All remote jobs
Open role
Remote opportunity atBetterHelp

Head of Security Engineering

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

Published
46Listing views
3Application actions
13 Oct 2026Apply before
Opportunity details

About this role.

AI Summary

BetterHelp is hiring a hands-on Head of Security Engineering to set and lead its security strategy, centered on a red-team-first and attacker-minded approach. The leader will direct offensive security capabilities such as penetration testing, code review, vulnerability discovery, and security tooling while overseeing SecOps and application security. This role partners closely with engineering to embed security in the SDLC, improve vulnerability management and incident response, and reduce technical debt across cloud and distributed systems. The ideal candidate brings extensive security engineering and leadership experience, can operate strategically and tactically, and communicates effectively with both technical and business stakeholders.

Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

Job Complexity

5/5
EasyHard

Pace & Pressure

5/5
RelaxedFast-paced

Autonomy Level

5/5
GuidedFull ownership

Communication Load

5/5
IndependentCollaborative
AI insightThis is a senior security leadership role requiring more than 10 years of security engineering experience and at least 5 years of leadership experience. It combines deep offensive-security expertise with broad responsibility for organizational strategy, cross-functional execution, and oversight of multiple security disciplines in a fast-release environment.

Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianMarket rate
$275,000
US market range$240k–$330k
AI insightThe disclosed base salary range is $250,000–$300,000 USD yearly, producing an offer median of $275,000. For a US-based Head of Security Engineering with substantial offensive-security, cloud, application-security, and people-leadership scope, an estimated US base-salary market range is $240,000–$330,000 annually; bonus, equity, and benefits may increase total compensation.

Core skills

Skills and capabilities most closely associated with this opportunity.

Sample interview questions
How would you establish a red-team-first security strategy while maintaining productive relationships with engineering teams?

I would align testing to the company’s most critical assets and realistic threat scenarios, then turn findings into risk-ranked, actionable engineering work. I would define clear remediation ownership, SLAs, and recurring reviews, while emphasizing that offensive testing is a tool for learning and resilience rather than a punitive exercise.

Describe how you would prioritize vulnerabilities discovered across applications, cloud infrastructure, and internal systems.

I would prioritize based on exploitability, exposure, asset criticality, data sensitivity, potential business impact, and the availability of compensating controls. A continuously maintained asset inventory and risk model would support consistent decisions, with critical internet-facing or PHI/PII-related findings receiving immediate attention and executive visibility.

What metrics would you use to demonstrate that the security engineering program is improving?

I would track time to detect and remediate critical findings, vulnerability recurrence, coverage of threat modeling and secure-code controls, remediation SLA attainment, penetration-test findings by severity, and incident trends. I would pair these operational measures with outcome-oriented reporting that shows reduced exposure across the highest-risk systems.

How would you embed security into a fast-moving software development lifecycle without creating excessive friction?

I would automate high-signal controls in CI/CD, provide secure defaults and reusable security patterns, and engage security champions within engineering teams. Threat modeling and design reviews would focus on high-risk changes, while clear self-service guidance and rapid security consultation would help teams ship securely at speed.

How would you approach emerging AI security risks at BetterHelp?

I would begin with an inventory of AI use cases, data flows, models, vendors, and permissions, then conduct threat modeling for risks such as prompt injection, data leakage, model abuse, insecure integrations, and supply-chain exposure. Controls would include data-governance guardrails, adversarial testing, monitoring, access restrictions, vendor assessments, and incident playbooks tailored to AI-enabled systems.

This analysis is generated from the job description. Salary estimates, role characteristics and sample answers are guidance, not employer-provided facts.

Who are we and why should you join us?

BetterHelp is on a mission to remove the traditional barriers to therapy and make mental health care more accessible to everyone. Founded in 2013, we are now the world’s largest online therapy service, providing affordable and convenient therapy across the globe. Our network of over 30,000 licensed therapists has helped millions of people take ownership of their mental health and change their lives forever. And we’re not stopping there – as the unmet need for mental health services continues to grow, BetterHelp is committed to being part of the solution.

As the Head of Security at BetterHelp, you’ll join a diverse team of licensed clinicians, engineers, product pros, creatives, marketers, and business leaders who share a passion for expanding access to therapy. And as a mental health company, we take employee mental health just as seriously as we do our mission. We deeply invest in our team’s well-being and professional development, because we know that business and individual growth go hand-in-hand. At BetterHelp, you’ll carve your own path, make an immediate impact, and be challenged every day – with a supportive community behind you the whole way.

What are we looking for?

BetterHelp is seeking a highly technical Head of Security Engineering to lead our security strategy with a strong emphasis on offensive security and attacker mindset.

This role will anchor our security organization in a red team–first approach, proactively identifying vulnerabilities and strengthening our defenses before they can be exploited. In addition to leading offensive security, you will provide oversight and strategic direction across Security Operations (blue team) and Application Security, ensuring a cohesive and effective security posture.

