Назад
Company hidden
3 дня назад

Head of IT & Cybersecurity

Формат работы
hybrid
Тип работы
fulltime
Грейд
head
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Head of IT & Cybersecurity (Healthcare AI/MedTech): Owning corporate IT operations, cybersecurity governance, SOC 2 compliance, and customer security documentation for an FDA-cleared digital health company with an accent on regulated healthcare security and end-to-end program ownership. Focus on building secure IT infrastructure, managing risk and incidents, leading audits, and translating technical security posture for executives, auditors, and health-system customers.

Location: Emeryville, California, United States; hybrid role with in-office days on Tuesday, Wednesday, and Thursday.

Company

hirify.global Health develops FDA-cleared AI-powered stethoscopes and digital health tools that help clinicians detect cardiac and pulmonary disease.

What you will do

  • Own corporate IT strategy, infrastructure, endpoints, identity and access management, network, workplace tools, helpdesk, and asset management.
  • Manage SaaS procurement, licensing, vendor relationships, the IT budget, technology roadmap, and the internal or outsourced IT support team.
  • Build and continuously mature the corporate cybersecurity program, including policies, endpoint and email security, DLP, identity governance, security awareness, and incident response.
  • Own the security risk register and coordinate investigation, containment, communication, and post-incident reviews for corporate security incidents.
  • Lead SOC 2 Type I/II activities from scoping and control implementation through evidence collection and external audit management.
  • Provide security documentation and technical support for health-system procurement, customer due diligence, audits, and security calls.

Requirements

  • 10+ years of experience in IT and/or cybersecurity, including leadership experience.
  • Experience in regulated healthcare, digital health, or medical device environments, with knowledge of HIPAA/HITECH, HITRUST, or FDA cybersecurity expectations.
  • Hands-on ownership of SOC 2 from scoping through audit, including evidence collection and external auditor management.
  • Strong knowledge of identity and access management, endpoint management, cloud workplace platforms, EDR, MDM, SSO/IdP, and DLP.
  • Experience building or maturing security programs, including policies, risk registers, incident response, and security awareness training.
  • Bachelor's degree in IT, Computer Science, Cybersecurity, or a related field, or equivalent practical experience.

Nice to have

  • CISSP, CISM, or CRISC certification.
  • Experience supporting international compliance requirements such as UK/EU GDPR.

Culture & Benefits

  • Mission-driven work focused on improving cardiac and pulmonary care.
  • Paid time off, parental leave, and medical, dental, vision, disability, and life insurance.
  • Stock incentive plans, 401(k) matching, and One Medical membership.
  • Learning and development stipend.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →