Head of IT & Security
Core
Lead security governance, compliance, IT operations, vendor security, and incident response for a healthcare infrastructure platform.
Role type
Senior IC Security Lead (Player-Coach)
Builds
Security governance, compliance programs, IT operations, and vendor security frameworks for a modern healthcare platform.
Domain
Healthcare technology / Cybersecurity
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Security program building from scratch, external audit management (SOC 2, HIPAA), application security, cloud security (AWS), vendor security management, incident response leadership, risk register management, privacy operations, team hiring and development
Preferred skills
Software engineering background, experience driving operational change in unmanaged functions, Board-level risk communication
Technologies
SIEM, MDR, IDS/IPS, WAF, DLP, vulnerability scanners
Responsibilities
Own security governance, compliance, and IT programs end-to-end; Serve as named Information Security Officer and Privacy Officer; Set security standards across application, vulnerability, cloud, and access controls; Build and develop the IT and workforce security program; Own vendor security lifecycle; Lead incident response and tabletop exercises; Manage risk register and privacy operations; Hire a Staff-level IT IC within year one
Seniority
Senior, hands-on IC with leadership responsibilities