Head of IT & Security
Core
Building and leading the security governance, compliance, and IT operations function for a healthcare infrastructure platform, ensuring SOC 2/HIPAA compliance and managing vendor risk.
Role type
Security Lead / Head of IT & Security (Player-coach)
Builds
Security program, compliance artifacts, incident response capabilities, and IT security infrastructure for a healthcare data platform.
Domain
Healthcare Technology / HealthTech Infrastructure
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Security program building from scratch, external audit management (SOC 2, HIPAA), cloud security (AWS), vendor security assessment, incident response leadership, team hiring and development, risk register management, privacy operations (DSARs), software engineering background.
Preferred skills
Hands-on experience with SIEM, MDR, IDS/IPS, WAF, DLP, vulnerability scanners, ability to influence engineering teams without direct authority, Board-level risk communication.
Technologies
AWS, SIEM, MDR, IDS/IPS, WAF, DLP, vulnerability scanners
Responsibilities
Own security governance, compliance, and IT programs end-to-end; Serve as named Information Security Officer and Privacy Officer; Set security standards across application, cloud, and access controls; Build and develop the IT and workforce security program; Own vendor security intake and assessment; Lead incident response and tabletop exercises; Manage risk register and privacy operations; Hire a Staff-level IT IC.
Seniority
Senior, hands-on IC building a function