>team<span> </span></span><span>is responsible for</span><span><span> </span>enterprise-wide security incident detection, triage, containment, response</span><span>, and forensics</span><span>. The<span> </span></span></span><b><span>Security Infrastructure</span></b><span><span><span> </span>team owns all security and IT tooling across the company—endpoint management, identity infrastructure, SIEM/SOAR, network security appliances, cloud security tooling, and the platforms that keep every employee and system running in a dynamic,<span> </span></span></span><b><span>multi-cloud (AWS, Azure, GCP) and multi-OS (Windows, macOS, Linux)</span></b><span><span><span> </span>environment.</span></span><span> </span></p><p></p></div><div><p><span><span>This role is ideal for a<span> </span></span></span><b><span>deeply technical security leader</span></b><span><span><span> </span>who has personally responded to and led security incidents, and who can also build and manage a team of senior engineers and architects capable of running a broad tool portfolio<span> </span></span></span><b><span>consistently and to high customer satisfaction</span></b><span><span>. The successful candidate has a technical background but is<span> </span></span></span><b><span>ruthlessly diligent about process, standards, execution, and being right</span></b><span><span>—someone who treats operational excellence as a discipline, not an afterthought.</span></span><span> </span></p><p></p></div><div><p><span><span>A key<span> </span></span><span>objective</span><span><span> </span>of this role is to drive<span> </span></span></span><b><span>standardization, reliability, and security maturity</span></b><span><span><span> </span>across infrastructure and incident operations while enabling Phreesia’s continued growth. The Director will function as a<span> </span></span></span><b><span>key contributor to our target-state enterprise and security architecture</span></b><span><span>, ensuring that security tooling and incident response capabilities are considered early in the design of new products, platforms, and integrations.</span></span><span> </span></p><p></p></div><div><p><span><span>This position will<span> </span></span><span>be responsible for</span><span><span> </span></span></span><b><span>collaborating with the GRC, IAM, Security Architecture, Product & Engineering, and Phreesia leadership</span></b><span><span><span> </span>teams on emerging challenges and operational<span> </span></span><span>priorities. The Director will stay current on<span> </span></span></span><b><span>evolving threats, technologies, and operational best practices</span></b><span><span><span> </span>and will ensure our security operations program<span> </span></span><span>anticipates</span><span><span> </span>rather than reacts to changes.</span></span><span> </span></p><p></p></div><div><p><span><span>Candidates must be comfortable<span> </span></span></span><b><span>leading through both direct management and influence in a highly matrixed environment</span></b><span><span>. You will directly manage threat response and infrastructure managers, while also driving outcomes through collaboration with engineering, product, and infrastructure teams across the company. This individual has<span> </span></span></span><b><span>hands-on experience building, running, and improving security operations and infrastructure programs</span></b><span><span><span> </span>in regulated data environments such as healthcare and payments, and is comfortable working across multiple compliance frameworks (PCI DSS, HITRUST, SOC 2, SOX ITGC, HIPAA/NIST) simultaneously.</span></span><span> </span></p><p></p></div><div><p><span><span>The ideal candidate<span> </span></span><span>demonstrates</span><span><span> </span></span></span><b><span>strong analytical, interpersonal communication skills, and operational management capabilities</span></b><span><span>: able to triage complex incidents under pressure, design practical tooling strategies, oversee implementation and hardening, and present clear status and risk updates to senior executives. They should be equally comfortable leading a live incident bridge, reviewing<span> </span></span><span>a firewall</span><span><span> </span>change request, and walking a customer’s security team through Phreesia’s control environment.</span></span><span> </span></p></div></div></div></div><div><p><span> </span></p></div><div><div><div><div><p><b><span>Job Responsibilities</span></b><span> </span></p></div></div><div><div><p><b><span>What<span> </span></span><span>you’ll</span><span><span> </span>do</span></b><span> </span></p></div><div><p><b><span>Threat Response Leadership</span></b><span> </span></p></div><div><ul><li><p><b><span>Own enterprise-wide security incident response</span></b><span><span>—ensure the team can detect, triage,<span> </span></span><span>contain</span><span>, eradicate, and recover from incidents across cloud, on-prem, SaaS, and endpoint environments with speed and precision.