[![Image]() Meet Jobicy Copilot — free AI autofill for job applications + remote job alerts ›](#)   [All remote jobs](https://jobicy.com/jobs.md)Open role[![BetterHelp logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/0b48fde8-221.jpeg)](https://jobicy.com/company/betterhelp.md)Remote opportunity at[BetterHelp](https://jobicy.com/company/betterhelp.md)

# Head of Security Engineering

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

[Apply for this job](#job-application)[View company](https://jobicy.com/company/betterhelp.md)Share13 Sep 2026Published52Listing views4Application actions13 Oct 2026Apply before  Opportunity details

## About this role.

AI SummaryBetterHelp is hiring a hands-on Head of Security Engineering to set and lead its security strategy, centered on a red-team-first and attacker-minded approach. The leader will direct offensive security capabilities such as penetration testing, code review, vulnerability discovery, and security tooling while overseeing SecOps and application security. This role partners closely with engineering to embed security in the SDLC, improve vulnerability management and incident response, and reduce technical debt across cloud and distributed systems. The ideal candidate brings extensive security engineering and leadership experience, can operate strategically and tactically, and communicates effectively with both technical and business stakeholders.

## Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

### Job Complexity

5/5EasyHard

### Pace & Pressure

5/5RelaxedFast-paced

### Autonomy Level

5/5GuidedFull ownership

### Communication Load

5/5IndependentCollaborative

AI insightThis is a senior security leadership role requiring more than 10 years of security engineering experience and at least 5 years of leadership experience. It combines deep offensive-security expertise with broad responsibility for organizational strategy, cross-functional execution, and oversight of multiple security disciplines in a fast-release environment.

## Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianMarket rate$275,000US market range$240k–$330k0$363k

AI insightThe disclosed base salary range is $250,000–$300,000 USD yearly, producing an offer median of $275,000. For a US-based Head of Security Engineering with substantial offensive-security, cloud, application-security, and people-leadership scope, an estimated US base-salary market range is $240,000–$330,000 annually; bonus, equity, and benefits may increase total compensation.

## Core skills

Skills and capabilities most closely associated with this opportunity.

[Security engineering leadership](https://jobicy.com/jobs?search_keywords=Security%20engineering%20leadership.md)[Offensive security](https://jobicy.com/jobs?search_keywords=Offensive%20security.md)[Red teaming](https://jobicy.com/jobs?search_keywords=Red%20teaming.md)[Penetration testing](https://jobicy.com/jobs?search_keywords=Penetration%20testing.md)[Application security](https://jobicy.com/jobs?search_keywords=Application%20security.md)[Security operations](https://jobicy.com/jobs?search_keywords=Security%20operations.md)[Vulnerability management](https://jobicy.com/jobs?search_keywords=Vulnerability%20management.md)[Secure SDLC](https://jobicy.com/jobs?search_keywords=Secure%20SDLC.md)[Cloud security](https://jobicy.com/jobs?search_keywords=Cloud%20security.md)[AI security](https://jobicy.com/jobs?search_keywords=AI%20security.md)

Sample interview questionsHow would you establish a red-team-first security strategy while maintaining productive relationships with engineering teams?I would align testing to the company’s most critical assets and realistic threat scenarios, then turn findings into risk-ranked, actionable engineering work. I would define clear remediation ownership, SLAs, and recurring reviews, while emphasizing that offensive testing is a tool for learning and resilience rather than a punitive exercise.

Describe how you would prioritize vulnerabilities discovered across applications, cloud infrastructure, and internal systems.

I would prioritize based on exploitability, exposure, asset criticality, data sensitivity, potential business impact, and the availability of compensating controls. A continuously maintained asset inventory and risk model would support consistent decisions, with critical internet-facing or PHI/PII-related findings receiving immediate attention and executive visibility.

What metrics would you use to demonstrate that the security engineering program is improving?

I would track time to detect and remediate critical findings, vulnerability recurrence, coverage of threat modeling and secure-code controls, remediation SLA attainment, penetration-test findings by severity, and incident trends. I would pair these operational measures with outcome-oriented reporting that shows reduced exposure across the highest-risk systems.

How would you embed security into a fast-moving software development lifecycle without creating excessive friction?

I would automate high-signal controls in CI/CD, provide secure defaults and reusable security patterns, and engage security champions within engineering teams. Threat modeling and design reviews would focus on high-risk changes, while clear self-service guidance and rapid security consultation would help teams ship securely at speed.

How would you approach emerging AI security risks at BetterHelp?

