Director, Application Security

Invitae • Remote

Company

Invitae

Location

Remote

Type

Full Time

Job Description

Invitae (NYSE: NVTA) is a leading medical genetics company trusted by millions of patients and their providers to deliver timely genetic information using digital technology. We aim to provide accurate and actionable answers to strengthen medical decision-making for individuals and their families. Invitae's genetics experts apply a rigorous approach to data and research, serving as the foundation of their mission to bring comprehensive genetic information into mainstream medicine to improve healthcare for billions of people.


Our Information Security Team is opening up the boundaries on shift left strategies to ensure all software development and IT operations at Invitae adhere to security best practices from inception to implementation. We are passionate about driving security strategy and improving security maturity for the organization. This position is a leadership role that requires an individual with a solid technical background, as well as an ability to partner and influence various technology and business operations teams to align on security priorities, strategies, and roadmaps.

Key Responsibilities:
  • Provide expert knowledge to the organization and stakeholders regarding the status, goals, functionality, and progression of Security Objectives
  • Understand and be able to relay Cloud, and Application Security information as an SME
  • Provide senior level leadership to a broad team of engineers, consultants, and staff across the organization.
  • Manage sophisticated deliverables across security and information technology teams to ensure we meet our timelines, goals, and requirements.
  • Develop staff to including training, mentorship, and functional alignment with our critical service delivery for Amazon Web Services and security tool implementation
  • Performing security design reviews to assess security implications for proposed new product features.
  • Identifying and assessing design and operational vulnerabilities in web application, network and system topologies
  • Advising on data security issues, compliance, and privacy requirements including, but not limited to HIPAA, HITRUST, SOC2, SOX,and ISO 27001
  • Taking a lead role in conducting security research on threats and remediation techniques/technology and making recommendations for implementation
  • Assisting in the development and automation of threat management, vulnerability management, and incident management processes
 Requirements
  • Require a minimum of 15 years of related experience with a Bachelor’s degree; or 12 years and a Master’s degree. 6 years of leadership experience preferred.
  • Strong hands-on experience in Application, Network, System and Cloud Security Architecture design and review
  • Good consultative, communication, teammate and analytical skills are a must, as you will be regularly interacting between various teams.
  • Self-motivated to remain informed on current and emerging trends and security best practices
  • Ability to work within a fast-paced environment with short timelines
  • Understanding of AWS and Security reference architecture
  • Understanding of DevOps and DevSecOps including current industry leading services and systems
  • SME on full development lifecycle processes, requirements, and security considerations
  • Application security experience and understanding of code scanning, remediation processes, and capabilities
Technical Requirements:
  • Experience breaking down complex systems and applications to find relevant security risks
  • Detailed understanding of Microsoft Active Directory, Identity and Auth services, DNS, DHCP and email infrastructure design and security
  • Deep understanding of VPN, PKI, IPAM and MFA technologies required
  • Understanding of application and operating system hardening, TCP/IP & network fundamentals, intrusion detection systems, firewalls, VPNs, WAFs
  • Demonstrated expertise crafting and running security solutions - vulnerability scanners, forensics software, SIEM, HIDS/NIDS, IPS, malware analysis and protection, content filtering, logical access controls,IAM, data loss prevention, content filtering technologies, and application firewalls
  • Understanding of cloud services
  • DevOps Proficiencies
  • Terraform / TFE
  • Hashi Vault
  • EKS / Kubernetes
  • Container Methodology
  • Application Security
  • Understanding of GitOps / Gitlab / Github
  • CI/CD processes and methodologies

This salary range is an estimate, and the actual salary may vary based on a wide range of factors, including your skills, qualifications, experience and location. This position is eligible for benefits including but not limited to medical, dental, vision, life insurance, disability coverage, flexible paid time off, Spring Health, Carrot Fertility, participation in a 401k with company match, ESPP, and many other additional voluntary benefits. Invitae also offers generous paid leave programs so you can spend time with your new child, recover from your own illness or care for a sick family member.
California Pay Range
$181,200—$235,500 USD

Please apply even if you don’t meet all of the “What you bring” requirements noted.  It’s rare that someone checks every single item, it’s ok, we encourage you to apply anyways.  

Join us!

At Invitae, we value diversity and provide equal employment opportunities (EEO) to all employees and applicants without regard to race, color, religion, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. We will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of the San Francisco Fair Chance Ordinance.

We truly believe a diverse workplace is crucial to our company's success and to better serve our diverse patients. Your input is especially valuable. We’d greatly appreciate it if you can take a quick moment to make your selection(s) below. Submissions will be anonymous.

You can find a detailed explanation of our privacy practices here.

Apply Now

Date Posted

11/06/2023

Views

32

Back to Job Listings ❤️Add To Job List Company Info View Company Reviews
Positive
Subjectivity Score: 0.9

Similar Jobs

Account Manager, Care Partnerships - Headway

Views in the last 30 days - 0

Headway a mental health care company founded in 2019 aims to revolutionize mental healthcare by building a national network of providers accepting ins...

View Details

Director of Pricing - Garner Health

Views in the last 30 days - 0

Garner Health is a rapidly growing company backed by toptier venture capital firms Their mission is to transform the healthcare economy by delivering ...

View Details

Director, Product, Customer, and Lifecycle Marketing - Garner Health

Views in the last 30 days - 0

Garner Health is seeking an experienced Product Marketing Leader to join their team The ideal candidate will lead the product marketing efforts focusi...

View Details

Linux Support Engineer - Voltage Park

Views in the last 30 days - 0

Voltage Park is seeking a Linux Support Engineer for a fulltime remote position The ideal candidate will have command line level Linux sys administrat...

View Details

Data Analyst - Agero

Views in the last 30 days - 0

Agero a leading B2B whitelabel provider of digital driver assistance services is revolutionizing the vehicle ownership experience through datadriven t...

View Details

Director, Product (Remote) - Dscout

Views in the last 30 days - 0

Dscout is a leading company in experience research technology offering a platform for major companies to gain insights into user needs and behaviors T...

View Details