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Maintain and continuously improve the<span> </span></span></span><b><span>incident response plan, playbooks, escalation procedures, and communication templates</span></b><span><span>, ensuring they are tested, current, and aligned to NIST CSF 2.0.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Serve as<span> </span></span></span><b><span>incident</span><span><span> </span>commander or executive sponsor</span></b><span><span><span> </span>for high-severity incidents; make real-time decisions on containment and remediation under pressure.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Drive<span> </span></span></span><b><span>post-incident reviews</span></b><span><span><span> </span>that produce actionable findings, root-cause analysis, and measurable improvements—not just documentation.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Coordinate threat response across<span> </span></span></span><b><span>US and India teams</span></b><span><span>, ensuring consistent coverage, quality, and process regardless of geography.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Partner with<span> </span></span></span><b><span>Legal & Privacy</span></b><span><span><span> </span>throughout the incident response lifecycle—ensuring<span> </span></span><span>timely</span><span><span> </span>notification assessments, evidence preservation, regulatory reporting obligations, and litigation hold requirements are met in coordination with response activities.</span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>Think ahead of the curve</span></b><span><span>—continuously assess the threat landscape,<span> </span></span><span>identify</span><span><span> </span>emerging<span> </span></span><span>risks</span><span><span> </span>and attack vectors likely to<span> </span></span><span>impact</span><span><span> </span>Phreesia before they materialize, and develop<span> </span></span></span><b><span>contingency plans, tabletop exercises, and pre-positioned response strategies</span></b><span><span><span> </span>so the organization is prepared, not surprised.</span></span><span> </span></p></li></ul><p></p></div><div><p><b><span>Security Infrastructure Leadership</span></b><span> </span></p></div><div><ul><li><p><b><span>Own the security and IT tooling portfolio</span></b><span><span><span> </span>across the company: endpoint management (MDM, EDR), identity infrastructure, SIEM/SOAR, network security, vulnerability scanning, email security, cloud security posture management, and related platforms.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Ensure all tools are<span> </span></span><span>operated</span><span><span> </span></span></span><b><span>consistently, reliably, and to high customer satisfaction</span></b><span><span>—treat every employee and system as a customer of the infrastructure team.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Drive<span> </span></span></span><b><span>standardization and process discipline</span></b><span><span><span> </span>across tool administration: change management, patching, configuration baselines, and lifecycle management.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Partner with<span> </span></span></span><b><span>Security Architecture</span></b><span><span><span> </span>to translate architectural decisions into operational reality—ensuring new tools are deployed<span> </span></span><span>correctly</span><span><span> </span>and legacy tools are retired cleanly.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Manage<span> </span></span></span><b><span>vendor relationships and contracts</span></b><span><span><span> </span>for security<span> </span></span><span>tooling;</span><span><span> </span>own renewal timelines, license optimization, and performance accountability.</span></span><span> </span></p></li></ul><p></p></div><div><p><b><span>Operational & Strategic</span></b><span> </span></p></div><div><ul><li><p><span><span>Build and<span> </span></span><span>maintain</span><span><span> </span></span></span><b><span>operational metrics and dashboards</span></b><span><span><span> </span>that provide the CISO and leadership with clear visibility into incident trends, MTTD/MTTR, tool health, SLA performance, and infrastructure posture.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Establish and enforce<span> </span></span></span><b><span>operational standards</span></b><span><span><span> </span>across both sub-teams: runbooks, on-call rotations, escalation paths, change management, and documentation requirements.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Collaborate closely with<span> </span></span></span><b><span>GRC</span></b><span><span><span> </span>to ensure incident response and infrastructure operations satisfy audit and compliance requirements across PCI DSS, HITRUST, SOC 2, and SOX ITGC.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Act as a<span> </span></span></span><b><span>matrixed leader</span></b><span><span>, influencing teams you<span> </span></span><span>don’t</span><span><span> </span>directly manage while providing clear, actionable guidance to executives, developers, and staff.