Job Description
Job Description
Speridian Technologies is seeking a Senior Security Engineering Manager / Coach for our State of California client, the Department of Health Care Services, Behavioral Health. This person will be part of a long-term, fully budgeted, state-of-the-art, extremely vast IT modernization project working with a variety of cross-functional teams and stakeholders.
This is a remote role, however, there will be meetings in the Sacramento area several times a year. Candidates are expected to work business hours, Monday-Friday Pacific time zone(PST). All candidates must be based in and work from the US.
Join DHCS’s Behavioral Health Transformation : Where Purpose Meets Innovation
Location : Remote / Hybrid
Department : Department of Healthcare Services (DHCS)
Commitment : Full-Time Consultant (W2 employee of Speridian or 1099 / IC for Speridian)
Why DHCS?
We work within government, for government, to deliver outcomes that matter to the citizens of California – but we don’t work like government. We are value-driven, agile in practice and philosophy, constantly innovating and improving our processes and tech stack, and committed to self-governing teams within a matrixed leadership structure.
We are passionate about solution delivery as a principle, entailing greater transparency and accountability for what is being delivered, decreasing risks faster, delivering organizational value sooner, and maximizing the flexibility and responsiveness of digital solutions to our customers' evolving business needs.
We serve the California Department of Health Care Services, which provides equitable access to quality health care for a third of Californians, leading to a healthy California for all. Right now, we are focused on transforming the delivery of behavioral health care delivery in California, including reducing suicide, drug overdoses, and the types of mental health and addiction crises that result in people living in tents on the streets where we live, too. We take this work very seriously, and we take team camaraderie and enjoying working with each other very seriously. We’re looking for innovators who are passionate about purposeful work and excited by the opportunity to drive lasting change through innovative solutions.
Our Core Values (Achieve Together, Be Curious, Elevate Yourself, and Deliver Value)
- We achieve together by championing a team-oriented workplace built on mutual respect, collaboration, and open communication.
- We encourage individuals and teams to constantly be curious and seek a deeper understanding and fresh ideas that drive innovation and meaningful change
- We provide a supportive workplace where you can elevate yourself and achieve personal growth through continuous learning, focused effort, and perseverance
- We deliver value as part of every action we take to serve California’s citizens
We’re honest about the challenges—state government is bureaucratic, and we can't match most tech salaries.
But here’s what we can offer :
Purpose that matters
Teammates who care deeply
Work-life balance and remote work
We're not just changing systems—we're changing how government works
Overview / Description
Senior Security Engineering Manager / Coach
Ready to defend California's digital healthcare frontier? Join the Department of Healthcare Services (DHCS) as a Senior Security Engineering Manager, where you'll lead the security transformation protecting sensitive healthcare data for 14 million Californians against nation-state actors and sophisticated cyber threats.
As a Senior Security Engineering Manager, you'll command a multidisciplinary security force spanning security engineering, SecOps, compliance, and penetration testing. This role transcends traditional security management – you'll architect zero-trust environments, orchestrate threat hunting operations, and build security programs that enable innovation rather than inhibit it. Your strategies will protect billions in healthcare transactions, ensure HIPAA compliance at massive scale, and establish DHCS as a model for government cybersecurity excellence.
DHCS offers the unique challenge of securing healthcare systems with nation-state level threats while maintaining the agility of a tech startup. You'll have comprehensive ownership across the security spectrum, from writing infrastructure-as-code for security controls to briefing executives on risk posture. You'll build a security organization that shifts from reactive compliance to proactive cyber resilience.
We're seeking a security leader who thrives in complexity – someone who can reverse-engineer malware while designing enterprise security architecture, who treats compliance as a baseline not a ceiling, and who believes that government agencies should set the standard for security excellence, not follow it.
