Head of Security Engineering (Red Team) at BetterHelp | Torre

Head of Security Engineering (Red Team)

Emma highlights
This highlight was written by Emma’s AI. Ask Emma to edit it.
Full-time

Legal agreement: Employment

Provide your expected compensation while applying
location_on
Remote (for United States residents)
Shared by
Emma of Torre.ai
5 days ago

Responsibilities


BetterHelp is on a mission to remove the traditional barriers to therapy and make mental health care more accessible to everyone. Founded in 2013, we are now the world’s largest online therapy service, providing affordable and convenient therapy across the globe.BetterHelp is seeking a highly technical Head of Security Engineering to lead our security strategy with a strong emphasis on offensive security and attacker mindset.This role will anchor our security organization in a red team–first approach, proactively identifying vulnerabilities and strengthening our defenses before they can be exploited. In addition to leading offensive security, you will provide oversight and strategic direction across Security Operations (blue team) and Application Security, ensuring a cohesive and effective security posture.This is a hands-on leadership role for someone who thrives in fast-moving environments and can balance deep technical work with broader organizational impact.What will you do?Lead BetterHelp’s security engineering strategy, with offensive security as the foundationOperate with a red team / attacker mindset, identifying vulnerabilities across applications, infrastructure, and internal systemsDirect and evolve the company’s red team capabilities, including penetration testing, code review, and vulnerability discoveryProvide oversight and guidance across:Partner closely with Engineering to embed security into the software development lifecycle (SDLC)Strengthen processes around vulnerability management, detection, and responseBuild and improve offensive security tooling and capabilities, complementing external programs like BugcrowdHelp reduce technical debt and improve system resilience through proactive security practicesIdentify and address emerging threats, including AI security risksMentor and guide a strong team, setting a high bar for technical rigor and impactWhat will you NOT do?You will NOT worry about "runway", "cash left", or "how much time we have until the next round". We have the startup DNA but we're fully backed and funded, all the way to success.You will NOT be confined to your "job". You will get involved in product, marketing, business strategy, and almost everything we do.You will NOT be bogged down by office politics, ego, or bad attitude. Only positive, pleasure-to-work-with people are allowed here!You will NOT get yourself burned out. We work hard but we believe in maintaining a sustainable work/life balance. Really.Can I work remotely?Yes. We operate on PST and candidates in any time zone are welcome to apply. We ask employees to travel to our San Jose, CA office up to three times per year plus one company-wide offsite to collaborate in person and strengthen working relationships. Travel expenses are covered and reasonable accommodations are made for those under unique circumstances who cannot travel.Requirements5+ years of security leadership experience10+ years of experience in security engineeringStrong background in offensive security (red team, penetration testing, or bug bounty)Deep understanding of how modern systems are attacked, and how to defend against themExperience working across or leading Red team, Blue team / SecOps, or Application SecurityExperience setting strategy, managing roadmaps, and delivering measurable security outcomes across multiple teams.Ability to operate both strategically and hands-onExperience working in fast-paced environments with frequent releasesStrong communication skills with both technical and non-technical stakeholdersBenefitsRemote work with regular in-person bonding experiences sponsored by the companyCompetitive compensationHolistic perks program (including free therapy, employee wellness, and more)Excellent health, dental, and vision coverage401k benefits with employer matching contributionThe chance to build something that changes lives – and that people loveAny piece of hardware or software that will make you happy and productiveAn awesome community of co-workersBonus (Great to have, but not required)Experience with AI/ML security or emerging attack vectorsExperience working with PHI/PIIExperience operating in environments with high regulatory, privacy, or customer trust requirements.Experience building and operating security programs for large-scale cloud, distributed systems, or consumer platforms.Experience partnering with GRC teamsThe base salary range for this position is $250,000 - $300,000. In addition to the base salary, this position is eligible for a performance bonus and the extensive benefits listed here (subject to eligibility requirements). Total compensation is based on several factors – including, but not limited to, type of position, location, education level, work experience, and certifications. This information is applicable to all full-time positions.