Security Lead

CommenceVirginia Beach, VA
Remote

About The Position

At Commence, we’re the start of a new age of data-centric transformation, elevating health outcomes and powering better, more efficient process to program and patient health. We combine quality data-driven solutions that fuel answers, technology that advances performance, and clinical expertise that builds trust to create a more efficient path to quality care. With human-centered, healthcare-relevant, and value-based solutions, we create new possibilities with data. We provide proof beyond the concept and performance beyond the scope with a focus on efficiencies that transform the lives of those we serve. With a culture driven by purpose, straightforward communication and clinical domain expertise, Commence cuts straight to better care.

Requirements

  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, or related field.
  • 10+ years of cybersecurity experience, including 2+ years supporting federal health programs.
  • 5+ years securing cloud-based solutions, including AWS.
  • Experience supporting healthcare or CMS-related systems.
  • Experience with ATO processes and federal compliance frameworks.
  • Experience leading security teams in Agile and DevSecOps environments.

Nice To Haves

  • CISSP – Certified Information Systems Security Professional

Responsibilities

  • Establish and oversee the cybersecurity, privacy, and compliance posture for a CMS case management program.
  • Serve as the primary security advisor to program leadership, working closely with the Program Manager, Solutions Architect, Cloud Architect, DevSecOps team, and government security stakeholders to ensure security is embedded into every layer of the solution.
  • Lead the program's cybersecurity strategy and ensure compliance with CMS ARS, FISMA, HIPAA/HITECH, NIST 800-53, and FedRAMP requirements.
  • Develop and maintain security plans, policies, and procedures aligned to federal standards.
  • Support Authority to Operate (ATO) activities and coordinate with government security officials and compliance auditors.
  • Manage Plan of Action and Milestones (POA&M) activities and maintain the program risk register.
  • Review and approve AWS cloud architecture designs, ensuring secure implementation of cloud-native services and security controls.
  • Enforce IAM policies, MFA, encryption at rest and in transit, network segmentation, and Zero Trust principles.
  • Embed security controls into CI/CD pipelines and validate cloud configurations against security baselines.
  • Implement automated scanning for source code, containers, Kubernetes workloads, Infrastructure as Code (IaC), and open-source dependencies.
  • Conduct security risk assessments and threat modeling; identify vulnerabilities and develop mitigation strategies.
  • Evaluate third-party and integration partner security risks.
  • Define data classification, handling, retention, and destruction requirements to protect PII and PHI.
  • Review interoperability and data-sharing solutions for HIPAA privacy compliance.
  • Develop and maintain incident response procedures and support SIEM-based monitoring and alerting strategies.
  • Coordinate response activities for security incidents and vulnerabilities.
  • Participate in Architecture Review Boards (ARBs) and review application, integration, data, and infrastructure designs for security gaps.
  • Ensure secure API and interoperability implementations across all integrated systems.

Benefits

  • Equal employment opportunity employer
  • Personnel processes are merit-based and applied without discrimination
  • Commitment to providing equal employment opportunities to all applicants, including individuals with disabilities
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service