Responsibilities & Outcomes
1. Security Strategy & Architecture
Drive enterprise security strategy across security engineering, SecOps, and compliance domainsDesign and oversee security architecture for cloud-native and hybrid environmentsChampion shift-left security practices including secure coding, threat modeling, and DevSecOpsMake critical trade-off decisions balancing security controls, operational efficiency, and delivery timelinesOutcome : Organizations operate with robust security postures that enable business while managing risk
2. Business Ownership & Financial Accountability
Own security metrics and ROI for security investments across tools, people, and processesDevelop cost-benefit analyses for security controls, tooling decisions, and compliance initiativesManage team budget including security tools, penetration testing, audits, and infrastructureTranslate security improvements into business value through reduced incidents and compliance costsDrive efficiency improvements in security operations while maintaining comprehensive protectionOutcome : Security decisions driven by risk-based approach with clear ROI and business alignment
3. People Management & Development
Manage, mentor, and develop a team of 10-20 security engineers across multiple disciplinesConduct regular 1 : 1s focused on career development and performanceExecute performance management including promotions, improvement plans, and difficult conversationsBuild diverse, inclusive teams through thoughtful hiring and team compositionOutcome : High-performing teams with strong retention, clear growth paths, and engaged security professionals
4. Security Operations & Incident Response
Establish and maintain security operations capabilities and incident response proceduresLead incident response efforts for critical security events and coordinate cross-functional responseImplement security monitoring, SIEM management, and threat intelligence programsDrive continuous improvement in mean time to detect (MTTD) and mean time to respond (MTTR)Outcome : Rapid detection and response to security threats with minimal business impact
5. Compliance & Risk Management
Ensure adherence to HIPAA, StateRAMP, NIST, and other regulatory frameworksManage security audit processes and remediation efforts across multiple compliance standardsDevelop and maintain security policies, standards, and proceduresConduct risk assessments and manage enterprise risk registerOutcome : Continuous compliance with all regulatory requirements and proactive risk management
6. Security Engineering & Testing
Oversee application security including SAST, DAST, and software composition analysisManage penetration testing programs including scope, vendor management, and remediationImplement infrastructure security controls for cloud and on-premise environmentsDrive automation of security controls and integration into CI / CD pipelinesOutcome : Comprehensive security testing coverage with vulnerabilities identified and remediated early
7. Cross-functional Partnership
Partner with Engineering on secure development practices and security requirementsCollaborate with Infrastructure teams on cloud security and zero-trust architectureWork with Legal and Compliance on regulatory requirements and audit responsesCommunicate security risks and metrics to executive stakeholders and board membersOutcome : Security embedded throughout the organization with strong stakeholder alignment
8. Talent Strategy & Team Building
Lead technical interviews and hiring decisions for security roles across multiple disciplinesDevelop team skills through training, certifications (CISSP, OSCP, AWS Security)Identify and cultivate future security leaders and architectsBuild team culture emphasizing proactive security and continuous improvementOutcome : Strong talent pipeline with security professionals growing into senior and leadership roles
Required Qualifications
Proven track record managing security teams of 15+ members across multiple disciplinesExperience owning P&L or budget responsibility for enterprise security programsDemonstrated ability to connect security initiatives to business outcomes and risk reductionExperience building and operating security programs including SecOps, compliance, and engineeringStrong background in cloud security, DevSecOps, and modern security practicesExperience managing compliance for regulated environments (HIPAA, FedRAMP, SOC2)Track record of reducing security incidents and improving security posture metricsBachelor's degree in Computer Science, Information Security, or equivalent experienceSkills : Technical
Cloud Security : AWS / Azure / GCP security services, IAM, network securitySecurity Tools : SIEM (Splunk / Datadog), SAST / DAST (Snyk), EDR (CrowdStrike)Infrastructure Security : Zero-trust architecture, microsegmentation, Kubernetes securityCompliance Frameworks : HIPAA, NIST CSF, StateRAMP, SOC2, ISO 27001Penetration Testing : OWASP, threat modeling, vulnerability managementLanguages : Python, Bash, Terraform, understanding of multiple programming languagesBusiness & Financial
Financial Management : Security budget ownership, tool optimization, and ROI analysisRisk Management : Risk assessment, risk register management, and business impact analysisSecurity Metrics : MTTD, MTTR, vulnerability closure rates, compliance scoresValue Communication : Articulating security investments in business risk termsVendor Management : Managing MSSPs, penetration testing firms, and security toolsLeadership
People Management : Performance management, career development, and 24 / 7 team coordinationTeam Building : Hiring across security disciplines, onboarding, and culture developmentCommunication : Board-level reporting, incident communication, and technical translationDecision Making : Risk-based security decisions and incident response leadershipStrategic Thinking : Aligning security strategy with business objectivesChange Management : Leading security transformation and tool migrationsGeneral
Problem-Solving : Complex security incident and architectural challenge resolutionCollaboration : Working effectively with Engineering, Legal, Compliance, and Executive teamsMentorship : Developing security professionals across multiple specializationsProcess Improvement : Implementing security automation and operational efficiencyCrisis Management : Leading through security incidents and maintaining composure under pressureSperidian is an Equal Opportunity Employer
Powered by JazzHR
OKlXx9bARy