bluedoor data·Job Postings API·bluedoor.sh ↗

HomeCompaniesNayyaDirector of Security & IT

Director of Security & IT

Nayya · New York, NY (Hybrid) · Hybrid · Active · $226,000–$275,000 / year · Greenhouse

Job facts

FieldValue
CompanyNayya
TitleDirector of Security & IT
Normalized title-
Department / teamEngineering
LocationNew York, NY, United States
Work modelHybrid / Hybrid
Employment type-
Salary$226,000–$275,000 / year
Statusactive
ATS providerGreenhouse
Posted / first seen2026-03-16 / 2026-05-29
Changed / last seen2026-05-29 / 2026-06-18

Related slices

PageWhat it containsOpen
Company jobsActive postings from Nayya.Open
Company breakdownsRole, location, ATS, and work model facets for this company.Open
ATS provider jobsActive postings observed through Greenhouse.Open
Provider filtered searchThe same provider as a filtered job collection.Open
City jobsActive postings in New York.Open
Department jobsActive postings in Engineering.Open
Work model jobsActive Hybrid postings.Open
Lifecycle eventsOpen, update, close, and reopen events for this posting.Open
Original postingCanonical source or apply URL captured from the ATS.Open

Linked records

CompanyNayya
Source00b3f4b1-9837-4e79-888d-d3d2606efabe
ATS providerGreenhouse

Description

About Nayya Founded in 2019, Nayya is on a mission to connect people’s most important information, so they can thrive in their health and wealth. Powered by AI and advanced analytics, Nayya’s platform transforms complex benefits experiences into intuitive, seamless, and ongoing interactions—meeting people's real world needs. As a trusted platform and partner to leading employers, benefits solutions, and HR tech providers, Nayya unlocks long-term value through helping employees live more resilient lives. Backed by strategic investors like ICONIQ, Felicis Ventures, SemperVirens, Workday Ventures, MetLife Nextgen Ventures, and ADP Ventures, Nayya is ushering in the future of health and wealth for all. Role Summary: We are seeking a Director of Security & IT to lead Nayya's security strategy, compliance programs, and IT operations. This role will serve as the single point of accountability for protecting sensitive health and financial data, maintaining regulatory compliance, and ensuring the reliability and security of internal technology systems. Nayya is a benefits intelligence platform serving approximately 5 million employees. Our AI-powered platform delivers personalized guidance grounded in real plan data and claims history. The security and compliance requirements of this environment are significant: we handle Protected Health Information (PHI) at scale and operate under HIPAA, SOC 2, and other regulatory frameworks. This role reports to the Chief Product & AI Officer. The Director of Security & IT will partner closely with Engineering on infrastructure security while maintaining independent ownership of the security program, compliance posture, and IT operations. Key Responsibilities Security Program Leadership Lead the design, implementation, and continuous improvement of a comprehensive security program spanning application security, infrastructure security, data protection, and incident response. Implement and manage vulnerability assessments, penetration testing, and security audits to identify and mitigate risks across IT infrastructure and systems. Develop and maintain security policies, procedures, and controls aligned to SOC 2 Type II and HIPAA Security Rule requirements. Coordinate response to security incidents, including root cause analysis, containment, remediation, and legal reporting requirements. Own identity and access management (IAM) strategy, ensuring least-privilege access controls across production systems, cloud environments, and internal tools. Implement encryption, access control, audit logging, and other technical safeguards to meet HIPAA security requirements for data at rest, in transit, and during processing. Compliance & Risk Management Own SOC 2 Type II compliance initiatives, including audit preparation, controls documentation, evidence collection, and remediation of findings. Ensure compliance with HIPAA Privacy and Security Rules across Nayya's handling of PHI, including technical safeguards and organizational policies. Develop and maintain a risk management framework that identifies, evaluates, and prioritizes security and compliance risks, ensuring alignment with applicable regulations. Conduct regular risk assessments and vulnerability scans to proactively address potential compliance gaps. Prepare for and manage regulatory audits, customer security assessments, and external inspections related to data security and privacy. Stay current on emerging trends in