More jobs:
Job Description & How to Apply Below
Med Me is building out a dedicated, in-house IT and internal security function to support our growing team. You'll step into a role with established tooling and processes already in place across device management, endpoint detection, email security, and access automation, and will take ownership of operating and evolving this function going forward.
This is our first dedicated IT hire. You'll inherit a stack to deploy, a fleet across two countries, and a compliance path running from SOC 2 toward HITRUST. The role combines architecture and execution: you'll design how IT works here and also be the one running it day to day.
About Med Me Health
At Med Me, we are passionate about empowering pharmacists to provide services beyond just prescribing. Our mission is to build an all-in-one cloud-based platform that enables pharmacists to schedule, document, and manage clinical services h over 4,500 pharmacies using our software, we've facilitated more than 25 million patient services, transforming pharmacies into community health hubs across North America.
What You'll Do
Identity and access
Own access provisioning and deprovisioning across the SaaS environment, automating wherever it's safe to do so
Administer Google Workspace, SSO, and the password manager
Run access reviews to audit-ready standard, and govern contractor and offshore access against our customer commitments on PHI
Devices and endpoints
Own the MDM platform: migration off our current provider, configuration baselines, endpoint policy
Manage the device fleet lifecycle end to end, procurement support, cross-border logistics, secure disposal
Build endpoint controls to HITRUST-ready standard
Security operations
Operate email security, endpoint detection, and account protection tooling: detection tuning, alert triage
Own incident response, escalation, remediation, communication, post-incident review
Manage vulnerability and patch programs, external penetration testing, and security awareness training
Data protection and resilience
Close our current DLP gap, recommending tooling or compensating controls
Own backup coverage, restore testing, and documented recovery procedures
Maintain retention policies and support legal hold and discovery requests
Infrastructure and workplace technology
Own network, VPN, DNS, and certificate management
Administer the collaboration platforms the company runs on, permissions, external sharing controls
Govern AI tool adoption: sanctioned tools, data handling review, detection of unapproved use
Service delivery
Own IT onboarding and offboarding to a consistent, documented standard
Act as the point of contact for support, reducing recurring volume through automation and self-serve documentation
Report monthly on service performance, endpoint compliance, spend, and open risk
Compliance and vendor management
Gate new tooling through security and procurement review
Produce audit evidence for SOC 2 and HITRUST, and support customer security questionnaires alongside Security and Legal
Own the IT budget, including vendor negotiations and renewals
About You
5+ years in IT operations or IT security, with hands-on ownership of endpoint management and identity for a distributed team
Direct experience deploying and operating email security and endpoint detection tooling
Strong Google Workspace administration, including security and conditional access controls
Practical networking experience: firewall, wireless, VPN, DNS, certificates
Working knowledge of SOC 2, HIPAA, HITRUST, or a comparable framework, including audit evidence requirements
Scripting or automation ability sufficient to build and maintain internal workflows
Comfort operating as the sole owner of a function
Nice to Have:
Healthcare or another regulated environment handling PHI or PII; HITRUST readiness or certification experience;
Vanta or comparable compliance automation;
Multi-entity or cross-border operations
Success in This Role Looks Like
30 days: Full visibility into current infrastructure, MSP scope, and vendor dependencies; MSP transition plan drafted and open-decision evaluation underway (DLP, backup/recovery, vulnerability management, MDR)
60 days: MSP handover underway; device management and email security piloted on the fleet; recommendations on the open decisions taking shape with cost and rationale
90 days: MSP relationship retired; device management and email security deployed across the fleet with provisioning automation live; recommendations delivered on all four open decisions
Long-term: A…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×