Senior Manager / Manager, Security
Job description
About Plenful
Plenful is on a mission to transform healthcare operations from the inside out. Fresh off our $50M Series B and backed by Notable Capital, Bessemer Venture Partners, TQ Ventures, Susa/Kivu Ventures, and other leading investors, we’re building the category-defining AI automation platform that healthcare teams rely on to operate smarter, faster, and more efficiently. Our technology empowers healthcare operators across hospital and health systems, pharmacies and payors to eliminate manual work, reduce administrative burden, and improve compliance, all while unlocking critical revenue to fund programs for their in-need patient populations.
Built by healthcare operators for healthcare operators, Plenful is driven by a deep understanding of the challenges facing today’s care teams. We’re passionate about equipping healthcare workers with world-class tools that deliver real, measurable impact, and we’re proud to serve 100+ leading health systems, pharmacies, and healthcare organizations across the country. If you’re excited to help shape the future of healthcare, we’d love to meet you. Apply now to join our growing team.
The Opportunity
This is an opportunity to lead and execute security at one of healthcare's fastest-growing AI companies.
As Senior Manager / Manager, Security, you will own and help mature security across the company—from product and application security to cloud infrastructure, corporate security, governance, compliance, incident response, and customer trust. You will set priorities, implement the right tooling and processes, lead a small team, and partner across Engineering, Product, IT, Legal, Compliance, Sales, and Executive Leadership.
This is also a hands-on role. You will work directly with engineers to identify, prioritize, and remediate vulnerabilities; improve secure development practices; strengthen detection and incident response; and implement security tooling and automation. We are looking for a builder who thrives in ambiguity, can set direction, and is equally comfortable reviewing application code, investigating an incident, implementing controls, supporting customer discussions, and communicating security risk to leadership.
What You Will Do
Lead and Execute the Security Program
- Define and execute a pragmatic security roadmap aligned with Plenful's product and business priorities.
- Lead a small security team and coordinate security work across Engineering, Product, IT, Legal, and Compliance.
- Personally own and execute critical security work while building scalable processes and automation.
- Prioritize security risks based on exploitability, business impact, customer commitments, and regulatory requirements.
- Create security processes that support rapid product development without slowing innovation.
Product and Application Security
- Establish and mature secure software development lifecycle practices across Engineering.
- Partner directly with engineers to identify, reproduce, prioritize, and remediate application vulnerabilities.
- Review application code and architecture, propose fixes, and contribute or validate security-related code changes where appropriate.
- Lead threat modeling, secure architecture reviews, penetration testing, vulnerability management, and remediation tracking.
- Integrate SAST, DAST, software composition analysis, secrets detection, and other security controls into CI/CD pipelines and developer workflows.
- Build reusable guardrails, secure coding patterns, and automation that make it easier for engineers to ship secure software.
- Define and implement security standards for AI-powered products and machine learning systems, including data protection, tenant isolation, prompt-injection risks, agent permissions, tool use, and continuous security evaluation.
Security Operations and Incident Response
- Build and operate security monitoring, detection, logging, alerting, and incident response capabilities.
- Triage security findings and incidents, lead investigations, coordinate containment and remediation, and drive postmortems to completion.
- Develop incident-response playbooks and lead tabletop exercises.
- Establish and operate a risk-based vulnerability-management program that consolidates findings, validates exploitability, assigns ownership and remediation SLAs, tracks exceptions, and drives issues through closure.
- Improve detection coverage and response readiness based on incidents, threat intelligence, and changes to Plenful's platform.
Cloud and Infrastructure Security
- Strengthen security across Plenful's AWS infrastructure.
- Improve identity and access management, secrets management, infrastructure hardening, endpoint security, and network security.
- Review Infrastructure as Code, Kubernetes, containers, and cloud architecture for security risks.
- Partner with Infrastructure and DevOps engineers to remediate findings and implement preventive controls.
Governance, Risk, and Compliance
- Lead Plenful's security compliance strategy, including SOC 2, HIPAA, HITRUST, and future certifications.
- Develop and maintain practical security policies, standards, and controls.
- Own or support vendor risk management and third-party security reviews.
- Partner closely with Legal and Compliance on security, privacy, incident response, and customer commitments.
Customer Trust and Executive Partnership
- Represent Security during enterprise customer reviews and technical security discussions.
- Partner with Sales and Customer Success to support enterprise deals, security questionnaires, and customer due diligence.
- Communicate security posture, material risks, incidents, investments, and priorities clearly to executive leadership and the Board.
- Build a security-first culture through education, practical guidance, and partnership.
What We Are Looking For
Required Qualifications
- 12+ years of progressive experience in cybersecurity, application security, security engineering, security operations, cloud security, or infrastructure security.
- 2+ years leading security teams, programs, or major cross-functional security initiatives.
- Deep, hands-on experience in application security and security operations.
- Demonstrated ability to investigate and remediate vulnerabilities in modern web applications, APIs, and distributed systems.
