Phreesia logo
Phreesia

Phreesia empowers patients to take an active role in their health and achieve better outcomes.

Director, Security Operations – Infrastructure

Security OperationsSecurity OperationsFull TimeRemoteLeadTeam 1,001-5,000Since 2005H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

4 days ago

Salary

$245K - $265K / year

Seniority

Lead

Bachelor Degree10 yrs expEnglishAWSAzureCloudGoogle Cloud PlatformLinuxMacOS

Job Description

Director, Security Operations – Infrastructure

Phreesia

• Own enterprise-wide security incident response —ensure the team can detect, triage, contain, eradicate, and recover from incidents across cloud, on-prem, SaaS, and endpoint environments with speed and precision. • Maintain and continuously improve the incident response plan, playbooks, escalation procedures, and communication templates, ensuring they are tested, current, and aligned to NIST CSF 2.0. • Serve as incident commander or executive sponsor for high-severity incidents; make real-time decisions on containment and remediation under pressure. • Coordinate threat response across US and India teams, ensuring consistent coverage, quality, and process regardless of geography. • Own the security and IT tooling portfolio across the company: endpoint management (MDM, EDR), identity infrastructure, SIEM/SOAR, network security, vulnerability scanning, email security, cloud security posture management, and related platforms. • Build and maintain operational metrics and dashboards that provide the CISO and leadership with clear visibility into incident trends, MTTD/MTTR, tool health, SLA performance, and infrastructure posture.

Job Requirements

  • Bachelor’s degree required; advanced degree preferred.
  • One or more preferred: CISSP, CISM, GIAC (GCIH, GCIA, GCFA), CCSP, or similar.
  • Incident response or forensics certifications (GCIH, GCFE, GCFA, EnCE) are a strong differentiator.
  • 10+ years in information security, with 5+ years in leadership roles managing security operations, incident response, or infrastructure/engineering teams.
  • Proven experience managing a team of senior engineers/architects responsible for running a broad portfolio of security and IT tools in a multi-cloud (AWS, Azure, GCP) and multi-OS (Windows, macOS, Linux) environment.
  • Significant experience in a product-driven, SaaS, or cloud-platform company, working closely with Product, Engineering, and Infrastructure organizations.
  • Strong technical fluency across: SIEM/SOAR platforms, EDR/XDR, network security, cloud security (AWS, Azure, GCP native controls), endpoint management (MDM, patching), identity infrastructure, and vulnerability management.

Benefits

  • 100% Remote work + home office expense reimbursements
  • Competitive compensation
  • Flexible PTO + 8 company holidays
  • Monthly reimbursement for cell phone + internet + wellness
  • 100% Paid 12-week parental leave to our U.S. employees, as well as a generous parental benefit to our employees in Canada
  • Variety of insurance coverage for people (and pets!)
  • Continuing education and professional certification reimbursement
  • Opportunity to join an Employee Resource Group.

Related Categories

Related Job Pages

More Security Operations Jobs

Millicom (Tigo) logo

Security Operations Engineer

Millicom (Tigo)

We build the digital highways that connect people, improve lives and develop the communities we proudly serve.

Full TimeRemoteTeam 10,001+Since 1992H1B No Sponsor

• Implementación, monitoreo, soporte y gestión de los servicios Profesionales y administrados remotos ofrecidos para los productos digitales • Evaluar y analizar las necesidades específicas de los clientes respecto a sus soluciones y gestión de redes • Implementa soluciones y realiza proceso rutina de monitoreo, notificación y reportes para productos que se ofrecen a los clientes a nivel de networking y ciberseguridad • Elaboración de pruebas de servicios implementados

Paraguay
LastPass logo

Director, Security Operations

LastPass

LastPass is a password and data management service headquartered in Boston, Massachusetts. Founded in 2008 by Joe Siegrist and Robert Billingslea, the company has continually worke

• Own and drive the strategy, roadmap, and maturation of LastPass's Security Operations function - translating the threat landscape into a multi-year program plan that scales with the business • Lead all response operations across the full incident lifecycle, from detection and triage through containment, eradication, recovery, and post-incident review • Build, develop, and retain a high-performing team of analysts and engineers - setting clear performance expectations, career development pathways, and a culture of operational excellence • Partner with the CISO, Legal, and Communications to manage high-severity incidents, coordinating executive response and fulfilling regulatory notification obligations • Define and own detection and response program metrics, SLAs, and reporting frameworks - providing the CISO and board with clear, evidence-based visibility into program maturity and risk posture • Champion the integration of AI-assisted triage, automation pipelines, and Detection-as-Code methodologies to reduce analyst toil and drive down mean-time-to-respond • Establish and maintain strategic relationships with external partners - including threat intelligence vendors, law enforcement, and industry information-sharing groups — to strengthen LastPass's situational awareness • Collaborate across Business Technology, Cloud Security, and Platform Engineering to ensure cohesive detection coverage and coordinated response capability across the full technology estate

Ireland
LastPass logo

Director, Security Operations

LastPass

LastPass is a password and data management service headquartered in Boston, Massachusetts. Founded in 2008 by Joe Siegrist and Robert Billingslea, the company has continually worke

• Own and drive the strategy, roadmap, and maturation of LastPass's Security Operations function - translating the threat landscape into a multi-year program plan that scales with the business • Lead all response operations across the full incident lifecycle, from detection and triage through containment, eradication, recovery, and post-incident review • Build, develop, and retain a high-performing team of analysts and engineers - setting clear performance expectations, career development pathways, and a culture of operational excellence • Partner with the CISO, Legal, and Communications to manage high-severity incidents, coordinating executive response and fulfilling regulatory notification obligations • Define and own detection and response program metrics, SLAs, and reporting frameworks - providing the CISO and board with clear, evidence-based visibility into program maturity and risk posture • Champion the integration of AI-assisted triage, automation pipelines, and Detection-as-Code methodologies to reduce analyst toil and drive down mean-time-to-respond • Establish and maintain strategic relationships with external partners - including threat intelligence vendors, law enforcement, and industry information-sharing groups — to strengthen LastPass's situational awareness • Collaborate across Business Technology, Cloud Security, and Platform Engineering to ensure cohesive detection coverage and coordinated response capability across the full technology estate

Portugal
Nexplay Consulting Inc. logo

IT Security Operations Engineer

Nexplay Consulting Inc.

Managing technology so business can RUN.

Full TimeRemoteTeam 11-50Since 2012H1B No Sponsor

• Assist in maintaining and enforcing PCI-DSS compliance across client environments • Help develop and document security templates, policies, SOPs, and audit artifacts • Support creation of standardized security forms, checklists, and processes • Coordinate with internal teams (L2/L3, Engineering) to ensure compliance alignment • Assist in preparing for audits and collecting required documentation/evidence • Monitor and track security-related tasks, requests, and remediation efforts • Contribute to continuous improvement of security protocols and procedures

Philippines