This is a hands-on leadership role for someone who thrives in fast-moving environments and can balance deep technical work with broader organizational impact.

What will you do?

  • Lead BetterHelp’s security engineering strategy, with offensive security as the foundation
  • Operate with a red team / attacker mindset, identifying vulnerabilities across applications, infrastructure, and internal systems
  • Direct and evolve the company’s red team capabilities, including penetration testing, code review, and vulnerability discovery
  • Provide oversight and guidance across:
  • Partner closely with Engineering to embed security into the software development lifecycle (SDLC)
  • Strengthen processes around vulnerability management, detection, and response
  • Build and improve offensive security tooling and capabilities, complementing external programs like Bugcrowd
  • Help reduce technical debt and improve system resilience through proactive security practices
  • Identify and address emerging threats, including AI security risks
  • Mentor and guide a strong team, setting a high bar for technical rigor and impact

What will you NOT do?

  • You will NOT worry about “runway”, “cash left”, or “how much time we have until the next round”. We have the startup DNA but we’re fully backed and funded, all the way to success.
  • You will NOT be confined to your “job”. You will get involved in product, marketing, business strategy, and almost everything we do.
  • You will NOT be bogged down by office politics, ego, or bad attitude. Only positive, pleasure-to-work-with people are allowed here!
  • You will NOT get yourself burned out. We work hard but we believe in maintaining a sustainable work/life balance. Really.

Can I work remotely?

Yes. We operate on PST and candidates in any time zone are welcome to apply. We ask employees to travel to our San Jose, CA office up to three times per year plus one company-wide offsite to collaborate in person and strengthen working relationships. Travel expenses are covered and reasonable accommodations are made for those under unique circumstances who cannot travel.

Requirements

  • 5+ years of security leadership experience
  • 10+ years of experience in security engineering
  • Strong background in offensive security (red team, penetration testing, or bug bounty)
  • Deep understanding of how modern systems are attacked, and how to defend against them
  • Experience working across or leading Red team, Blue team / SecOps, or Application Security
  • Experience setting strategy, managing roadmaps, and delivering measurable security outcomes across multiple teams.
  • Ability to operate both strategically and hands-on
  • Experience working in fast-paced environments with frequent releases
  • Strong communication skills with both technical and non-technical stakeholders

Benefits

  • Remote work with regular in-person bonding experiences sponsored by the company
  • Competitive compensation
  • Holistic perks program (including free therapy, employee wellness, and more)
  • Excellent health, dental, and vision coverage
  • 401k benefits with employer matching contribution
  • The chance to build something that changes lives – and that people love
  • Any piece of hardware or software that will make you happy and productive
  • An awesome community of co-workers

Bonus (Great to have, but not required)

  • Experience with AI/ML security or emerging attack vectors
  • Experience working with PHI/PII
  • Experience operating in environments with high regulatory, privacy, or customer trust requirements.
  • Experience building and operating security programs for large-scale cloud, distributed systems, or consumer platforms.
  • Experience partnering with GRC teams

The base salary range for this position is $250,000 – $300,000. In addition to the base salary, this position is eligible for a performance bonus and the extensive benefits listed here (subject to eligibility requirements): Teladoc Health Benefits 2025. Total compensation is based on several factors – including, but not limited to, type of position, location, education level, work experience, and certifications. This information is applicable to all full-time positions.

At BetterHelp we thrive on difference and individuality, and as part of the Teladoc Health family, we are proud to be an Equal Opportunity Employer. We never have and never will discriminate against any job candidate or employee due to age, race, ethnicity, religion, sex, color, national origin, gender, gender identity, sexual orientation, medical condition, marital status, parental status, disability, or Veteran status.

Notice to Candidates:
BetterHelp has been made aware of fraudulent job postings and unaffiliated third parties posing as our recruiting team – please know that we have no affiliation or connection to these situations. We only post open roles on our career page (betterhelp.com/careers) or reputable job boards like our official LinkedIn or Indeed pages, and all official BetterHelp recruitment emails will come from the domain @betterhelp.com. Our commitment is to ensure a safe and transparent hiring experience for all candidates. We will never ask you for money, gift cards, or any form of payment during our hiring process, and we will never send money or checks to candidates. If you experience this, it is a scam.

Apply now >

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Did you apply?Let us know, and we’ll help you track your application.

Continue on the employer website

Protect your personal information and never pay to secure an interview or job offer. View safety guidance.

Log in to save
One quick step before you apply

Create your free account, then apply.

Build a more organized job search on Jobicy and continue to the employer's application when you're ready.

  • Never lose a promising opportunitySave roles and return to them from your dashboard.
  • See your entire search at a glanceTrack applications, stages and next steps in one place.
  • Get matched with relevant remote jobsChoose the alerts and digests that work for you.
Applying is free. The employer's application opens in a new tab.
Add alert
Jobs Talent AI Tools Salaries
Menu