healthcare data privacy regulations (HIPAA, HITECH, state-level requirements) and assess their impact on company policies and procedures. IT Operations & Help Desk Services Oversee day-to-day IT operations, ensuring all systems, networks, and applications function effectively and securely with minimal downtime. Lead the internal IT help desk function, ensuring timely resolution of technical issues with clear escalation protocols and service level agreements (SLAs). Monitor help desk performance metrics and implement improvements based on organizational needs. Manage IT asset lifecycle, including procurement, tracking, maintenance, and compliance with company policies. Ensure effective onboarding and offboarding processes for IT systems, with a focus on security awareness and HIPAA compliance training. Vendor & Third-Party Risk Management Evaluate and manage relationships with cloud providers, vendors, and third-party services to ensure they meet HIPAA and SOC 2 security and privacy requirements. Conduct due diligence and security assessments of third-party vendors, ensuring alignment with Nayya's data protection and compliance standards. Negotiate and manage contracts and SLAs to ensure third-party vendors meet security, compliance, and privacy expectations. Cross-Functional Collaboration Partner closely with the VP of Engineering on cloud security, infrastructure hardening, disaster recovery, and production access controls. Work with Legal, Finance, and People teams to ensure security and data privacy strategies align with business operations and legal obligations. Serve as the primary security and compliance liaison for enterprise customers, partners, and prospects during due diligence and procurement processes. Act as a strategic advisor to senior leadership on security investments, balancing risk mitigation against operational constraints and business priorities. Provide regular reports to the executive team on the status of security initiatives, compliance posture, and audit results. Team Leadership & Development Lead, mentor, and develop a team of security, IT, and compliance professionals. Foster a culture of continuous improvement to stay ahead of cybersecurity threats and regulatory changes. Provide training to team members and the broader organization on security best practices, with emphasis on HIPAA compliance and PHI protection. Qualifications Required 10+ years of experience in security, IT infrastructure, and compliance, with at least 3 years owning a security function in a leadership capacity. Experience at a scaling software or AI company (50-1,000 employees) with exposure to the tradeoffs of building security programs with constrained resources. Proven depth in HIPAA compliance, healthcare data protection, and SOC 2 Type II audits. Strong understanding of cloud security architecture (AWS), network security, container security, and production access patterns. Experience building or significantly maturing security and compliance programs, not solely operating existing ones. Demonstrated ability to operate cross-functionally with Engineering, Legal, Finance, and People teams, turning ambiguity into structured execution. Strong program execution skills with a track record of driving multi-quarter initiatives across security, compliance, disaster recovery, access management, and vendor risk. Sound judgment in high-trust environments involving sensitive systems, company risk, customer data, and internal operations. Strong people leadership with experience managing technical teams, setting expectations, and creating accountability. Ability and willingness to go deep in a hands-on way where needed and delegate to the team where appropriate. Experience in healthcare, benefits, fintech, or another regulated environment where data sensitivity and compliance requirements are material. Preferred Relevant certifications: CISSP, CISM, CCSP, AWS Certified Solutions Architect, or similar. SOC 2 and HIPAA-specific credentials are highly desirable. Hands-on technical capability to engage in architecture discussions, evaluate operational tradeoffs, and assess technical risk directly when needed. A bias toward simplicity and prioritization across a broad surface area, focusing effort on what materially reduces risk and improves reliability. The salary range for New York based candidates for this role is $226,000- $275,000. We use a location factor to adjust this range for candidates that are located outside of geographic region of our New York office. Placement within the salary band is determined based on experience. #LI-KD1 Nayya is proud to be an Equal Employment Opportunity employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics

