> Markdown version of [/jobs/ext/2716552-strategic-director-of-information-technology-information-security](https://www.wearedevelopers.com/jobs/ext/2716552-strategic-director-of-information-technology-information-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # strategic Director of Information Technology & Information Security - **Company:** Take Command Health - **Location:** Dallas, TX, United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Software as a Service, Cloud Computing, Cloud Computing Security, Collaborative Software, CompTIA Security+, Cyber Security, Identity and Access Management, Information Technology Operations, Network Security, Automation of Marketing, Systems Development Life Cycle, Cloud Services, Security Information and Event Management, Software Engineering, Software Vulnerability Management, EndPointSecurity, Data Logging, Computer Networking Systems, Information Technology, Vulnerability Analysis - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/director-information-technology-security-take-command-health-9837099 ## About the Role Required: * 8+ years of progressive experience in IT operations and/or information security, including at least 2-3 years in a people-management or team-lead capacity. * Demonstrated experience building or maturing an information security program in a startup environment * Experience in a highly regulated industry such as health, insurance, financial services, etc. * Hands-on experience with HIPAA and/or SOC 2 compliance frameworks, including audit preparation and evidence management. * Experience managing IT vendors, budgets, and service-level agreements. * Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience. Preferred (Optional): * One or more relevant certifications: CISSP, CISM, CISA, CompTIA Security+, or equivalent. * ITIL Foundation or similar IT service management certification. * Strong working knowledge of cloud infrastructure security, identity and access management, endpoint security, and network security fundamentals. * Experience with security and compliance tooling such as SIEM platforms, EDR/XDR, vulnerability scanners, and GRC/compliance automation platforms (e.g., Vanta, Drata). Skills: This role blends deep technical expertise with the ability to lead and communicate across the business. Technical Skills: * Cloud infrastructure security * Identity & access management (IAM) * Endpoint detection & response (EDR) and network security * HIPAA / SOC 2 compliance frameworks * Security monitoring, logging, and SIEM tooling Communication & Leadership Skills: * Translating technical risk into business terms for executives and the Board * Team building, mentorship, and performance management * Cross-functional collaboration with Engineering, People Ops, Legal, and Finance * Vendor and budget management * Problem-solving under pressure, especially during incidents ## Description Take Command is a start-up on a mission to improve the healthcare system, starting with health insurance. Pragmatically speaking, we help employers reimburse employees for individual insurance instead of offering a traditional one-size-fits-all group plan. We believe this model can empower employees (when they have the right support) to be savvy healthcare consumers and have a transformative impact on the entire healthcare system., We're seeking a hands-on and strategic Director of Information Technology & Information Security to lead Take Command's corporate IT operations and own our information security program end to end. Reporting to our VP, Enterprise Operations (with this reporting line expected to shift to our CTO as the function matures), you'll keep our technology running smoothly for every employee while building the security controls, policies, and compliance posture - including HIPAA and SOC 2 - that protect our members, customers, and business. This is a unique opportunity for an experienced IT and security leader who thrives in a fast-paced, high-growth startup and is excited about building a best-in-class function from the ground up, managing a small team out of our Dallas, TX office (hybrid or onsite)., * IT Operations & Infrastructure: Own the day-to-day operation, availability, and performance of our corporate IT environment - including endpoint management, identity and access management (IAM), collaboration tools, cloud services, and network systems. Develop and maintain an IT roadmap that aligns technology investments with our growth. * Information Security & Compliance: Own and continuously evolve Take Command's information security program, including strategy, roadmap, policies, standards, and technical controls that protect company, employee, and member data, including protected health information (PHI). Establish clear security governance and decision-making frameworks, including risk escalation and acceptance processes, and advise executive leadership on material technology and security risks. Lead our HIPAA and SOC 2 compliance efforts. * Risk Management, Incident Response, & Business Continuity: Design and maintain a proactive security risk management program, including regular risk assessments and vulnerability management. Own incident response planning and execution - detection, containment, communication, and post-incident review. Lead technology business continuity and disaster recovery planning, ensuring we have practical, tested plans to restore critical systems and operations when disruptions occur. * Vendor & Budget Management: Manage relationships, contracts, and spend with IT vendors, managed service providers (MSPs), and SaaS providers. Own the IT budget and drive cost-effective technology decisions. * Third-Party Risk Management: Own the security assessment and ongoing risk management of third-party vendors with access to Take Command systems or data. Partner with internal stakeholders to establish appropriate security requirements, access controls, contractual protections, and remediation plans throughout the vendor lifecycle. * Cross-Functional Security Partnership: Partner with Engineering and Product to embed security best practices into the software development lifecycle (SDLC) and our cloud infrastructure. Serve as the primary point of contact for security questionnaires, audits, and customer due diligence. * Security Awareness & Training: Build and maintain a company-wide security awareness training program, and implement endpoint detection and response (EDR) and security monitoring capabilities. * Team Leadership & Development: Build, mentor, and manage a small team of IT and security professionals. Report on IT and security posture, risk, and roadmap progress to executive leadership and, as needed, the Board or external auditors. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Leverage Cloud Computing Benefits with Serverless Multi-Cloud ML ](https://www.wearedevelopers.com/videos/78-leverage-cloud-computing-benefits-with-serverless-multi-cloud-ml) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [ZEISS & Microsoft - Building the Next Generation Medical Ecosystem in the Cloud](https://www.wearedevelopers.com/videos/424-zeiss-microsoft-building-the-next-generation-medical-ecosystem-in-the-cloud) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer)