Cybersecurity Engineer

Iterative HealthCambridge, MA
Hybrid

About The Position

Iterative Health is seeking its first dedicated cybersecurity hire to build and lead the company's cybersecurity strategy. This role involves establishing the foundation to protect the company's people, technology, data, and business as it scales. The position requires owning the end-to-end security landscape, including AWS cloud infrastructure, identity and access management, SaaS ecosystem, endpoint security, sensitive data, and compliance frameworks. The Cybersecurity Engineer will collaborate with IT, Engineering, Compliance, Legal, and business leaders to enhance security posture, reduce risk, and integrate security across the organization. The ideal candidate is a hands-on security leader with deep technical expertise, strong business judgment, and a builder's mindset, comfortable with architecting solutions, responding to threats, developing policies, and influencing stakeholders. This is an opportunity to create a scalable, modern security program for a fast-paced healthcare technology company.

Requirements

  • Bachelor's degree in IT, engineering, mathematics, or a related field; candidates with extensive cybersecurity certification in lieu of a degree will be considered.
  • 5+ years of experience in cybersecurity, security engineering, cloud security, IT security, or a related technical security role.
  • Strong working knowledge of HIPAA, HITECH, SOC 2, and HITRUST frameworks.
  • Hands-on experience with AWS, Microsoft 365, and Google Workspace security tooling.
  • Experience with Bitdefender, Microsoft Defender, Intune, Entra ID, Microsoft Purview, Google Workspace security, Okta, or SIEM/logging tools.
  • Strong documentation skills, including policy and procedure writing.
  • Ability to communicate effectively with non-technical business partners.
  • Experience with PowerShell, Python, APIs, or security workflow automation.
  • Experience with vulnerability management, penetration test remediation, phishing simulation programs, or third-party risk reviews.

Nice To Haves

  • Knowledge of EU General Data Protection Regulation (GDPR).
  • One or more relevant certifications, including but not limited to: CompTIA Security+, CySA+, or Pen Test+; GCIH; ISC2 CCSP; AWS Certified Security Specialty (SCS-C03); Microsoft SC-200, SC-300, SC-401, SC-100, or SC-900; Google Cybersecurity Professional or Cloud Cybersecurity Certificate.
  • Experience building or maturing a security program in a high-growth or startup environment.
  • Background in healthcare technology, clinical research, or other highly regulated industries.

Responsibilities

  • Serve as Iterative Health's first dedicated cybersecurity resource — build, mature, and operate the company's security program from the ground up.
  • Identify security gaps, prioritize remediation, and partner with the IT Director to define security priorities, roadmap items, and risk reduction plans.
  • Develop, maintain, and enforce security policies, standards, procedures, runbooks, and control documentation.
  • Provide company-wide subject matter expertise and support related to cybersecurity awareness and compliance.
  • Work with the engineering team to secure and monitor AWS environments, including IAM, logging, encryption, backups, access controls, and overall cloud security posture.
  • Configure firewalls, encryption, and access controls across cloud and corporate infrastructure.
  • Improve security controls across Okta, Entra ID, Microsoft 365, Google Workspace, Box, SharePoint, AWS, and other cloud platforms.
  • Maintain and improve RBAC, access reviews, privileged access controls, admin role governance, service account oversight, and joiner/mover/leaver security processes.
  • Own incident response for suspected cyberattacks, account compromise, malware, data exposure, unauthorized access, and other security events.
  • Lead incident investigation, containment, remediation, documentation, root-cause analysis, and post-incident improvement tracking.
  • Own security evidence collection, control documentation, remediation tracking, and audit support for SOC 2, HIPAA/HITECH, and applicable GDPR requirements.
  • Own all vendor assessment and security questionnaire responses.
  • Support vulnerability management, penetration testing, social engineering testing, customer security reviews, vendor security questionnaires, third-party risk assessments, security awareness, and user education.
  • Perform related duties as requested.

Benefits

  • Hybrid work environment with in-office collaboration two days per week in either our NYC or Boston office
  • Comprehensive medical, dental, and vision coverage, with up to 80% of premiums covered by Iterative Health
  • Mental health and wellness support through Spring Health
  • Health HSA or FSA options, and commuter FSA contributions supported by Iterative Health
  • Unlimited PTO, 12 company holidays, and a company-wide shutdown between Christmas and New Years
  • 401(k) program with a company match of up to 3% (up to $3,000 annually)
  • Weekly in-office lunch benefit every Tuesday
  • 100% company-paid short-term and long-term disability coverage
  • Annual wellness and professional development stipend to support your health and growth
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service