Smartlinx
Lead, Cybersecurity

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Description
Since 2000, Smartlinx has been redefining how senior care organizations manage their workforce. Our modern, purpose-built solutions from dynamic scheduling and compliance to integrated payroll and real-time analytics give providers the agility and intelligence needed to thrive in today's healthcare environment.
As the parent company of BekTek (HostedTime) and StafferLink, Smartlinx brings together a wide range of solutions for managing both full-time and contingent staff. Together, these capabilities give Smartlinx the most comprehensive workforce management solution set in senior care.
We are driven by one mission: to power exceptional senior care through smarter workforce management. Join us as we shape the future of work in long-term care.
About The Role
Reporting to the Head of IT, the Lead, Cybersecurity is responsible for defining and operating Smartlinx's cybersecurity program across its multi-tenant SaaS products, cloud infrastructure, corporate technology environment, data platforms, integrations, and third-party services.
This leader owns SaaS product and application security, cloud and infrastructure security, identity and access management, vulnerability management, security monitoring, incident response, third-party risk, and SOC 2 Type II readiness and audit execution. The role is accountable for protecting sensitive healthcare workforce, payroll, personally identifiable information, and customer data while enabling reliable and timely product delivery.
The Lead, Cybersecurity will partner closely with Product, Engineering, Architecture, Quality Assurance, DevOps, Data Engineering, Corporate IT, Compliance, Legal, Customer Support, and Customer Success to integrate security into design, development, deployment, operations, and customer commitments.
Success in this role requires a hands-on, pragmatic security leader who can translate business and regulatory requirements into effective technical controls, personally investigate risk and incidents, drive remediation to closure, and communicate clearly with executives, auditors, customers, and technical teams.
Key Responsibilities
SaaS Product and Application Security
- Own the product-security strategy and operating model across the Smartlinx, BekTek (HostedTime), and StafferLink product portfolio.
- Embed security throughout the product development lifecycle, including requirements, architecture, design, development, testing, release, and production operation.
- Lead threat modeling, security architecture reviews, abuse-case analysis, and risk assessments for new products, features, APIs, integrations, mobile applications, and material platform changes.
- Establish secure coding standards and engineering guidance based on OWASP, CWE, API security, and relevant industry practices.
- Integrate automated security testing into CI/CD pipelines, including static application security testing, dynamic application security testing, software composition analysis, secrets scanning, infrastructure-as-code scanning, container scanning, and software bill of materials generation.
- Review and strengthen authentication, authorization, role-based access control, session management, tenant isolation, API security, file handling, encryption, audit logging, and secure data-export capabilities.
- Plan and coordinate independent application and API penetration testing, validate findings, assign risk-based remediation deadlines, and confirm closure through retesting.
- Assess AI-enabled product capabilities and third-party AI services for prompt injection, data leakage, tenant isolation, model access, sensitive-data handling, human oversight, and other emerging risks.
- Define proportionate release-security gates and exception processes that protect customers without creating unnecessary friction for engineering delivery.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Cloud and Infrastructure Security
- Lead security architecture and control implementation for Smartlinx's Microsoft Azure cloud environments, production and non-production infrastructure, corporate systems, endpoints, networks, and remote-work capabilities.
- Establish secure cloud baselines using recognized frameworks and vendor guidance; continuously identify and remediate configuration drift, exposed services, excessive permissions, unsupported software, and insecure defaults.
- Strengthen network security through segmentation, private connectivity, firewall and security-group governance, DDoS protection, secure administrative access, and controlled ingress and egress.
- Implement and govern secrets management, certificate management, encryption, key rotation, secure service identities, and protection of privileged credentials across applications and infrastructure.
- Partner with DevOps and Corporate IT to maintain effective patching, endpoint protection, malware defense, vulnerability scanning, cloud security posture management, and secure configuration management.
- Review the security of databases, data lakes, warehouses, analytics platforms, ETL and ELT pipelines, customer data exchanges, backups, and disaster-recovery environments.
- Ensure logging, telemetry, alerting, and forensic data are available across cloud resources, applications, identities, endpoints, networks, and data platforms to support timely detection and investigation.
- Assess resilience to destructive cyber events, including ransomware and credential compromise, and validate recoverability through protected backups, restoration tests, and cyber-recovery exercises.
SOC 2, Healthcare Compliance, and Audit Readiness
- Lead Smartlinx's SOC 2 Type II readiness, control design, evidence collection, auditor coordination, remediation, management responses, and annual attestation cycle.
