HealthEquity has a vision that by 2030 we will make HSAs as wide-spread and popular as retirement accounts. We are passionate about providing a solution that allows American families to connect health and wealth.
Director, Attack Surface & Infrastructure Vulnerability Management
Location
United States
Posted
4 days ago
Salary
$167K - $221K / year
No structured requirement data.
Job Description
Role Description
At HealthEquity, security protects something deeply personal. People trust us with their health, their finances, and their futures. In this role, you will help protect that trust at scale.
You will shape how the company understands, prioritizes, and reduces real‑world risk across every product and platform we run. This is not a role focused on chasing vulnerabilities or managing tools. It is an opportunity to build a modern, intelligent, and outcome‑driven security capability that leadership relies on and engineering partners value.
Your work will directly influence how we invest, how teams build, and how resilient our technology ecosystem becomes over time. If you want ownership, visibility, and the chance to leave a lasting mark on a growing organization, this role was designed for you.
What You’ll Be Doing
- Define and lead the long‑term enterprise strategy for attack surface and infrastructure vulnerability management
- Drive modernization of Product Security capabilities including automated risk scoring, AI‑enabled security, risk‑based vulnerability management, and targeted offensive security
- Own the full vulnerability lifecycle across cloud, infrastructure, endpoints, identities, and platforms
- Build prioritization models that reflect real risk using exploitability, exposure, asset criticality, and business impact
- Lead continuous discovery and reduction of internal and external attack surface across all production environments
- Partner closely with Engineering, Product, Cloud Platform, IT, Security Operations, Risk, Compliance, and Legal to drive durable risk reduction
- Establish and oversee targeted offensive security initiatives that validate real‑world exploitability and influence architecture and investment decisions
- Define ASVM tool strategy, integrations, automation, and trusted data pipelines across the security ecosystem
- Translate complex technical risk into clear, executive‑level insights that inform business decisions
- Build, lead, and develop a high‑performing team with clear ownership, accountability, and growth paths
- Define KPIs and deliver regular executive updates on risk posture, trends, and program effectiveness
Qualifications
- 10+ years of experience in cybersecurity, with strong depth in vulnerability management, attack surface management, or infrastructure security
- Experience leading enterprise‑scale security programs with broad organizational impact
- Strong understanding of cloud platforms, modern infrastructure, identity systems, and application security
- Hands‑on experience with risk‑based vulnerability management and exposure prioritization beyond CVSS
- Experience designing or overseeing offensive security efforts such as penetration testing or adversary simulation
Requirements
- Proven people leader with experience hiring, coaching, and developing high‑performing teams
- Ability to influence senior leaders and align cross‑functional partners without relying on authority alone
- Comfort making strategic tradeoffs and owning outcomes that matter at an executive level
- Outcome‑focused mindset with a bias toward measurable risk reduction
- Strong judgment, curiosity, and ability to operate effectively in complex environments
- Passion for building scalable, durable security capabilities that stand the test of growth
Benefits
- Medical, dental, and vision
- HSA contribution and match
- Dependent care FSA match
- Uncapped paid time off
- Adventure accounts
- Paid parental leave
- 401(k) match
- Personal and healthcare financial literacy programs
- Ongoing education & tuition assistance
- Gym and fitness reimbursement
- Wellness program incentives
Company Description
HealthEquity has a vision that by 2030 we will make HSAs as wide-spread and popular as retirement accounts. We are passionate about providing a solution that allows American families to connect health and wealth. Join us and discover a work experience where the person is valued more than the position.
HealthEquity, Inc. is an equal opportunity employer that is committed to inclusion and diversity. We take affirmative action to ensure equal opportunity for all applicants without regard to race, age, color, religion, sex, sexual orientation, gender identity, national origin, status as a qualified individual with a disability, veteran status, or other legally protected characteristics. HealthEquity is a drug-free workplace.
Job Requirements
- 10+ years of experience in cybersecurity, with strong depth in vulnerability management, attack surface management, or infrastructure security
- Experience leading enterprise‑scale security programs with broad organizational impact
- Strong understanding of cloud platforms, modern infrastructure, identity systems, and application security
- Hands‑on experience with risk‑based vulnerability management and exposure prioritization beyond CVSS
- Experience designing or overseeing offensive security efforts such as penetration testing or adversary simulation
- Proven people leader with experience hiring, coaching, and developing high‑performing teams
- Ability to influence senior leaders and align cross‑functional partners without relying on authority alone
- Comfort making strategic tradeoffs and owning outcomes that matter at an executive level
- Outcome‑focused mindset with a bias toward measurable risk reduction
- Strong judgment, curiosity, and ability to operate effectively in complex environments
- Passion for building scalable, durable security capabilities that stand the test of growth
Benefits
- Medical, dental, and vision
- HSA contribution and match
- Dependent care FSA match
- Uncapped paid time off
- Adventure accounts
- Paid parental leave
- 401(k) match
- Personal and healthcare financial literacy programs
- Ongoing education & tuition assistance
- Gym and fitness reimbursement
- Wellness program incentives
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Cybersecurity Threat Intelligence Expert evaluating incident response strategies
The lead will perform CCRI, vulnerability assessments, and penetration testing across networks, databases, computer applications, and IT frameworks supporting a financial management modernization program.
Staff Product Security Engineer
Greenlight Financial TechnologyGreenlight is the leading family fintech company on a mission to help parents raise financially smart kids. We proudly serve more than 6 million parents and kids with our award-winning banking app for families. With Greenlight, parents can automate allowance, manage chores, set flexible spend controls, and invest for their family’s future. Kids and teens learn to earn, save, spend wisely, and invest. At Greenlight, we believe every child should have the opportunity to become financially healthy and happy. It’s no small task, and that’s why we leap out of bed every morning to come to work. Because creating a better, brighter future for the next generation depends on it.
This role is responsible for the end-to-end security of consumer products, the digital platform, and a new hardware device line, driving security review, threat modeling, and leading penetration testing and PSIRT operations. Key duties include championing secure AI adoption, establishing security guardrails for AI products, and advising on security implications of new features.
This role is responsible for developing, engineering, and maintaining the Medical Device/IoMT Security Program, which includes designing, engineering, managing, and recommending improvements for security solutions and configurations based on NIST standards. The specialist will also identify vulnerabilities, develop remediation processes, provide technical guidance to IT teams, and assist in defining the overall medical device protection strategy.