FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Head of IT, Cybersecurity
Eko Health. Own Eko's corporate IT strategy, infrastructure, and day-to-day operations, including employee endpoints, identity and access management, corporate network, cloud workplace tools, helpdesk/support, and asset management .
Posted 10/2/2026full-timeEmeryville • California • United StatesLead💰 $229,500 - $256,000 per yearWebsite
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in IT strategy, cybersecurity program management, and compliance with regulations such as HIPAA and GDPR. Proven ability to lead teams, manage budgets, and communicate technical risks effectively to diverse audiences.
Highest-signal resume keywords
IT Strategy OwnershipCybersecurity Program ManagementSOC 2 ManagementCompliance with HIPAA/HITECHIdentity and Access Management
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
CybersecurityIT Infrastructure ManagementVendor ManagementRisk ManagementIncident ResponseSecurity Awareness TrainingEndpoint ManagementCloud Workplace PlatformsEvidence CollectionControl Design
Soft Skills
Excellent Communication SkillsLeadership ExperienceExecutive Presentation Skills
Tools & Technologies
Google WorkspaceMicrosoft 365EDRMDMSSO/IdPDLP
Certifications & Qualifications
CISSPCISMCRISC
Industry Keywords
Healthcare ComplianceDigital HealthMedical Device SecurityUK/EU GDPRHITRUST
Tech Stack
Tools & technologiesCloudCyber Security
About the role
Key responsibilities & impact- Own Eko's corporate IT strategy, infrastructure, and day-to-day operations, including employee endpoints, identity and access management, corporate network, cloud workplace tools, helpdesk/support, and asset management
- Manage software and SaaS procurement, licensing, lifecycle, vendor selection, and renewal negotiations in partnership with Finance
- Own the IT budget and technology roadmap
- Build or manage the team responsible for day-to-day IT support
- Design, implement, and continuously mature Eko's corporate cybersecurity program
- Own the corporate security risk register and drive remediation of identified gaps
- Serve as Eko's primary point of contact for corporate-level security incidents
- Own SOC 2 Type I/II end to end, including scoping, control design and implementation, evidence collection, and external audit management
- Own or contribute to other corporate compliance obligations, including HIPAA/HITECH, HITRUST, CCPA, and UK/EU GDPR as applicable
- Serve as the primary liaison for customer and partner security questionnaires, vendor security due diligence, and audit committee or board reporting
- Maintain the compliance calendar for renewals, audits, and control testing
- Own timely delivery of corporate compliance and security documentation requested by customers
- Maintain a current documentation package for Sales and Customer Success
- Partner with Sales, Customer Success, and Legal on customer security calls and due-diligence sessions
- Partner with People/HR on secure onboarding, offboarding, device provisioning, and access provisioning/deprovisioning
- Partner with Legal on vendor security reviews and data processing agreements
- Partner with Product Security as a testing resource, executing tests against procedures defined by that team
Requirements
What you’ll need- Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or a related field, or equivalent practical experience
- 10+ years of experience in IT and/or cybersecurity roles, including leadership experience, ideally at a growth-stage company
- Experience in a regulated healthcare, digital health, or medical device company
- Familiarity with HIPAA/HITECH, HITRUST, or FDA cybersecurity expectations for connected devices
- Hands-on experience owning SOC 2 from scoping through audit, including evidence collection and direct management of the external auditor relationship
- Strong working knowledge of identity and access management, endpoint management, cloud workplace platforms such as Google Workspace or Microsoft 365, and modern security tooling including EDR, MDM, SSO/IdP, and DLP
- Track record of building or maturing a security program, including policies, a risk register, incident response, and security awareness training, largely from the ground up
- Excellent written, verbal, and executive presentation skills, with the ability to translate technical risk for executive and non-technical audiences
- Relevant certification such as CISSP, CISM, or CRISC is preferred
- Experience supporting compliance needs tied to international expansion, such as UK/EU GDPR, is preferred
- Must be able to perform job duties with or without reasonable accommodation
Benefits
Comp & perks- The opportunity to work on products that impact the health of millions of people
- Generous paid-time off
- Stock incentive plans
- Medical/Dental/Vision, Disability + Life Insurance
- One Medical membership
- Parental Leave
- 401k Matching
- Learning and Development stipend