- Ability to read application code, reason about security flaws, and work directly with engineers on effective fixes. Experience contributing security-related code changes is strongly preferred.
- Experience with threat modeling, secure architecture reviews, penetration-test remediation, vulnerability management, and incident response.
- Experience integrating and operating security tooling across CI/CD pipelines and developer workflows.
- Strong technical background in modern cloud environments, preferably AWS, including IAM, logging, network security, secrets management, and Infrastructure as Code.
- Experience securing enterprise SaaS platforms and multi-tenant systems.
- Experience with healthcare security and compliance frameworks, including HIPAA and SOC 2.
- Strong judgment in prioritizing security work in a fast-moving environment with limited resources.
- Exceptional communication skills with the ability to work effectively with engineers, executives, customers, auditors, Legal, Compliance, and Sales.
- Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or equivalent practical experience.
Preferred Qualifications
- Experience as an early security hire at a startup or high-growth technology company.
- Hands-on experience with Python, TypeScript, or similar modern application languages.
- Experience with HITRUST certification.
- Experience securing AI/ML platforms, agentic systems, and modern data infrastructure.
- Experience with Kubernetes, container security, Infrastructure as Code, and cloud-native architectures.
- Experience building security automation and internal security tooling.
- CISSP, CISM, CCSP, GIAC, or comparable certifications.
What Success Looks Like
Within your first 12 months, you will:
- Establish a risk-based security roadmap with clear ownership and measurable outcomes.
- Reduce the existing application and infrastructure vulnerability backlog and establish sustainable remediation SLAs.
- Embed practical AppSec controls and security tooling into Engineering workflows and CI/CD pipelines.
- Improve Plenful's monitoring, detection, incident-response, and vulnerability-management capabilities.
- Strengthen cloud security, tenant isolation, identity, secrets management, and other high-impact preventive controls.
- Establish security standards and evaluation practices for Plenful's AI-powered products.
- Strengthen compliance and customer trust programs to support enterprise growth.
- Become a trusted, hands-on partner to Engineering, Product, Legal, Compliance, Sales, customers, and executive leadership.
Why You'll Love Working Here
- 🚀 Mission-Driven, World-Class Team — Join an exceptional group of professionals aligned around a meaningful mission and committed to making an impact
- 📈 Opportunities for Growth — Strengthen your expertise through collaboration with experienced, high-performing leaders across the organization
- 🏢 Flexible Hybrid Work Environment — We're remote-first, with meaningful office presence in San Francisco and New York. R&D roles follow a hybrid model, with two days per week in our San Francisco office
Benefits & Perks
- 🏥 Healthcare Coverage — Full medical, dental, and vision insurance for you and participation for your family
- 💰 401(k) with Company Match — Plenful matches 50% of your first 3% contributed
- 📊 Equity — Every full-time employee shares in our success
- 🌴 Unlimited PTO — Take the time you need, when you need it
- 🍽️ Daily Lunch Stipend — $100/week to cover your midday meals
- 💪 Wellness Stipend — $100/month to support your health and well-being
- 🚇 Commuter Benefits — $100/month for SF and NYC-based employees
- 👶 Parental Leave — Paid leave to support growing families
Skills mentioned
- AI
- API
- Automation
- AWS
- CI Cd
- Cism
- Cissp
- Cloud
- Cloud Native
- Cloud Security
- Container Security
- Customer Success
- Cybersecurity
- Dast
- DEVOPS
- Distributed Systems
- Due Diligence
- HIPAA
- IAM
- Infrastructure As Code
- Kubernetes
- Llmops
- Machine Learning
- Network Security
- Penetration Testing
- Python
- Regulatory Compliance
- Risk Management
- SAAS
- Sales
- Sast
- Sdlc
- Secrets Management
- Secure Coding
- Security Operations
- SOC 2
- TypeScript

Plenful was founded in 2021 by experienced pharmacy operators who recognized the pressing challenges within the healthcare sector, particularly around labor shortages, increasing administrative burdens, and rising costs. Our mission is to empower healthcare professionals by providing innovative, AI-driven workflow automation solutions designed to address the daily inefficiencies that plague pharmacy and healthcare operations. We focus on streamlining critical processes, such as 340B audits, prior authorization management, and integrating disparate data, ensuring that healthcare providers can focus on what truly matters: patient care. Our solutions cater to a wide array of healthcare entities, including large health systems and specialty pharmacies, facilitating seamless integration and optimization of existing workflows. With our platform, healthcare teams can automate over 95% of manual tasks, recovering lost revenue and enhancing operational efficiency. We pride ourselves on our commitment to creating a supportive and responsive environment for our clients, as evidenced by numerous positive testimonials from partners like Tampa General Hospital and Renown Health, where our solutions have led to significant improvements in workflow efficiency and savings. As we look to the future, we remain dedicated to transforming healthcare operations through innovative technology and unparalleled customer support.
Apply for this job
Use the application link supplied with this listing to apply to Plenful. Check the destination before entering personal information.
