Director, Chief Information Security Officer (CISO)
CerebralAbout the role
Our Company:
At Cerebral, we're on a mission to democratize access to high-quality mental health care for all. We believe that everyone everywhere deserves to get the care they need, and are striving to make care convenient and accessible, while tackling the stigmas that surround mental illness.
Since launching in January of 2020, Cerebral has scaled to provide mental health services to more than 700,000 people in all fifty US states. With support from investors like SoftBank, Silver Lake, Access Industries, Bill Ackman, WestCap, and others, and impactful leaders like you, we’ll continue to democratize mental health care and double down on clinical quality and deliver exceptional client outcomes for years to come. With a heavy focus on clinical quality and safety in all that we do, we’ve accomplished excellent outcomes for hundreds of thousands of clients:
- 82% of clients report an improvement in their anxiety symptoms after using Cerebral.
- 75% of clients who report improvement in their depression see improvement within 60 days.
- 50% of clients who initially report suicidal ideation no longer harbor suicidal thoughts after treatment with Cerebral.
This is just the beginning for Cerebral, and we won’t stop building, growing, and iterating until everyone, everywhere can access high-quality, evidence-based mental health care without high costs and/or long wait times. We’re looking for mission-driven leaders who share these values, and we need your help as we transform access to high-quality mental health care in the United States and beyond.
The Role:
As a Director, CISO you’ll bring expert knowledge in IT and application security. You’ll lead and develop a lean, high-performing team in setting up or improving incident management procedures and protocols across the organization. You’re an established player-coach who can write infrastructure code to secure our systems and manage the security and IT team. You have previous CISO experience and have built and run a security program effectively.
Who you are:
- Demonstrate strong technical architecture and engineering skills along with the ability to switch between technology paradigms
- Adept at prioritizing value and shipping complex products requiring coordination across multiple teams
- Experience securing AWS and Kubernetes based applications
- Experience with threat modeling, open-source, and commercial security tools
- Ability to write code to solve security issues; writing security tools, or automation/management of security-sensitive environments
- Deep knowledge of AWS; how to configure least privileged access
- Use of tools such as Terraform, Istio for managing security in public cloud environments
- Use of vulnerability management tools (Tenable, CrowdStrike, Prisma, etc.)
- Hands-on experience with SIEM, IDS, IPS and WAF solutions
- Incident and IT security management
- Familiarity with security and compliance frameworks such as HIPAA, HITRUST, SOC2, ISO 27001/27013, NIST 800-53
- General understanding of common web application deployment models and components
- Posses discretion and must be capable of conducting confidential internal investigations using Google Workspace Admin, Google Vault, and similar tools
How your skills and passion will come to life at Cerebral:
- Partner with Infrastructure, Engineering, Compliance, and Operations to ensure Cerebral’s end-to-end technology footprint is secure, utilizing preventative measures by matrix managing a security program for the entire organization
- Hands-on implementation of security controls including preventative threat detection and employee training meetings
- Develop, implement, and review security guidelines and configurations for an AWS based HIPAA compliant SaaS environment and a remote IT workforce
- Institute proactive security monitoring and alerting capabilities utilizing a combination of custom cools and strategic partners
- Build security automation into infrastructure deployment and CI/CD pipelines
- Perform manual and automated compliance, vulnerability, and penetration testing
- Demonstrate and promote security best practices
- Constantly improve policies
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s