Omada Health is on a mission to inspire and enable people everywhere to live free of chronic disease.
In this role, you will develop and execute information security programs designed to protect critical company assets. Additionally, you will participate in customer and third-party security and compliance audits. This hands-on technical position requires experience in security architecture, trends and threats, policy writing, business continuity planning, and risk management.
- Define information security standards, procedures, and guidelines in accordance with relevant regulations and industry best practices
- Define and assist in the implementation of physical, technological, procedural, policy and training safeguards
- Implement and manage security tools such as security information and event management (SIEM), static code analysis, data loss protection (DLP), and vulnerability assessment solutions
- Enhance Omada's security culture by organizing security awareness campaigns and security trainings
- Devise and execute means to test security implementation and adherence to security practices
- Perform periodic risk assessments and controls audits
- Conduct vendor assessments and audits
- Answer security questionnaires for Omada customers, detailing the ways in which Omada protects its health information
- Coordinate the response to security incidents
You will love this job if you have:
- 7+ years of security experience
- B.S. or M.S. in related field or equivalent experience
- Certified Information Systems Security Professional (CISSP),
- Broad knowledge of IT security
- Experience in developing Information Technology and Information Security policies and controls in a regulated environment; Health Information Trust Alliance (HITRUST) and SOC 2 experience a plus
- Technical knowledge in relevant technology areas: networking, servers, storage, virtualization, cloud, IaaS (AWS), Docker
- Proficient in network security design and architecture, endpoint protection, patch-management, vulnerability management, penetration testing, intrusion detection, risk management, mobile device management, wireless management, data loss prevention, forensics
- In-depth understanding and hands on experience with: firewalls, Identity and Access Management (IAM), Intrusion Detection Systems (IDS), Web Application Firewall (WAF), Security Information and Event Management (SIEM), Forensics, and 802.1X
- Experience with implementing and managing Business Continuity Program (BCP)
- Competitive salary
- Stock options (extended post termination option exercise window for Omadans who are with us 3 years or more)
- Flexible vacation
- Parental leave
- Health, dental, and vision
- Healthy snacks and meals
- Wellness events (e.g. running club)
- Community volunteering
- 401k retirement savings plan
About Omada Health: We’ve pioneered digital behavioral medicine: an innovative approach to tackling the growing epidemic of type 2 diabetes, heart disease, and obesity. Our online programs combine world-class science, technology, and design to inspire and enable people everywhere to live free of chronic disease. Named one of Fast Company’s “50 Most Innovative Companies in the World,” our team includes passionate and talented individuals. Our approach has been embraced by major employers across the country, including Costco and Iron Mountain, as well as leading health plans, such as Kaiser Permanente and Blue Cross Blue Shield of Louisiana.
We carefully hire the best talent we can find, which means actively seeking diversity of beliefs, backgrounds, education, and ways of thinking. We strive to build an inclusive culture where differences are celebrated and leveraged to inform better design and business decisions. Omada is proud to be an equal opportunity workplace and affirmative action employer. We are committed to equal opportunity regardless of race, color, religion, sex, gender identity, national origin, ancestry, citizenship, age, physical or mental disability, legally protected medical condition, family care status, military or veteran status, marital status, domestic partner status, sexual orientation, or any other basis protected by local, state, or federal laws.