Lyra Health operates at the intersection of clinical care and technology, serving over 20 million people across 200+ countries and territories. The company's platform handles sensitive health data at global scale - protected health information flowing between patients, nearly 2,700 employees, and a diverse provider network that includes 1,000+ LGBTQIA+ clinicians and nearly half BIPOC representation. The threat model here is real and specific: safeguarding mental health records, session data, and clinical communications across international boundaries with varying regulatory frameworks.
The technical surface area spans platform engineering, identity and access management for a network that touches multiple continents, and the infrastructure required to deliver care that the company reports results in twice-as-fast recovery rates compared to standard approaches. Security work at this scale means protecting not just perimeter and cloud infrastructure but the trust layer between vulnerable patients and their providers. Burlingame-headquartered with operations well beyond, the company's culture signals a focus on measurable outcomes - reduced medical claims costs and transformed clinical results - which implies data-driven security metrics and a need for engineering rigor that matches the sensitivity of what's being protected.
For security professionals, the draw is a platform where the data isn't abstract - it's deeply personal health information with direct human impact. The regulatory environment (HIPAA, international equivalents), the scale of the provider network, and the technology-forward care delivery model create a complex and substantive security challenge. The company emphasizes collaboration and optimizing for impact over facetime, suggesting teams that ship and measure rather than posture.





