This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
As our new IT Security & Operations Lead, you will take hands-on ownership of critical IT security and operations projects. You will be responsible for executing projects like our HIPAA Risk Assessment and driving our current Google Workspace security remediation plan. Long-term, you will drive high-impact technology projects ranging from Data Loss Prevention (DLP), deploying enterprise password management tools, to the technical oversight of our application security intake and third-party vendor risk assessment process. You will serve as a strategic partner to business stakeholders to identify and deploy tools that enhance productivity—such as AI or clinical workflow apps—while providing the technical judgment to ensure every rollout is architected safely and remains compliant with our security standards. You will be joining a lean, highly effective IT team that reports directly to the Senior Manager of IT & Data Analytics.
Job Responsibility:
Spearhead our annual HIPAA Risk Assessment and lead related remediation activities
Take ownership of our existing Google Workspace security audit findings
Drive remediation projects to completion by managing our MSP's execution and handling the critical configurations that require our internal business context
Be a key contributor to our strategy
In partnership with the Senior Manager of IT & Data Analytics, be responsible for developing, implementing, and maintaining information security policies, standards, and procedures, including the AI Usage Policy and the Disaster Recovery Plan
Serve as the hands-on project lead for key initiatives
Own the intake and security review process for new business applications, Google Workspace add-ons, and third-party vendors
Conduct security assessments to determine if a vendor or tool meets our standards before it is introduced to our environment
Act as a primary technical point of contact for our security partners and our MSP
Coordinate penetration tests and cloud security assessments
Lead end-to-end change management strategy (communications, training, and stakeholder engagement) for new technology implementations
Contribute to the overall IT cybersecurity strategy and technical roadmap
Proactively monitor and stay informed about new security threats, vulnerabilities, and technologies pertinent to the organization
Requirements:
Bachelor’s degree in a field related to technology or cybersecurity, or equivalent practical experience
Minimum 3 years of proven hands-on experience personally executing complex technical projects (e.g., system configurations, security audits) required
Direct, practical experience with HIPAA required
Must be able to demonstrate strong knowledge of cybersecurity related control frameworks such as NIST, HIPAA, CIS Critical Security Controls, and ISO 27001
Demonstrable experience building and executing change management plans to drive user adoption, including measuring success post-launch
Advanced proficiency in Google Workspace administration - including the admin console, security configurations, and permission structures
Ability to identify and prioritize security enhancements that provide maximum organizational protection while minimizing operational friction for clinical and administrative staff
Strong communication skills and a demonstrated ability to communicate complex technical risks and security objectives to non-technical stakeholders
Demonstrated ability to lead MSPs and security partners on specific project deliverables