I would begin with an inventory of AI use cases, data flows, models, vendors, and permissions, then conduct threat modeling for risks such as prompt injection, data leakage, model abuse, insecure integrations, and supply-chain exposure. Controls would include data-governance guardrails, adversarial testing, monitoring, access restrictions, vendor assessments, and incident playbooks tailored to AI-enabled systems.

### Who are we and why should you join us?

BetterHelp is on a mission to remove the traditional barriers to therapy and make mental health care more accessible to everyone. Founded in 2013, we are now the world’s largest online therapy service, providing affordable and convenient therapy across the globe. Our network of over 30,000 licensed therapists has helped millions of people take ownership of their mental health and change their lives forever. And we’re not stopping there – as the unmet need for mental health services continues to grow, BetterHelp is committed to being part of the solution.

As the Head of Security at BetterHelp, you’ll join a diverse team of licensed clinicians, engineers, product pros, creatives, marketers, and business leaders who share a passion for expanding access to therapy. And as a mental health company, we take employee mental health just as seriously as we do our mission. We deeply invest in our team’s well-being and professional development, because we know that business and individual growth go hand-in-hand. At BetterHelp, you’ll carve your own path, make an immediate impact, and be challenged every day – with a supportive community behind you the whole way.

### What are we looking for?

BetterHelp is seeking a highly technical Head of Security Engineering to lead our security strategy with a strong emphasis on offensive security and attacker mindset.

This role will anchor our security organization in a red team–first approach, proactively identifying vulnerabilities and strengthening our defenses before they can be exploited. In addition to leading offensive security, you will provide oversight and strategic direction across Security Operations (blue team) and Application Security, ensuring a cohesive and effective security posture.

This is a hands-on leadership role for someone who thrives in fast-moving environments and can balance deep technical work with broader organizational impact.

### What will you do?

* Lead BetterHelp’s security engineering strategy, with offensive security as the foundation
* Operate with a red team / attacker mindset, identifying vulnerabilities across applications, infrastructure, and internal systems
* Direct and evolve the company’s red team capabilities, including penetration testing, code review, and vulnerability discovery
* Provide oversight and guidance across:
* Partner closely with Engineering to embed security into the software development lifecycle (SDLC)
* Strengthen processes around vulnerability management, detection, and response
* Build and improve offensive security tooling and capabilities, complementing external programs like Bugcrowd
* Help reduce technical debt and improve system resilience through proactive security practices
* Identify and address emerging threats, including AI security risks
* Mentor and guide a strong team, setting a high bar for technical rigor and impact

### What will you NOT do?

* You will NOT worry about “runway”, “cash left”, or “how much time we have until the next round”. We have the startup DNA but we’re fully backed and funded, all the way to success.
* You will NOT be confined to your “job”. You will get involved in product, marketing, business strategy, and almost everything we do.
* You will NOT be bogged down by office politics, ego, or bad attitude. Only positive, pleasure-to-work-with people are allowed here!
* You will NOT get yourself burned out. We work hard but we believe in maintaining a sustainable work/life balance. Really.

### Can I work remotely?

Yes. We operate on PST and candidates in any time zone are welcome to apply. We ask employees to travel to our San Jose, CA office up to three times per year plus one company-wide offsite to collaborate in person and strengthen working relationships. Travel expenses are covered and reasonable accommodations are made for those under unique circumstances who cannot travel.

### Requirements

* 5+ years of security leadership experience
* 10+ years of experience in security engineering
* Strong background in offensive security (red team, penetration testing, or bug bounty)
* Deep understanding of how modern systems are attacked, and how to defend against them
* Experience working across or leading Red team, Blue team / SecOps, or Application Security
* Experience setting strategy, managing roadmaps, and delivering measurable security outcomes across multiple teams.
* Ability to operate both strategically and hands-on
* Experience working in fast-paced environments with frequent releases
* Strong communication skills with both technical and non-technical stakeholders

### Benefits

* Remote work with regular in-person bonding experiences sponsored by the company
* Competitive compensation
* Holistic perks program (including free therapy, employee wellness, and more)
* Excellent health, dental, and vision coverage
* 401k benefits with employer matching contribution
* The chance to build something that changes lives – and that [people love](https://www.betterhelp.com/reviews/)
* Any piece of hardware or software that will make you happy and productive
* An awesome community of co-workers

Bonus (Great to have, but not required)

* Experience with AI/ML security or emerging attack vectors
* Experience working with PHI/PII
* Experience operating in environments with high regulatory, privacy, or customer trust requirements.
* Experience building and operating security programs for large-scale cloud, distributed systems, or consumer platforms.
* Experience partnering with GRC teams

The base salary range for this position is $250,000 – $300,000. In addition to the base salary, this position is eligible for a performance bonus and the extensive benefits listed here (subject to eligibility requirements): [Teladoc Health Benefits 2025](https://s3.amazonaws.com/images.teladoc.com/aem_assets/documents/Teladoc-Health-2026-BAAG-Recruiting.pdf). Total compensation is based on several factors – including, but not limited to, type of position, location, education level, work experience, and certifications. This information is applicable to all full-time positions.

