Director of Security

Sequencing
•Remote

About The Position

Sequencing is seeking its first dedicated security leader to build and own the company's security function from the ground up. This is a hands-on role where the individual will execute the majority of the work initially, including policy writing, triaging findings, and configuring controls, with the plan to hire and coach a team as the program matures. The role is for an AI-first security leader who will use AI daily in their work and set the company's posture on AI adoption and governance. The Director of Security will report to the Head of Engineering and collaborate with Platform Engineering, Bioinformatics, and AI functions. The primary responsibility is to protect sensitive consumer data, including whole genome sequences and health data.

Requirements

  • 8+ years in security, with at least one experience as the first or only security leader at a company under a few hundred people.
  • Experience taking a company through SOC 2 or building a HIPAA program from scratch.
  • Hands-on experience in AWS and web application security, including reading Terraform PRs, triaging pentest findings, and tuning WAF rules.
  • Proven ability to run pentests through vendors, triage findings, and close them with engineers.
  • Experience securing a consumer-facing product at scale, including identity and account security, MFA, credential stuffing defense, and session/account recovery abuse.
  • Understanding of privacy and breach obligations beyond HIPAA.
  • AI-first work approach, using coding assistants and LLMs daily and demonstrating how they have improved security workflows.
  • Belief in governing AI tools rather than blocking them.
  • Exceptional communication skills under pressure, including briefing boards or executive teams during live incidents.
  • Ability to explain risk and tradeoffs to non-technical leaders in plain language, both written and verbally.

Nice To Haves

  • Healthcare or genomics experience.
  • Familiarity with state genetic privacy laws, the FTC Health Breach Notification Rule, and state breach notification requirements.
  • E-commerce or payment-processing security experience.
  • ISO 27001 certification.
  • PCI DSS compliance experience.
  • Drupal security knowledge.
  • Experience with GDPR and international data transfers.
  • Mobile application security experience.
  • Experience with Vanta or Drata.
  • SIEM experience.
  • Cloudflare Enterprise experience.
  • Zero Trust architecture knowledge.

Responsibilities

  • Create the security ownership map with Platform Engineering, defining roles for infrastructure controls, policy, assurance, AppSec, offensive security, and incident response leadership.
  • Complete a HIPAA and HITECH review and deliver a prioritized remediation roadmap.
  • Achieve SOC 2 readiness within six months, aligned with the infrastructure roadmap.
  • Formalize incident response processes, including severity models, escalation paths, communications, executive coordination, and post-incident reviews.
  • Extend security policy to AI tooling and model providers, covering data classification, acceptable use, and data-handling standards.
  • Run the security program, including policy management, risk register maintenance, security awareness and training, and GRC tooling.
  • Manage offensive security, including scoping and managing external pentest firms, triaging findings, and driving remediation.
  • Oversee security reviews of third-party data flows, including partner and marketplace apps, provider data sharing, marketing and analytics integrations, and AI model providers.
  • Establish security standards for contractors, agencies, and third-party development partners, covering IP protection, device management, and access lifecycle.
  • Govern SaaS usage, manage shadow IT visibility, and define identity lifecycle policy.
  • Apply AI to the security program itself for tasks like detection and log triage, automated evidence collection, policy and control drafting, and code/infrastructure review.
  • Serve as the escalation point for security incidents, including after hours.
  • Report security posture, risk, and roadmap to the founder and leadership team in business-oriented language.
  • Translate security findings into practical actions for engineering teams that maintain product velocity.

Benefits

  • Comprehensive medical, dental, and vision insurance coverage
  • 401(k) with company matching
  • Paid time off
  • Paid volunteer time off
  • Fully remote work
  • Home office stipend
  • Parental bonding leave
  • Private and confidential clinical-grade whole genome sequencing for you and your family
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service