In‑House IT & Security Lead | SOC 2/HITRUST Ready

medmehealth

Toronto

Hybrid

CAD 85,000 - 110,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Health benefits
RRSP
Professional development
Work-from-Home stipend
Holiday office closure
Company retreats

Job summary

MedMe Health seeks a seasoned IT operations/security lead to build and run our in-house IT function. You will own identity, access management, device fleet, security operations, data protection, and cross-border infrastructure across two countries.

You will deploy and operate email security and endpoint detection, manage compliance with SOC 2 and HITRUST readiness, and drive automation to reduce manual work. This role is a hands-on owner position in a hybrid Toronto-based team.

Qualifications

  • 5+ years in IT operations or IT security.
  • Hands-on ownership of endpoint management and identity for a distributed team.
  • Direct experience deploying and operating email security and endpoint detection tooling.
  • Strong Google Workspace administration, including security and conditional access controls.
  • Practical networking experience: firewall, wireless, VPN, DNS, certificates.
  • Working knowledge of SOC 2, HIPAA, HITRUST, or a comparable framework, including audit evidence requirements.
  • Scripting or automation ability sufficient to build and maintain internal workflows.
  • Comfort operating as the sole owner of a function.

Responsibilities

  • Own access provisioning and deprovisioning across the SaaS environment, automating wherever it's safe to do so.
  • Administer Google Workspace, SSO, and the password manager.
  • Run access reviews to audit-ready standard, and govern contractor and offshore access against customer commitments on PHI.
  • Own the MDM platform: migration off current provider, configuration baselines, endpoint policy.
  • Manage the device fleet lifecycle end to end, procurement support, cross-border logistics, secure disposal.
  • Build endpoint controls to HITRUST-ready standard.
  • Operate email security, endpoint detection, and account protection tooling: detection tuning, alert triage.
  • Own incident response, escalation, remediation, communication, post-incident review.
  • Manage vulnerability and patch programs, external penetration testing, and security awareness training.
  • Close our current DLP gap, recommending tooling or compensating controls.
  • Own backup coverage, restore testing, and documented recovery procedures.
  • Maintain retention policies and support legal hold and discovery requests.
  • Own network, VPN, DNS, and certificate management.
  • Administer the collaboration platforms the company runs on, permissions, external sharing controls.
  • Govern AI tool adoption: sanctioned tools, data handling review, detection of unapproved use.
  • Own IT onboarding and offboarding to a consistent, documented standard.
  • Act as the point of contact for support, reducing recurring volume through automation and self-serve documentation.
  • Report monthly on service performance, endpoint compliance, spend, and open risk.
  • Gate new tooling through security and procurement review.
  • Produce audit evidence for SOC 2 and HITRUST, and support customer security questionnaires alongside Security and Legal.
  • Own the IT budget, including vendor negotiations and renewals.

Skills

IT operations
IT security
Google Workspace
Networking
SOC 2
Automation
Ownership
PHI familiarity

Tools

MDM platform
SSO
Backup tooling

Job description

MedMe Health seeks a seasoned IT operations/security lead to build and run our in-house IT function. You will own identity, access management, device fleet, security operations, data protection, and cross-border infrastructure across two countries.

You will deploy and operate email security and endpoint detection, manage compliance with SOC 2 and HITRUST readiness, and drive automation to reduce manual work. This role is a hands-on owner position in a hybrid Toronto-based team.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Tech Operations Lead — Secure, Scalable IT (Hybrid)
Tech Operations Lead — Secure, Scalable IT (Hybrid)

Ascendant • Toronto

On-site
CAD 120,000 - 180,000
Identity & Access Management Lead
Identity & Access Management Lead

Green Shield Canada (GSC) • Toronto

Hybrid
CAD 104,000 - 142,000
Remote Security & Compliance Analyst (Ontario-based)
Remote Security & Compliance Analyst (Ontario-based)

Habitat Learn Inc • Toronto

Remote
CAD 25,000 - 30,000
Remote Employment
Health Benefits
IT Operations Lead (IT & Compliance)
IT Operations Lead (IT & Compliance)

HONK • Toronto

On-site
CAD 100,000 - 150,000
Hybrid work model
Health, dental and vision coverage
IT Operations Lead (IT & Compliance)
IT Operations Lead (IT & Compliance)

HonkMobile • Toronto

On-site
CAD 110,000 - 140,000
Hybrid work in Toronto
Health, dental, vision coverage
Senior SOC 2 Audit Lead - IT Risk & Performance (Hybrid)
Senior SOC 2 Audit Lead - IT Risk & Performance (Hybrid)

Covenant HR • Toronto

Hybrid
CAD 90,000 - 120,000
IT & Cybersecurity Services Leader
IT & Cybersecurity Services Leader

Durham Community Health Centre • Oshawa

Hybrid
CAD 61,000 - 75,000
Group benefits
HOOPP
Senior Information Security & Compliance Lead
Senior Information Security & Compliance Lead

Teladoc Health • Toronto

Hybrid
CAD 175,000 - 200,000
Director - CSIRT (Cybersecurity Incident Response Team)
Director - CSIRT (Cybersecurity Incident Response Team)

KellyOCG • Montreal (administrative region)

On-site
CAD 180,000 - 230,000
Senior Analyst - Security Operations, Information & Cybersecurity
Senior Analyst - Security Operations, Information & Cybersecurity

Realign Llc • Toronto

On-site
CAD 90,000 - 120,000