At BetterHelp we thrive on difference and individuality, and as part of the Teladoc Health family, we are proud to be an Equal Opportunity Employer. We never have and never will discriminate against any job candidate or employee due to age, race, ethnicity, religion, sex, color, national origin, gender, gender identity, sexual orientation, medical condition, marital status, parental status, disability, or Veteran status.

Notice to Candidates:
BetterHelp has been made aware of fraudulent job postings and unaffiliated third parties posing as our recruiting team – please know that we have no affiliation or connection to these situations. We only post open roles on our career page ([betterhelp.com/careers](http://betterhelp.com/careers)) or reputable job boards like our official[LinkedIn](https://www.linkedin.com/company/betterhelp/jobs/) or[Indeed](https://www.indeed.com/jobs?q=BetterHelp&l=remote&from=searchOnHP%2Cwhatautocomplete%2CwhatautocompleteSourceStandard&vjk=b0bfe5fb85c831a5) pages, and all official BetterHelp recruitment emails will come from the domain @[betterhelp.com](http://betterhelp.com/). Our commitment is to ensure a safe and transparent hiring experience for all candidates. We will never ask you for money, gift cards, or any form of payment during our hiring process, and we will never send money or checks to candidates. If you experience this, it is a scam.

Show more

[Apply now >](https://jobicy.com/jobs/153174-head-of-security-engineering.md)

*

![Upload CV](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NSIgaGVpZ2h0PSI2NSIgZmlsbD0ibm9uZSIgeG1sbnM6dj0iaHR0cHM6Ly92ZWN0YS5pby9uYW5vIj48ZyBjbGlwLXBhdGg9InVybCgjQSkiPjxwYXRoIGQ9Ik0wIDBINjVWNjVIMFYwWiIgZmlsbD0iIzAyOWFlYiIvPjxnIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2ZmZiIgc3Ryb2tlLXdpZHRoPSIyIj48cGF0aCBkPSJNMzMuMDQ5IDE1LjQ1NGExLjQzIDEuNDMgMCAwIDAtMi4wOTcgMGwtNy41NzkgOC4xNDdhMS4zOCAxLjM4IDAgMCAwIC4wOSAxLjk3MyAxLjQ0IDEuNDQgMCAwIDAgMi4wMDgtLjA4OGw1LjEwOS01LjQ5MnYyMC42MWExLjQxIDEuNDEgMCAwIDAgMS40MjEgMS4zOTdjLjc4NSAwIDEuNDIxLS42MjUgMS40MjEtMS4zOTd2LTIwLjYxbDUuMTA5IDUuNDkyYTEuNDQgMS40NCAwIDAgMCAyLjAwOC4wODggMS4zOCAxLjM4IDAgMCAwIC4wOS0xLjk3M2wtNy41NzktOC4xNDZ6TTE2Ljc2OSAzOC40YzAtLjc3My0uNjItMS40LTEuMzg1LTEuNFMxNCAzNy42MjcgMTQgMzguNHYuMTAybC4yMTUgNi4yMjljLjIyMyAxLjY4LjcwMSAzLjA5NSAxLjgxMyA0LjIxOHMyLjUxIDEuNjA3IDQuMTcyIDEuODMzYzEuNi4yMTggMy42MzYuMjE4IDYuMTYuMjE4aDExLjI4bDYuMTYtLjIxOGMxLjY2Mi0uMjI2IDMuMDYxLS43MDkgNC4xNzItMS44MzNzMS41ODktMi41MzggMS44MTMtNC4yMThDNTAgNDMuMTEzIDUwIDQxLjA1NSA1MCAzOC41MDNWMzguNGMwLS43NzMtLjYyLTEuNC0xLjM4NS0xLjRzLTEuMzg1LjYyNy0xLjM4NSAxLjRsLS4xOSA1Ljk1OGMtLjE4MiAxLjM3LS41MTUgMi4wOTUtMS4wMjYgMi42MTJzLTEuMjI4Ljg1My0yLjU4MyAxLjAzOGMtMS4zOTUuMTktMy4yNDMuMTkzLTUuODkzLjE5M0gyNi40NjJjLTIuNjUgMC00LjQ5OC0uMDAzLTUuODkzLS4xOTMtMS4zNTUtLjE4NC0yLjA3Mi0uNTIxLTIuNTgzLTEuMDM4cy0uODQ0LTEuMjQyLTEuMDI2LTIuNjEyYy0uMTg3LTEuNDEtLjE5MS0zLjI3OS0uMTkxLTUuOTU4eiIvPjwvZz48L2c+PGRlZnM+PGNsaXBQYXRoIGlkPSJBIj48cGF0aCBmaWxsPSIjZmZmIiBkPSJNMCAwaDY1djY1SDB6Ii8+PC9jbGlwUGF0aD48L2RlZnM+PC9zdmc+)

### Upload your resume now

To unlock remote work opportunities and be discovered by global employers.

