IT Manager

RXinsider LTD.

Toronto

Hybrid

CAD 85,000 - 110,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health Benefits
RRSP
Professional Development
Work-from-Home Stipend
Office Closure for Holidays
Company Retreats

Job summary

MedMe Health is building an in-house IT and security function to support our growing team. This is the first dedicated IT hire, owning architecture and day-to-day operations across identity, devices, security, and compliance in a two-country footprint.

You will implement and evolve tooling, run access controls, manage MDM and email security, and drive SOC 2 toward HITRUST readiness with vendors and cross-border considerations.

Qualifications

  • 5+ years in IT operations or IT security, with hands-on ownership of endpoint management and identity for a distributed team
  • Direct experience deploying and operating email security and endpoint detection tooling
  • Strong Google Workspace administration, including security and conditional access controls
  • Practical networking experience: firewall, wireless, VPN, DNS, certificates
  • Working knowledge of SOC 2, HIPAA, HITRUST, or a comparable framework, including audit evidence requirements
  • Scripting or automation ability sufficient to build and maintain internal workflows
  • Comfort operating as the sole owner of a function
  • Nice to Have: Healthcare or another regulated environment handling PHI or PII; HITRUST readiness or certification experience; Vanta or comparable compliance automation; Multi-entity or cross-border operations

Responsibilities

  • Identity and access — Own access provisioning and deprovisioning across the SaaS environment, automating wherever it's safe to do so
  • Administer Google Workspace, SSO, and the password manager
  • Run access reviews to audit-ready standard, and govern contractor and offshore access against our customer commitments on PHI
  • Devices and endpoints — Own the MDM platform: migration off our current provider, configuration baselines, endpoint policy
  • Manage the device fleet lifecycle end to end, procurement support, cross-border logistics, secure disposal
  • Build endpoint controls to HITRUST-ready standard
  • Security operations — Operate email security, endpoint detection, and account protection tooling: detection tuning, alert triage
  • Own incident response, escalation, remediation, communication, post-incident review
  • Manage vulnerability and patch programs, external penetration testing, and security awareness training
  • Data protection and resilience — Close our current DLP gap, recommending tooling or compensating controls
  • Own backup coverage, restore testing, and documented recovery procedures
  • Maintain retention policies and support legal hold and discovery requests
  • Infrastructure and workplace technology — Own network, VPN, DNS, and certificate management
  • Administer the collaboration platforms the company runs on, permissions, external sharing controls
  • Govern AI tool adoption: sanctioned tools, data handling review, detection of unapproved use
  • Service delivery — Own IT onboarding and offboarding to a consistent, documented standard
  • Act as the point of contact for support, reducing recurring volume through automation and self-serve documentation
  • Report monthly on service performance, endpoint compliance, spend, and open risk
  • Compliance and vendor management — Gate new tooling through security and procurement review
  • Produce audit evidence for SOC 2 and HITRUST, and support customer security questionnaires alongside Security and Legal
  • Own the IT budget, including vendor negotiations and renewals

Skills

IT operations
IT security
Email security tooling
Endpoint detection tooling
Google Workspace administration
Scripting or automation
PHI/PII handling

Tools

Google Workspace
SSO
Password manager
Endpoint protection tools
MDR tools

Job description

The Opportunity

MedMe is building out a dedicated, in-house IT and internal security function to support our growing team. You'll step into a role with established tooling and processes already in place across device management, endpoint detection, email security, and access automation, and will take ownership of operating and evolving this function going forward. This is our first dedicated IT hire. You'll inherit a stack to deploy, a fleet across two countries, and a compliance path running from SOC 2 toward HITRUST. The role combines architecture and execution: you'll design how IT works here and also be the one running it day to day.

About MedMe Health

At MedMe, we are passionate about empowering pharmacists to provide services beyond just prescribing. Our mission is to build an all-in-one cloud-based platform that enables pharmacists to schedule, document, and manage clinical services at scale. With over 4,500 pharmacies using our software, we've facilitated more than 25 million patient services, transforming pharmacies into community health hubs across North America.