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Function as the<span> </span></span></span><b><span>CISO’s functional backup for incident response and security infrastructure matters</span></b><span><span>—represent the security program in customer meetings and partner with the<span> </span></span></span><b><span>Legal/Privacy team on litigation-related security matters</span></b><span><span>. (The Director, GRC & Data Protection serves as CISO backup for auditor and regulator<span> </span></span><span>engagements.)</span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>Recruit, develop, and<span> </span></span><span>retain</span></b><span><span><span> </span>high-performing talent; build a culture that values precision, accountability, continuous improvement, and teamwork.</span></span><span> </span></p></li></ul></div></div></div></div><div><p><span> </span></p><p><b><span>What<span> </span></span><span>You’ll</span><span><span> </span>Bring</span></b></p></div><div><div><div><div><p><b><span>Education</span></b><span> </span></p></div></div><div><div><p><span><span>Bachelor’s degree<span> </span></span><span>required</span><span>; advanced degree preferred.</span></span><span> </span></p><p></p></div></div><div><div><p><b><span>Certifications</span></b><span> </span></p></div></div><div><div><p><span><span>One or more preferred: CISSP, CISM, GIAC (GCIH, GCIA, GCFA), CCSP, or similar.</span></span><span> </span></p></div><div><p><span><span>Incident response or forensics certifications (GCIH, GCFE, GCFA,<span> </span></span><span>EnCE</span><span>) are a strong differentiator.</span></span><span> </span></p><p></p></div></div><div><div><p><b><span>Experience, Knowledge & Skills</span></b><span> </span></p></div></div><div><div><ul><li><p><b><span>10+ years</span></b><span><span><span> </span>in information security, with<span> </span></span></span><b><span>5+ years in leadership roles</span></b><span><span><span> </span>managing security operations, incident response, or <span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">infrastructure/engineering</span> teams.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Prior role as a<span> </span></span></span><b><span>Director of Security Operations, Head of Incident Response, or Security Infrastructure lead</span></b><span><span><span> </span>for an organization of meaningful scale and complexity.</span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>Hands-on incident response experience</span></b><span><span>—you have personally led incident bridges, performed triage, coordinated containment, and driven remediation for significant security events. This is not a role for someone who has only managed from a distance.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Proven experience<span> </span></span></span><b><span>managing a team of senior engineers/architects</span></b><span><span><span> </span>responsible for running a broad portfolio of security and IT tools in a<span> </span></span></span><b><span>multi-cloud (AWS, Azure, GCP) and multi-OS (Windows, macOS, Linux)</span></b><span><span><span> </span>environment.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Experience in<span> </span></span></span><b><span>healthcare, health IT, payments, or other highly regulated data environments</span></b><span><span><span> </span>where PCI, HITRUST, SOX, and SOC 2 interact.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Significant experience</span><span><span> </span>in a<span> </span></span></span><b><span>product-driven, SaaS, or cloud-platform company</span></b><span><span>, working closely with Product, Engineering, and Infrastructure organizations.</span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>Ruthlessly process-oriented</span></b><span><span>—</span><span>demonstrated</span><span><span> </span></span><span>track record</span><span><span> </span>of building and enforcing standards, runbooks, change management, and operational discipline across distributed teams.</span></span><span> </span></p></li></ul></div><div><ul><li><p><b><span>Forward-looking and proactive</span></b><span><span>—</span><span>demonstrated</span><span><span> </span>ability to<span> </span></span><span>anticipate</span><span><span> </span>emerging threats, technology shifts, and operational risks before they<span> </span></span><span>impact</span><span><span> </span>the business, and to develop contingency plans and preparedness exercises accordingly.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Strong technical fluency across: SIEM/SOAR platforms, EDR/XDR, network security, cloud security (AWS, Azure, GCP native controls),<span> </span></span><span>endpoint management (MDM, patching), identity infrastructure, and vulnerability management.