Director, Information Technology & Security
Core
Lead corporate IT operations and own the end-to-end information security program for a health insurance startup, ensuring compliance with HIPAA and SOC 2 while managing infrastructure and risk.
Role type
Director, Information Technology & Information Security
Builds
Corporate IT environment, security controls, compliance posture, and a small team of IT/security professionals
Domain
Health insurance / Healthcare technology
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
IT operations management, information security program building, HIPAA compliance, SOC 2 compliance, risk management, incident response, vendor management, budget management, team leadership
Preferred skills
CISSP, CISM, CISA, CompTIA Security+, ITIL Foundation, cloud infrastructure security, IAM, endpoint security, network security, SIEM, EDR/XDR, vulnerability scanning, GRC automation
Technologies
Cloud infrastructure, IAM, EDR, SIEM, Vanta, Drata
Responsibilities
Own day-to-day IT operations including endpoint management, IAM, collaboration tools, and cloud services; Establish security governance, policies, and technical controls; Lead HIPAA and SOC 2 compliance efforts; Design risk management programs and incident response plans; Manage IT vendors, contracts, and budget; Partner with Engineering to embed security in SDLC; Build and mentor a small IT and security team
Seniority
Director, hands-on IC with team leadership