- Build a continuous-control-monitoring program that keeps the organization audit-ready throughout the year rather than relying on a point-in-time preparation effort.
- Define, document, test, and improve controls across access management, change management, secure software development, vulnerability management, incident response, vendor risk, data protection, and business continuity.
- Maintain the control matrix, security policies, standards, procedures, risk register, evidence repository, exception records, remediation plans, and executive compliance reporting.
- Apply healthcare security and privacy requirements, including HIPAA and HITECH, to product, infrastructure, operational, vendor, and data-handling decisions; support business associate and customer contractual obligations.
- Evaluate alignment with NIST, CIS Controls, ISO 27001, and HITRUST expectations where they strengthen the security program or support customer and market requirements.
- Coordinate effectively with external auditors, penetration-testing providers, legal counsel, cyber-insurance partners, customers, and other independent assessors.
- Lead or support responses to customer security questionnaires, due-diligence reviews, contractual security requirements, and customer audit requests with accurate, consistent, and timely information.
Vulnerability, Risk, and Third-Party Security
- Establish a unified vulnerability-management program covering SaaS applications, APIs, cloud infrastructure, endpoints, containers, databases, open-source components, and third-party software.
- Prioritize remediation using severity, exploitability, exposure, asset criticality, data sensitivity, customer impact, compensating controls, and active-threat intelligence rather than relying on CVSS scores alone.
- Define measurable remediation service-level targets for critical, high, medium, and low-risk findings; monitor aging, exceptions, recurrence, and closure quality.
- Own formal security-risk acceptance, exception, escalation, and expiration processes, ensuring material risks receive appropriate executive visibility and approval.
- Conduct periodic enterprise, product, cloud, and data-security risk assessments and translate findings into prioritized, funded remediation roadmaps.
- Evaluate vendors, subprocessors, managed services, technology partners, and AI providers for security, privacy, resilience, data handling, incident notification, and contractual risk before onboarding and throughout the relationship.
- Monitor changes in the threat landscape, exploited vulnerabilities, attack techniques, and healthcare-sector risks; convert relevant intelligence into actionable protections and tests.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Security Operations, Incident Response, and Resilience
- Define and operate security monitoring across applications, cloud infrastructure, identities, endpoints, networks, databases, and data platforms using SIEM, EDR, WAF, and related capabilities.
- Develop high-value detection use cases for account compromise, privilege escalation, anomalous access, data exfiltration, malicious application activity, insecure configuration changes, and other material threats.
- Own the cybersecurity incident-response plan, severity model, escalation paths, on-call expectations, investigation procedures, communications protocols, evidence handling, and post-incident review process.
- Lead or coordinate containment, eradication, recovery, forensic analysis, customer-impact assessment, regulatory and contractual notification support, and executive communication during security incidents.
- Conduct regular tabletop exercises involving executive leadership, Engineering, DevOps, IT, Legal, Compliance, Customer Support, Customer Success, and Communications; document gaps and drive corrective actions to closure.
- Track and improve security operational measures such as mean time to detect, acknowledge, contain, recover, and permanently remediate incidents and recurring control failures.
- Establish relationships and operating procedures with external incident-response, forensic, legal, insurance, and specialized security partners before an incident occurs.
Identity, Data Protection, and Privacy by Design
- Establish an identity-first security model based on least privilege, multifactor authentication, privileged access management, separation of duties, conditional access, and periodic access certification.
- Strengthen joiner, mover, and leaver processes for employees, contractors, service accounts, customer support access, production access, and privileged roles.
- Define and govern security controls for Microsoft Entra ID, application identities, API credentials, machine accounts, emergency access, and third-party access.
- Partner with data owners, Product, Legal, Compliance, and Engineering to implement data classification, minimum-necessary access, encryption, masking, retention, deletion, and secure disposal.
- Protect sensitive healthcare workforce, payroll, tax, financial, personally identifiable, and authentication data throughout collection, processing, storage, transmission, sharing, export, backup, and disposal.
- Implement data-loss-prevention controls and monitoring appropriate to corporate systems, SaaS products, data platforms, collaboration tools, endpoints, and customer data-sharing workflows.
- Incorporate privacy and security by design into product decisions, integration patterns, analytics, AI use cases, customer implementations, and vendor engagements.
Security Governance, Leadership, and Performance Management
- Develop and execute
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location