Перейти к основному содержимому
Tonal

Director, IT & Security

УдалённоUnited States только
Опубликовано
Роль
Безопасность
Опыт
Лид
Занятость
Полная занятость
$178k–$220k/yr
Проверьте доступность

Доступно для: US only. Укажите, откуда вы работаете, чтобы проверить доступность.

Коротко по делу

IT and security leader with 10+ years owning IT/security functions end-to-end. Must have hands-on HIPAA implementation, security program building, IAM, endpoint security, SaaS administration, and network infrastructure experience. Austin, TX role listed as telecommute.

Ключевые навыки

HIPAAIdentity and access managementSaaS administration

Обязательные навыки

HITECHSIEMMDMEDROkta Identity GovernanceSCIMRBAC

Желательные навыки

SOC 2 Type IINIST CSFHITRUST

Чем предстоит заниматься

  • Own end-to-end IT operations, including device lifecycle, onboarding/offboarding, SaaS administration, identity and access management, help desk, and office infrastructure across all locations.
  • Lead the technical controls side of Tonal's HIPAA compliance program, implementing safeguards required by the HIPAA Security Rule and HITECH Act, including encryption, SIEM, MDM/EDR, and role-based access.
  • Own and execute Tonal's security program, including penetration testing remediation, security policy, tabletop exercises, vendor security reviews, and incident response.
  • Govern Tonal's AI tool ecosystem, including licensing, spend, API key governance, corporate AI policy, DLP, and prompt injection protections.
  • Drive AI training and best practices across the organization.
  • Administer Tonal's SaaS portfolio, owning contract renewals, license optimization, and vendor negotiations across critical platforms.
  • Drive automation and identity governance maturity, including Okta Identity Governance, SCIM-based provisioning, RBAC frameworks, workflow automation, and system integration.
  • Lead and grow the IT & Security team, managing engineers and administrators, overseeing the virtual CISO engagement, owning the budget, and aligning org structure to Tonal’s needs.
  • Own IT documentation and process improvement, maintaining runbooks and closing gaps in onboarding, offboarding, and incident response, and driving overall automation.
  • Manage global physical infrastructure, including networking, Wi-Fi, AV, and physical access, across a distributed, multi-office footprint.
  • Serve as a trusted operator on Tonal's most sensitive matters, from executive access provisioning to security incidents and legal holds.
  • Report regularly to senior leadership and the C-suite, translating IT & Security roadmap priorities, progress, technical risk, and incident management into clear, actionable narratives.

Что требуется

  • 10+ years in IT and security leadership, with full functional ownership and experience across identity and access management, endpoint security, SaaS administration, network infrastructure, and security program management.
  • Hands-on HIPAA compliance implementation experience, beyond writing policies.
  • Track record of building a security program from the ground up, including policy, penetration testing, and real incident response.
  • Broad expertise across identity and access management, endpoint security, SaaS administration, and network infrastructure.
  • Comfortable configuring technical systems and presenting security risk to executive leadership.
  • Start-up mindset and ability to thrive in fast-moving, resource-constrained environments without cutting corners on security.
  • Proven ability to prioritize with a lean team and limited budget, with outcomes to show for it.
  • Experience managing a large SaaS portfolio, including contract renewals, vendor negotiation, and license governance.
  • Strong people leadership skills, setting clear expectations and developing team members.
  • High standards of trust, integrity, and discretion, given access to the company's most sensitive systems.
  • Preferred: HIPAA compliance roll-out and execution, owning the technical controls end-to-end.
  • Preferred: Experience with SOC 2 Type II, NIST CSF, or HITRUST in a hands-on implementation capacity.
  • Preferred: Background in healthcare technology, digital health, or clinical-grade software environments.

Преимущества

  • Employee experiences designed to contribute to your growth.
  • Accommodation requests for people with disabilities can be made via confidential email.

municipality in the State of Chiapas, Mexico

Fitness
$178k–$220k/yr