What's Happening?
BetterHelp, the world's largest online therapy service, is actively recruiting a Head of Security Engineering. This leadership role is designed to anchor the company's security organization with a 'red team-first' approach, emphasizing offensive security to proactively
identify vulnerabilities. The new Head of Security Engineering will be responsible for leading BetterHelp's security engineering strategy, operating with an attacker mindset to pinpoint weaknesses across applications, infrastructure, and internal systems. Key responsibilities include directing and evolving the company’s red team capabilities, such as penetration testing, code review, and vulnerability discovery. The role also involves providing oversight and guidance across Security Operations (blue team) and Application Security, ensuring a cohesive and effective security posture. This position is a hands-on leadership role, requiring a balance of deep technical work and broader organizational impact, and aims to embed security into the software development lifecycle (SDLC) in close partnership with the engineering team. BetterHelp, a part of the Teladoc Health family, is committed to expanding access to mental health care and views robust security as integral to its mission.
Why It's Important?
The recruitment of a Head of Security Engineering with a strong offensive security focus by BetterHelp underscores the increasing importance of cybersecurity in the digital healthcare sector. As online therapy platforms handle sensitive personal health information (PHI) and personally identifiable information (PII), robust security measures are paramount to protect user data and maintain trust. A 'red team-first' approach signifies a proactive and aggressive stance against potential cyber threats, aiming to discover and remediate vulnerabilities before malicious actors can exploit them. This strategy is crucial for safeguarding patient privacy and ensuring the integrity of mental health services. The emphasis on embedding security into the software development lifecycle (SDLC) reflects a broader industry trend towards 'security by design,' where security considerations are integrated from the initial stages of development rather than being an afterthought. This move by BetterHelp could set a precedent for other telehealth providers, highlighting the necessity of advanced security practices to mitigate risks associated with data breaches and cyberattacks in a highly regulated and sensitive industry.
What's Next?
The successful candidate for the Head of Security Engineering position will be tasked with strengthening processes around vulnerability management, detection, and response, as well as building and improving offensive security tooling. This will complement existing external programs like Bugcrowd, indicating a multi-faceted approach to security. The role also involves reducing technical debt and improving system resilience through proactive security practices, and identifying and addressing emerging threats, including AI security risks. The individual will mentor and guide a security team, setting high standards for technical rigor and impact. BetterHelp's commitment to a remote work model, with regular in-person bonding experiences, suggests a flexible yet collaborative environment for this critical role. The company's ongoing efforts to enhance its security posture are likely to involve continuous adaptation to evolving cyber threats and regulatory requirements, ensuring the long-term trust and safety of its millions of users worldwide.
Beyond the Headlines
This strategic hire by BetterHelp reflects a deeper understanding within the telehealth industry of the evolving threat landscape and the critical need for advanced cybersecurity. Beyond merely reacting to threats, the adoption of an offensive security mindset signifies a shift towards anticipating and neutralizing potential attacks. This proactive approach is not just about protecting data; it's about preserving the fundamental trust users place in mental health services, where confidentiality and privacy are paramount. The integration of security into the SDLC also highlights a cultural shift, moving security from a departmental silo to a shared responsibility across engineering and product teams. This could lead to more secure and resilient digital health platforms, fostering greater confidence in virtual care. Furthermore, addressing AI security risks indicates foresight into future challenges as artificial intelligence becomes more integrated into healthcare, raising ethical and technical considerations around data bias, algorithmic fairness, and the potential for new attack vectors. This move by BetterHelp could influence industry best practices, pushing other digital health companies to adopt similar robust security frameworks.