What You'll Do

Identity and access

  • Own access provisioning and deprovisioning across the SaaS environment, automating wherever it's safe to do so
  • Administer Google Workspace, SSO, and the password manager
  • Run access reviews to audit-ready standard, and govern contractor and offshore access against our customer commitments on PHI

Devices and endpoints

  • Own the MDM platform: migration off our current provider, configuration baselines, endpoint policy
  • Manage the device fleet lifecycle end to end, procurement support, cross-border logistics, secure disposal
  • Build endpoint controls to HITRUST-ready standard

Security operations

  • Operate email security, endpoint detection, and account protection tooling: detection tuning, alert triage
  • Own incident response, escalation, remediation, communication, post-incident review
  • Manage vulnerability and patch programs, external penetration testing, and security awareness training

Data protection and resilience

  • Close our current DLP gap, recommending tooling or compensating controls
  • Own backup coverage, restore testing, and documented recovery procedures
  • Maintain retention policies and support legal hold and discovery requests

Infrastructure and workplace technology

  • Own network, VPN, DNS, and certificate management
  • Administer the collaboration platforms the company runs on, permissions, external sharing controls
  • Govern AI tool adoption: sanctioned tools, data handling review, detection of unapproved use

Service delivery

  • Own IT onboarding and offboarding to a consistent, documented standard
  • Act as the point of contact for support, reducing recurring volume through automation and self-serve documentation
  • Report monthly on service performance, endpoint compliance, spend, and open risk

Compliance and vendor management

  • Gate new tooling through security and procurement review
  • Produce audit evidence for SOC 2 and HITRUST, and support customer security questionnaires alongside Security and Legal
  • Own the IT budget, including vendor negotiations and renewals
About You
  • 5+ years in IT operations or IT security, with hands-on ownership of endpoint management and identity for a distributed team
  • Direct experience deploying and operating email security and endpoint detection tooling
  • Strong Google Workspace administration, including security and conditional access controls
  • Practical networking experience: firewall, wireless, VPN, DNS, certificates
  • Working knowledge of SOC 2, HIPAA, HITRUST, or a comparable framework, including audit evidence requirements
  • Scripting or automation ability sufficient to build and maintain internal workflows
  • Comfort operating as the sole owner of a function
  • Nice to Have: Healthcare or another regulated environment handling PHI or PII; HITRUST readiness or certification experience; Vanta or comparable compliance automation; Multi-entity or cross-border operations
Success in This Role Looks Like
  • 30 days: Full visibility into current infrastructure, MSP scope, and vendor dependencies; MSP transition plan drafted and open-decision evaluation underway (DLP, backup/recovery, vulnerability management, MDR)
  • 60 days: MSP handover underway; device management and email security piloted on the fleet; recommendations on the open decisions taking shape with cost and rationale
  • 90 days: MSP relationship retired; device management and email security deployed across the fleet with provisioning automation live; recommendations delivered on all four open decisions
  • Long-term: A secure, well-documented, fully in-house IT function that scales with the company
How We Hire
  • Initial screening conversation with our People and Culture team
  • Intro interview with the hiring manager
  • Technical interview with the team
  • Additional cross-functional interview as required (depending on the role)
  • References and offer
How We Use AI

At MedMe, we use AI to help us organize and manage applications, so our team can spend their time where it matters most. Every CV is personally reviewed by a human being; AI helps us stay organized, not make decisions. We believe AI should make great people more effective, not replace the thinking and judgment that great hiring requires.

