Director, Application Security

Invitae • San Francisco, CA

Company

Invitae

Location

San Francisco, CA

Type

Full Time

Job Description

Invitae (NYSE: NVTA) is a leading medical genetics company trusted by millions of patients and their providers to deliver timely genetic information using digital technology. We aim to provide accurate and actionable answers to strengthen medical decision-making for individuals and their families. Invitae's genetics experts apply a rigorous approach to data and research, serving as the foundation of their mission to bring comprehensive genetic information into mainstream medicine to improve healthcare for billions of people.

Our Information Security Team is opening up the boundaries on shift left strategies to ensure all software development and IT operations at Invitae adhere to security best practices from inception to implementation. We are passionate about driving security strategy and improving security maturity for the organization. This position is a leadership role that requires an individual with a solid technical background, as well as an ability to partner and influence various technology and business operations teams to align on security priorities, strategies, and roadmaps.

Key Responsibilities:
  • Provide expert knowledge to the organization and stakeholders regarding the status, goals, functionality, and progression of Security Objectives
  • Understand and be able to relay Cloud, and Application Security information as an SME
  • Provide senior level leadership to a broad team of engineers, consultants, and staff across the organization.
  • Manage sophisticated deliverables across security and information technology teams to ensure we meet our timelines, goals, and requirements.
  • Develop staff to including training, mentorship, and functional alignment with our critical service delivery for Amazon Web Services and security tool implementation
  • Performing security design reviews to assess security implications for proposed new product features.
  • Identifying and assessing design and operational vulnerabilities in web application, network and system topologies
  • Advising on data security issues, compliance, and privacy requirements including, but not limited to HIPAA, HITRUST, SOC2, SOX,and ISO 27001
  • Taking a lead role in conducting security research on threats and remediation techniques/technology and making recommendations for implementation
  • Assisting in the development and automation of threat management, vulnerability management, and incident management processes
 Requirements:
  • Require a minimum of 15 years of related experience with a Bachelor’s degree; or 12 years and a Master’s degree. 6 years of leadership experience preferred.
  • Strong hands-on experience in Application, Network, System and Cloud Security Architecture design and review
  • Good consultative, communication, teammate and analytical skills are a must, as you will be regularly interacting between various teams.
  • Self-motivated to remain informed on current and emerging trends and security best practices
  • Ability to work within a fast-paced environment with short timelines
  • Understanding of AWS and Security reference architecture
  • Understanding of DevOps and DevSecOps including current industry leading services and systems
  • SME on full development lifecycle processes, requirements, and security considerations
  • Application security experience and understanding of code scanning, remediation processes, and capabilities
Technical Requirements:
  • Experience breaking down complex systems and applications to find relevant security risks
  • Detailed understanding of Microsoft Active Directory, Identity and Auth services, DNS, DHCP and email infrastructure design and security
  • Deep understanding of VPN, PKI, IPAM and MFA technologies required
  • Understanding of application and operating system hardening, TCP/IP & network fundamentals, intrusion detection systems, firewalls, VPNs, WAFs
  • Demonstrated expertise crafting and running security solutions - vulnerability scanners, forensics software, SIEM, HIDS/NIDS, IPS, malware analysis and protection, content filtering, logical access controls,IAM, data loss prevention, content filtering technologies, and application firewalls
  • Understanding of cloud services
  • DevOps Proficiencies
  • Terraform / TFE
  • Hashi Vault
  • EKS / Kubernetes
  • Container Methodology
  • Application Security
  • Understanding of GitOps / Gitlab / Github
  • CI/CD processes and methodologies

This salary range is an estimate, and the actual salary may vary based on a wide range of factors, including your skills, qualifications, experience and location. This position is eligible for benefits including but not limited to medical, dental, vision, life insurance, disability coverage, flexible paid time off, Spring Health, Carrot Fertility, participation in a 401k with company match, ESPP, and many other additional voluntary benefits. Invitae also offers generous paid leave programs so you can spend time with your new child, recover from your own illness or care for a sick family member.
California Pay Range
$181,200—$235,500 USD

Please apply even if you don’t meet all of the “What you bring” requirements noted.  It’s rare that someone checks every single item, it’s ok, we encourage you to apply anyways.  

Join us!

At Invitae, we value diversity and provide equal employment opportunities (EEO) to all employees and applicants without regard to race, color, religion, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. We will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of the San Francisco Fair Chance Ordinance.

We truly believe a diverse workplace is crucial to our company's success and to better serve our diverse patients. Your input is especially valuable. We’d greatly appreciate it if you can take a quick moment to make your selection(s) below. Submissions will be anonymous.

You can find a detailed explanation of our privacy practices here.

Apply Now

Date Posted

11/06/2023

Views

12

Back to Job Listings ❤️Add To Job List Company Info View Company Reviews
Positive
Subjectivity Score: 0.9

Similar Jobs

Software Engineer, Data Platform (Lead) - Benchling

Views in the last 30 days - 0

Benchling a leading biotechnology company is seeking a Senior Software Engineer to design and implement scalable multitenant services and APIs The rol...

View Details

Senior Product Manager, Enterprise - Atlassian

Views in the last 30 days - 0

Loom a video communication platform for asynchronous work is seeking a Senior Product Manager for its Enterprise team The role involves defining strat...

View Details

Relationship Executive, Middle Market Banking - Executive Director - JPMorganChase

Views in the last 30 days - 0

The job description is for a Relationship Executive role in the Middle Market Banking team The role involves building and retaining profitable relatio...

View Details

Internal Audit & SOX Senior - Chime

Views in the last 30 days - 0

Chime is seeking a Senior Internal Audit and SOX professional to implement a worldclass SOX program and contribute to the broader internal audit funct...

View Details

South LA, CA Territory Account Executive - Toast

Views in the last 30 days - 0

Toast is seeking a Territory Sales Account Executive to join their team in transforming the restaurant industry The role involves prospecting building...

View Details

Strategic Finance Associate - Chime

Views in the last 30 days - 0

Chime is seeking a Strategic Finance Associate to join their Finance team The role involves collaborating with the Strategic Finance team to shape bus...

View Details