Director, Security Operations & Infrastructure at Phreesia managing enterprise-wide security incident response. Leading operational excellence in security tooling and incident operations.
Responsibilities
Own enterprise-wide security incident response —ensure the team can detect, triage, contain, eradicate, and recover from incidents across cloud, on-prem, SaaS, and endpoint environments with speed and precision.
Maintain and continuously improve the incident response plan, playbooks, escalation procedures, and communication templates, ensuring they are tested, current, and aligned to NIST CSF 2.0.
Serve as incident commander or executive sponsor for high-severity incidents; make real-time decisions on containment and remediation under pressure.
Drive post-incident reviews that produce actionable findings, root-cause analysis, and measurable improvements—not just documentation.
Coordinate threat response across US and India teams, ensuring consistent coverage, quality, and process regardless of geography.
Partner with Legal & Privacy throughout the incident response lifecycle—ensuring timely notification assessments, evidence preservation, regulatory reporting obligations, and litigation hold requirements are met in coordination with response activities.
Own the security and IT tooling portfolio across the company: endpoint management (MDM, EDR), identity infrastructure, SIEM/SOAR, network security, vulnerability scanning, email security, cloud security posture management, and related platforms.
Build and maintain operational metrics and dashboards that provide the CISO and leadership with clear visibility into incident trends, MTTD/MTTR, tool health, SLA performance, and infrastructure posture.
One or more preferred: CISSP, CISM, GIAC (GCIH, GCIA, GCFA), CCSP, or similar.
Incident response or forensics certifications (GCIH, GCFE, GCFA, EnCE) are a strong differentiator.
10+ years in information security, with 5+ years in leadership roles managing security operations, incident response, or infrastructure/engineering teams.
Proven experience managing a team of senior engineers/architects responsible for running a broad portfolio of security and IT tools in a multi-cloud (AWS, Azure, GCP) and multi-OS (Windows, macOS, Linux) environment.
Experience in healthcare, health IT, payments, or other highly regulated data environments where PCI, HITRUST, SOX, and SOC 2 interact.
Remote First: 100% Remote work + home office expense reimbursements+ monthly reimbursement for cell phone, internet and wellness.
Top of market rewards: Competitive compensation
Take time when you need time: Flexible PTO + company holidays
Top class healthcare benefits: Variety of healthcare benefits for you and your family (and your pets!) starting day one
Care about your families: Generous top-up for parental leave benefits
Support personal development: Continuing education and professional certification reimbursement
Connecting in person: Various offsite events and activities for team to connect and meet in person, to support team building and engagement.
Giveback to community: Local in-person volunteer events, and give back programs to our communities.
Recognition and perks: We have a company wide recognition tool (Phireworks) to celebrate milestones, recognize achievements and strengthen your bond with your teams. You can accumulate points and redeem them for a wide catalogue of items!
Diversity and inclusive environment: At Phreesia, all employees are encouraged to bring their authentic self to work, feel supported and perform at their best. We have a variety of Employee Resources Groups (ERGs) which bring together individuals from a wide range of backgrounds, experiences and perspectives, and seek to foster a sense of shared community and empowerment for employees who share a common social identity, such as gender, race, ethnicity, and sexual orientation. Opportunity to join an Employee Resource Group.
Security Training & Operations Team Lead at OLG overseeing security operations and developing training programs for personnel across various locations. Requires strong leadership in managing safety and compliance protocols.
Lead SOC Team at Starling Group ensuring information security and response for global operations. Collaborate with top SecOps professionals managing incident response and continuous improvement.
Head of Fusion & Cybersecurity Operations at TD responsible for strategic direction and operational oversight of protect operations. Safeguarding data and systems from cyber threats and managing teams in cyber crime prevention.
Intermediate Security Operations Centre Analyst at Long View managing security incidents and working with IT systems. Engaging with teams across Canada in a dynamic IT environment.
SOC Analyst responsible for monitoring security events and assessing risks while collaborating with global customers. Working with Fortinet's SOC - as - a - Service team to improve security posture.
IAM Operations Lead responsible for daily administration, governance, and security of identity infrastructure, ensuring correct access and minimizing risks.
CSOC Analyst responsible for managing security incidents and threat investigation at Just Eat Takeaway. Working with an internal team to detect, investigate, and respond to significant threats.
Security Operations Engineer at Supabase providing front - line coverage for security alerts and customer security tickets. Supporting internal IT operations and improving security processes in a remote setup.
SecOps Engineer integrating security into development processes for Lido Protocol. Collaborating on security practices, incident management, and developer training.