Perks at MedMe
  • Comprehensive Health Benefits: Full coverage for dental, vision, physical, and mental health, plus a health spending account to cover additional wellness needs
  • Group RRSP: Secure your future with our Group Registered Retirement Savings Plan (RRSP)
  • Professional Development: We support your growth with a yearly budget dedicated to learning opportunities
  • Work-from-Home Stipend: A dedicated stipend to help set up and maintain your ideal home office
  • Office Closure for Holidays: Enjoy 1 week of company-wide office closure during the holidays
  • Company Retreats: Participate in exciting on-site team retreats for collaboration and bonding
Location

This is a hybrid position, based at our office located at the intersection of Adelaide and Spadina in Toronto, with in-person work required 2-3 days per week, aligned to operational needs. Occasional travel is expected for customer meetings, partner discussions, and industry events. Remote candidates may be considered on an exceptional basis based on experience.

Equal Opportunity & Accessibility

MedMe is a proud equal opportunity workplace that is committed to equal employment opportunity regardless of race, colour, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. We're looking for motivated and compassionate people who can execute from the ground up and support the work that MedMe believes in.

MedMe is committed to developing an inclusive, barrier-free recruitment process and work environment. Should you require any accommodation, please inform us and we will work with you to meet your accessibility needs. For any accessibility-related assistance, requests for information in accessible alternative formats or to report any accessibility problems, please share in your application.

Learn More About MedMe
  • Globe and Mail – Canada's Top Growing Companies (2025): MedMe was recognized on The Globe and Mail's list of Canada's Top Growing Companies, based on audited three-year revenue growth. Link
  • Forbes 30 Under 30: Our co-founders were named to Forbes 30 Under 30 for their work building MedMe. Read more
  • C100 Growth Cohort (2025): MedMe is part of the 2025 C100 Growth Cohort, a selective community of Canada's top scaling companies. Link
Compensation

The salary range for this role is CAD $85,000.00 - $110,000.00 annually. Compensation is determined based on experience, skills, and alignment to the role's scope. We're happy to discuss the full details of our compensation package with candidates who progress through our interview process.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Manager
IT Manager

MedMe Health • Toronto

Hybrid
CAD 85,000 - 110,000
Comprehensive Health Benefits
Group RRSP
Professional Development
+3
Technical Project Manager (TPM)
Technical Project Manager (TPM)

RXinsider LTD. • Toronto

Hybrid
CAD 90,000 - 115,000
Health benefits
RRSP
Professional development
+3
Technical Project Manager (TPM)
Technical Project Manager (TPM)

MedMe Health • Toronto

Hybrid
CAD 90,000 - 115,000
Comprehensive Health Benefits
Group RRSP
Professional Development
+3
Technical Project Manager (TPM)
Technical Project Manager (TPM)

Medme-Health • Toronto

Hybrid
CAD 90,000 - 115,000
Comprehensive Health Benefits
Group RRSP
Professional Development
+3
Full Stack Engineer (Intermediate)
Full Stack Engineer (Intermediate)

medmehealth • Toronto

On-site
CAD 50,000 - 90,000
Comprehensive Health Benefits
Group RRSP
Professional Development
+3
Sr. Full-Stack Automation Engineer
Sr. Full-Stack Automation Engineer

medmehealth • Toronto

Hybrid
CAD 116,000 - 156,000
Comprehensive Health Benefits
Group RRSP
Professional Development
+3
Head of Strategic Accounts, Canada
Head of Strategic Accounts, Canada

RXinsider LTD. • Toronto

Hybrid
CAD 120,000 - 160,000
Comprehensive Health Benefits: Dental/
RRSP plan
Professional Development
+3
Sr. Platform Engineer
Sr. Platform Engineer

Medme-Health • Toronto

Hybrid
CAD 110,000 - 156,000
Health benefits
RRSP
Professional development
+3
Technical Project Manager (TPM)
Technical Project Manager (TPM)

medmehealth • Toronto

Hybrid
CAD 90,000 - 115,000
Health Benefits
RRSP
Professional Development
+3
Head of Strategic Accounts, Canada
Head of Strategic Accounts, Canada

MedMe Health • Toronto

Hybrid
CAD 120,000 - 160,000
Comprehensive Health Benefits
Group RRSP
Professional Development
+3