TO

Director, IT & Security

tonal· 28 open roles

Remote RemoteFullTime1 months ago
Salaryest.
$150,000 - $250,000
Experience
Mid
Job Type
FullTime
Posted
1 months ago
Apply Now

Boost your chances at tonal

Tailor your resume to this exact job and generate a matching cover letter in about 60 seconds with JobEase — our AI application assistant.

  • ATS-optimized resume
  • Personalized cover letter
  • Match score & keyword gaps
Tailor my application

Free to start · no card required

Get more other jobs in your inbox

Verified daily — no ghost listings.

About This Role

Tonal is seeking a Director of IT & Security to own the IT and security function end-to-end, with a focus on HIPAA compliance and security program management. The ideal candidate has a start-up mentality and experience in IT and security leadership. The role carries the highest privileges across sensitive systems and direct accountability for IT and security outcomes company-wide. The Director will report to the VP of Business Technology and work closely with senior leadership. The role requires a strong start-up mindset, with the ability to move fast in a lean environment while maintaining security and compliance discipline.

Key ResponsibilitiesAI-extracted

  • 1
    Own end-to-end IT operations, including device lifecycle, onboarding/offboarding, SaaS administration, identity and access management, help desk, and office infrastructure across all locations.
  • 2
    Lead the technical controls side of Tonal's HIPAA compliance program, implementing the safeguards required by the HIPAA Security Rule and HITECH Act.
  • 3
    Own and execute Tonal's security program, including penetration testing remediation, security policy, tabletop exercises, vendor security reviews, and incident response.
  • 4
    Govern Tonal's AI tool ecosystem, including licensing, spend, API key governance, corporate AI policy, and DLP and prompt injection protections.
  • 5
    Drive automation and identity governance maturity, including Okta Identity Governance, expanding SCIM-based provisioning, building & enforcing RBAC frameworks, and driving workflow automation and system integration.

RequirementsAI-extracted

  • 10+ years in IT and security leadership, with full functional ownership and experience across identity and access management, endpoint security, SaaS administration, network infrastructure, and security program management.
  • Hands-on HIPAA compliance implementation experience, beyond writing policies.
  • Track record of building a security program from the ground up: policy, penetration testing, and real incident response.
  • Broad expertise across identity and access management, endpoint security, SaaS administration, and network infrastructure.
  • Strong people leadership skills, setting clear expectations and developing team members.

Perks & BenefitsAI-extracted

Typically: health coverage.
Typically: paid time off.
Typically: opportunities for professional growth and development.
Typically: access to cutting-edge technology and tools.
Typically: a dynamic and supportive work environment.

Apply to This Job in Minutes

Generate ATS-optimized resume + cover letter + interview prep with Jobease.ca AI. Complete your application faster.

Get Started Free

Similar Jobs

RE

Client Account Manager, Large Customer Sales (Retail Beauty)

redditNew York City, NY
View
RE

Client Account Manager, Large Customer Sales (Financial Services)

redditNew York City, NY
View
RE

Machine Learning Engineer, Ads Optimization

redditRemote
View