Boost your chances at tonal
Tailor your resume to this exact job and generate a matching cover letter in about 60 seconds with JobEase — our AI application assistant.
- ATS-optimized resume
- Personalized cover letter
- Match score & keyword gaps
Free to start · no card required
Get more other jobs in your inbox
Verified daily — no ghost listings.
About This Role
Tonal is seeking a Director of IT & Security to own the IT and security function end-to-end, with a focus on HIPAA compliance and security program management. The ideal candidate has a start-up mentality and experience in IT and security leadership. The role carries the highest privileges across sensitive systems and direct accountability for IT and security outcomes company-wide. The Director will report to the VP of Business Technology and work closely with senior leadership. The role requires a strong start-up mindset, with the ability to move fast in a lean environment while maintaining security and compliance discipline.
Key ResponsibilitiesAI-extracted
- 1Own end-to-end IT operations, including device lifecycle, onboarding/offboarding, SaaS administration, identity and access management, help desk, and office infrastructure across all locations.
- 2Lead the technical controls side of Tonal's HIPAA compliance program, implementing the safeguards required by the HIPAA Security Rule and HITECH Act.
- 3Own and execute Tonal's security program, including penetration testing remediation, security policy, tabletop exercises, vendor security reviews, and incident response.
- 4Govern Tonal's AI tool ecosystem, including licensing, spend, API key governance, corporate AI policy, and DLP and prompt injection protections.
- 5Drive automation and identity governance maturity, including Okta Identity Governance, expanding SCIM-based provisioning, building & enforcing RBAC frameworks, and driving workflow automation and system integration.
RequirementsAI-extracted
- 10+ years in IT and security leadership, with full functional ownership and experience across identity and access management, endpoint security, SaaS administration, network infrastructure, and security program management.
- Hands-on HIPAA compliance implementation experience, beyond writing policies.
- Track record of building a security program from the ground up: policy, penetration testing, and real incident response.
- Broad expertise across identity and access management, endpoint security, SaaS administration, and network infrastructure.
- Strong people leadership skills, setting clear expectations and developing team members.
Perks & BenefitsAI-extracted
Apply to This Job in Minutes
Generate ATS-optimized resume + cover letter + interview prep with Jobease.ca AI. Complete your application faster.
75% of AI Resumes Get Rejected
Beat the ATS with Jobease.ca's AI Resume Builder. Optimized for real hiring systems.
Build My ResumeProfile Match
Loading…Checking your profile against this job…
Job Overview
Share This Job
Track All Your Applications
Never lose track again. Jobease.ca organizes every application, interview, and follow-up.
Organize My Search