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

## Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Keep exploring

## Related remote jobs.

Matched by job category10 related opportunities[Cybersecurity](https://jobicy.com/categories/cybersecurity.md) [Browse all jobs](https://jobicy.com/jobs.md)
*
![Deloitte logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/09/370c2482dacb3fffbd4043cfca5674fe.png)
Deloitte  Sep 13

### [Manager, Cyber Compliance, Deloitte Global Technology](https://jobicy.com/jobs/150563-manager-cyber-compliance-deloitte-global-technology.md)

Job Type: Permanent Work Model: Remote Reference code: 134501 Primary Location: Toronto, ON All Available Locations: Toronto, ON   Our Purpose   At Deloitte, our Purpose is to make an impact that matters. We exist to inspire…

*
![1Password logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/09/WRILS-200909195848-296323.png)
1Password  Sep 12

### [Manager, Security Incident Response](https://jobicy.com/jobs/153123-manager-security-incident-response.md)

1Password is growing. We’ve surpassed $400M in ARR and we’re continuing to accelerate, earning a spot on the Forbes Cloud 100 for four years in a row and teaming up…

*
![Sporty Group logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/8e6c246a-221.png)
Sporty Group  Sep 12

### [Offensive Security Engineer](https://jobicy.com/jobs/149060-offensive-security-engineer.md)

About the roleMission Strengthen Sporty’s offensive security posture by proactively testing and identifying vulnerabilities across our external perimeter, standalone virtual private servers (VPS), physical office infrastructure, and endpoint defenses. The…

*
![Rithum logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/fe3986d8-221-1.jpeg)
Rithum  Sep 12

### [Staff Information Security Engineer – AI First](https://jobicy.com/jobs/153112-staff-information-security-engineer-ai-first.md)

Rithum™ is the world’s most trusted commerce network, accelerating how brands, suppliers, and retailers work together to deliver seamless e-commerce experiences. We provide an unmatched platform for brands and retailers,…

*
![Liftoff logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/c47aea9f-221.png)
Liftoff  Sep 12

### [Security Engineer, Detection & Response](https://jobicy.com/jobs/153102-security-engineer-detection-response.md)

Liftoff is a leading AI-powered performance marketing platform for the mobile app economy. Our end-to-end technology stack helps app marketers acquire and retain high-value users, while enabling publishers to maximize…

*
![Stripe logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/10/WRILS-201011073943-272457.png)
Stripe  Sep 11

### [Abuse Research Engineer](https://jobicy.com/jobs/153053-abuse-research-engineer.md)

Who we are About Stripe Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow…

*
![Ping Identity logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/09/63e8d5a6-221.png)
Ping Identity  Sep 11

### [Cyber Security Engineer II](https://jobicy.com/jobs/153056-cyber-security-engineer-ii.md)

About Ping Identity: At Ping Identity, we believe in making digital experiences both secure and seamless for all users, without compromise. We call this digital freedom. And it’s not just…

*
![Luna Physical Therapy logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/07/fcb34e841928-221.webp)
Luna Physical Therapy  Sep 11

### [Director , Information Security and IT](https://jobicy.com/jobs/153041-director-information-security-and-it.md)

Luna is seeking a Director of Information Security & IT to lead the strategy, execution, and continuous evolution of the company’s enterprise technology and information security programs. Reporting to the…

*
![CertiK logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/03/Jobicy-210308091023-955845.jpg)
CertiK  Sep 10

### [Blockchain Security Expert Intern – AI Track](https://jobicy.com/jobs/152979-blockchain-security-expert-intern-ai-track.md)

About the Company Founded in 2018 by professors of Yale University and Columbia University, CertiK is a pioneer in blockchain security, utilizing best-in-class AI technology to secure and monitor blockchain…

*
![CertiK logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/03/Jobicy-210308091023-955845.jpg)
CertiK  Sep 10

### [Blockchain Security Expert – Security Audit Track](https://jobicy.com/jobs/152975-blockchain-security-expert-security-audit-track.md)

About You You’re a self-starter. You believe in tackling the most important problems, even if they are the most difficult problems. You’re comfortable with the unknown and understand that #startuplife…