Director of Information Security

Artisight · United States · Engineering

Posted 2026-09-23

Apply for this role →

About the Role

The Director of Information Security owns Artisight's security program end to end: security engineering and architecture, incident response, healthcare regulatory compliance (HIPAA and related frameworks), AI governance, and third-party risk. Artisight's platform sits inside hospital environments, so this role carries direct responsibility for protecting patient data, clinical workflows, and the AI systems running on smart hospital infrastructure.

This is a hands-on leadership role. The Director will run a lean security function, work closely with Engineering and the CTO on architecture and tooling decisions, and represent security to executive leadership, hospital customers, and auditors.

This role is remote, based in the United States, and requires U.S. work authorization.

What You’ll Do

Own security architecture review for new systems, integrations, and AI-driven features deployed into hospital environments, and maintain security standards for cloud infrastructure, endpoints, and network/edge security across Artisight's smart hospital hardware and software stack.

Own the relationship with our vCISO vendor, co-designing and operating the compliance and security programs.

Own the portfolio of third party security products, selecting vendors, ensuring proper implementation, and validating effectiveness.

Act as incident commander for security events, coordinating cross-functional response, containment, and communication; build and maintain incident response plans specific to a healthcare environment, including breach notification obligations; lead post-incident reviews focused on systemic fixes.

Ensure compliance with the HIPAA Security Rule and other applicable healthcare data protection requirements; own the security policy library, risk register, and control framework; lead internal and external audits and assessments, coordinating evidence collection across Engineering, Product, and Legal.

Partner with Engineering and product leadership on the security dimensions of AI governance, since Artisight's core product is AI-driven hospital infrastructure; set risk tolerance, guardrails, and review processes for new AI models, agents, and integrations before rollout; track emerging AI security and regulatory risk and translate it into practical controls.

Own vendor and third-party security risk assessment for new tools, integrations, and hospital-system contracts, and maintain a repeatable process for evaluating vendor and partner security posture, including hospital-side IT security requirements.

Hire, coach, and develop the security function as it scales beyond a single leader; report program maturity, open risk, and remediation progress to executive leadership on a regular cadence; represent Information Security credibly to executives, hospital customers, and auditors.

What You Have

7+ years in information security, including meaningful experience in security architecture, incident response, and compliance.

3+ years in a security leadership role.

Direct incident command experience, including coordinating cross-functional response to significant security events.

Experience building or running a healthcare-focused (or otherwise regulated) security compliance program, including familiarity with HIPAA and SOC 2 compliance.

Working knowledge of cloud security, identity and access management, and AI/agent architecture risk.

Bachelor's degree in Information Security, Information Systems, or a related field, or equivalent experience.

Strong written and verbal communication skills, including comfort presenting to executive audiences.

Bonus Points For

Experience in a healthcare, medical device, or health-tech company, particularly one operating inside hospital environments.

Experience with GRC tooling and control-framework work (SOC 2, ISO 27001, HITRUST, NIST CSF/AI RMF).

Familiarity with generative AI and agent security risk, including model/tool access patterns and delegated identity.

Relevant certifications (CISSP, CISM, CRISC, HCISPP, or equivalent).

Experience leading or building a security function from an early or lean stage.

Why You’ll Enjoy This Role

Impact: Your technical leadership will directly shape healthcare systems worldwide, creating AI-powered solutions that improve patient outcomes and provider experiences

Growth: You'll work at the intersection of cutting-edge AI, IoT technology, and healthcare innovation while expanding your expertise across our full technical stack

Team: Collaborate with executives, operational experts, and Engineering teams who share your passion for transforming healthcare through technology

#LI-REMOTE

Apply for this role →

← Back to all jobs