Full job record

Job ID5aa16d9841480baa553cff109ecf03d78487b8f7
Org IDa3f4ffa6-afa4-4b27-8cd3-54bfd06cb150
Source ID00b3f4b1-9837-4e79-888d-d3d2606efabe
Board ID00b3f4b1-9837-4e79-888d-d3d2606efabe
Providergreenhouse
Provider Job Key5829557004
TitleDirector of Security & IT
Normalized Title
Statusactive
Activeyes
Location TextNew York, NY (Hybrid)
DepartmentEngineering
Team
Employment Type
Workplace Typehybrid
Remote Policyhybrid
CountryUnited States
RegionNY
CityNew York
Salary Rawsalary range for New York based candidates for this role is $226,000- $275,000. We use a location factor to adjust this range for candidates that are located o
Salary Min226,000
Salary Max275,000
Salary CurrencyUSD
Salary Periodyear
Source URLhttps://nayya.com/career?gh_jid=5829557004
Apply URLhttps://nayya.com/career?gh_jid=5829557004
First Seen At2026-05-29 22:55:28Z
Last Seen At2026-06-18 07:31:42Z
Last Checked At2026-06-18 07:31:42Z
Last Changed At2026-05-29 22:55:28Z
Inactive At
Source Posted At2026-03-16 18:41:46Z
Source Updated At2026-05-29 21:27:50Z
Raw Payload Uris3://job-postings-prod-raw-590183727216/raw/provider=greenhouse/board=nayya/date=2026-06-18/2026-06-18T07-31-42-910Z-08d6520fee64e05a7c701dee80b4033bad73b4af661dbec4579a618c56098870.json
Event Fields
{
  "content_hash": "729b5e4de5de3fe4464bcb3dc7fef0d5292bcb394fdad79a096b4929a9b4d1a2",
  "source_hash": "b96c946ad5447e69c260cf306dd886feb78955a8b2b79b1bfd7f6f20cd228749",
  "last_changed_at": "2026-05-29T22:55:28.709Z",
  "active_status": "active"
}
Parsed Structured
{
  "language": "en",
  "location": {
    "raw": "New York, NY (Hybrid)",
    "city": "New York",
    "region": "NY",
    "country": "United States",
    "is_remote": false,
    "confidence": 0.9
  },
  "salary_max": 275000,
  "salary_min": 226000,
  "inferred_at": "2026-06-18T07:31:42.988Z",
  "launch_scope": {
    "reason": "english_us_canada",
    "included": true,
    "language": "en",
    "location": {
      "raw": "New York, NY (Hybrid)",
      "city": "New York",
      "region": "NY",
      "country": "United States",
      "is_remote": false,
      "confidence": 0.9
    },
    "countries": [
      "United States"
    ]
  },
  "remote_policy": "hybrid",
  "salary_period": "year",
  "workplace_type": "hybrid",
  "salary_currency": "USD"
}
Extensions
{}
Native Structured
{
  "title": "Director of Security & IT",
  "offices": [
    {
      "id": 4003787004,
      "name": "New York",
      "location": "New York, New York, United States",
      "child_ids": [],
      "parent_id": null
    }
  ],
  "language": "en",
  "location": {
    "name": "New York, NY (Hybrid)"
  },
  "metadata": [],
  "updated_at": "2026-05-29T17:27:50-04:00",
  "departments": [
    {
      "id": 4006834004,
      "name": "Engineering",
      "child_ids": [],
      "parent_id": null
    }
  ],
  "company_name": "Nayya",
  "requisition_id": 5064597004,
  "first_published": "2026-03-16T14:41:46-04:00",
  "application_deadline": null
}
Get this page with API

Rendered from the bluedoor Job Postings API. Reproduce it:

GET https://api.bluedoor.sh/job-postings/v1/jobs/5aa16d9841480baa553cff109ecf03d78487b8f7?include=descriptionJSON
GET https://api.bluedoor.sh/job-postings/v1/orgs/a3f4ffa6-afa4-4b27-8cd3-54bfd06cb150JSON
GET https://api.bluedoor.sh/job-postings/v1/sources/00b3f4b1-9837-4e79-888d-d3d2606efabeJSON
GET https://api.bluedoor.sh/job-postings/v1/jobs/5aa16d9841480baa553cff109ecf03d78487b8f7/eventsJSON