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Exceptional written and verbal communication skills, including direct experience presenting to<span> </span></span></span><b><span>senior executives, boards, customers, and auditors</span></b><span><span><span> </span>on security posture, incident status, and operational metrics.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Proven effectiveness in a<span> </span></span></span><b><span>highly matrixed organization</span></b><span><span>, influencing cross-functional stakeholders and resolving conflicting priorities.</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Experience managing<span> </span></span></span><b><span>geographically distributed teams</span></b><span><span><span> </span>(US, Canada, India) with varying time zones and cultural contexts.</span></span><span> </span></p></li></ul><p></p></div></div><div><div><p><b><span>Technology</span></b><span> </span></p></div></div><div><div><p><span><span>Deep familiarity with security and infrastructure tooling, including but not limited to:</span></span><span> </span></p></div><div><ul><li><p><span><span>AI/LLM Platforms (OpenAI, Anthropic, Google, LLM Gateways)</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>SIEM/SOAR (e.g., Splunk, Sentinel, Palo Alto XSIAM, Swimlane)</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>EDR/XDR (e.g., CrowdStrike,<span> </span></span><span>SentinelOne</span><span>, Microsoft Defender)</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Cloud security (AWS Security Hub, Azure Defender, GCP SCC, CSPM tools)</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Network security (firewalls, IDS/IPS, DNS security, web gateways)</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Endpoint management (</span><span>Jamf</span><span>, Intune, patch management</span><span><span> </span>solutions</span><span>)</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Identity infrastructure (Okta, Azure AD/Entra ID, PAM solutions)</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Vulnerability management (Qualys, Tenable, Rapid7)</span></span><span> </span></p></li></ul></div><div><ul><li><p><span><span>Email security and DLP platforms</span><span><span> </span>(Mimecast, Proofpoint, Cyera)</span></span><span> </span></p></li></ul><p></p></div></div><div><div><p>Total cash compensation for U.S.-based employees ranges from $245,000–$265,000, inclusive of base salary and variable incentive, and is dependent on qualifications. In addition, Phreesia offers a highly competitive and comprehensive Total Rewards package.</p><p></p><p><b><span>Other</span></b><span> </span></p></div></div><div><div><p><span><span>This position requires occasional travel for team meetings, incident response coordination, customer<span> </span></span><span>engagements</span><span>, and audit support.</span></span><span> </span></p></div><div><p><span><span>Must be able to<span> </span></span><span>participate</span><span><span> </span>in an on-call rotation for critical security incidents.</span></span><span> </span></p></div></div></div></div><p style="text-align:inherit"></p><p style="text-align:inherit"></p><p><b>Who We Are:</b></p><p></p><p>At Phreesia, we’re looking for smart and passionate people to help drive our mission of creating a better, more engaging healthcare experience. We’re committed to helping healthcare organizations succeed in an ever-evolving landscape by transforming the way healthcare is delivered. Our SaaS platform digitizes appointment check-in and offers tools to engage patients, improve efficiency, optimize staffing, and enhance clinical care.</p><p></p><p>Phreesia cares about our employees by providing a diverse and dynamic work environment. We’re a five-time winner of Modern Healthcare Magazine’s Best Places to Work in Healthcare award and we’ve been recognized on the Bloomberg Gender Equality Index. We are dedicated to continuously improving our employee experience by launching new programs and initiatives. If you thrive in a culture of recognition, value inclusivity, professional development, and growth opportunities, Phreesia could be a great fit!</p><p></p><p><b>Top-rated Employee Benefits:</b></p><ul><li><p>100% Remote work + home office expense reimbursements</p></li><li><p>Competitive compensation</p></li><li><p>Flexible PTO + 8 company holidays</p></li><li><p>Monthly reimbursement for cell phone + internet + wellness</p></li><li><p>100% Paid 12-week parental leave to our U.S. employees, as well as a generous parental benefit to our employees in Canada</p></li><li><p>Variety of insurance coverage for people (and pets!)</p></li><li><p>Continuing education and professional certification reimbursement</p></li><li><p>Opportunity to join an Employee Resource Group. Learn more here: <a href="https://www.phreesia.com/dei/" target="_blank" rel="noopener noreferrer"><span style="overflow-wrap: break-word; display: inline; text-decoration: inherit; hyphens: auto;">https://www.phreesia.com/workforce/</span></a></p></li></ul><p></p><p><i>We strive to provide a diverse and inclusive environment and are an equal opportunity employer.</i></p>