Take Command Health

Director, Information Technology & Security

Take Command Health$125K — $150K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years in IT operations and/or information security with 2-3 years in a leadership role.
  • Proven track record of developing an information security program in a startup setting.
  • Experience in regulated sectors like health, insurance, or finance.
  • Hands-on expertise with HIPAA and SOC 2 compliance, including preparation for audits.
  • Background in managing IT vendors, service contracts, and budget responsibilities.
  • Bachelor's degree in Computer Science, Information Security, or related field (or equivalent).

Responsibilities

  • Oversee daily IT operations and ensure performance and availability of IT environment.
  • Develop and enhance the company's information security program and governance frameworks.
  • Design and implement risk management strategies and business continuity plans.
  • Manage IT vendor relationships, contracts, and budget allocations effectively.
  • Conduct security assessments of third-party vendors and establish security prerequisites.
  • Collaborate with Engineering and Product teams to integrate security into software development.
  • Establish a security awareness training program company-wide.

Benefits

  • Generously funded ICHRA for medical, dental, vision premiums, and expenses.
  • Unlimited personal vacation leave alongside regular company holidays.
  • 401(k) plan with a 4% match, vesting over 4 years with a one-year cliff.
  • Two office locations with well-designed spaces conducive to various work environments.
  • Parental leave policy for new parents, recognizing family needs.
  • Up to two paid days for 'Paw-ternity' leave for pet care.
  • ClassPass corporate membership for access to numerous wellness activities.
  • Flexible working arrangements, with options for remote work as needed.
Full Job Description
About the Director, IT & Information Security Role:

We're seeking a hands-on and strategic Director of Information Technology & Information Security to lead Take Command's corporate IT operations and own our information security program end to end. Reporting to our VP, Enterprise Operations (with this reporting line expected to shift to our CTO as the function matures), you'll keep our technology running smoothly for every employee while building the security controls, policies, and compliance posture - including HIPAA and SOC 2 - that protect our members, customers, and business. This is a unique opportunity for an experienced IT and security leader who thrives in a fast-paced, high-growth startup and is excited about building a best-in-class function from the ground up, managing a small team out of our Dallas, TX office (hybrid or onsite).

Key Responsibilities:
  • IT Operations & Infrastructure: Own the day-to-day operation, availability, and performance of our corporate IT environment - including endpoint management, identity and access management (IAM), collaboration tools, cloud services, and network systems. Develop and maintain an IT roadmap that aligns technology investments with our growth.
  • Information Security & Compliance: Own and continuously evolve Take Command's information security program, including strategy, roadmap, policies, standards, and technical controls that protect company, employee, and member data, including protected health information (PHI). Establish clear security governance and decision-making frameworks, including risk escalation and acceptance processes, and advise executive leadership on material technology and security risks. Lead our HIPAA and SOC 2 compliance efforts.
  • Risk Management, Incident Response, & Business Continuity: Design and maintain a proactive security risk management program, including regular risk assessments and vulnerability management. Own incident response planning and execution - detection, containment, communication, and post-incident review. Lead technology business continuity and disaster recovery planning, ensuring we have practical, tested plans to restore critical systems and operations when disruptions occur.
  • Vendor & Budget Management: Manage relationships, contracts, and spend with IT vendors, managed service providers (MSPs), and SaaS providers. Own the IT budget and drive cost-effective technology decisions.
  • Third-Party Risk Management: Own the security assessment and ongoing risk management of third-party vendors with access to Take Command systems or data. Partner with internal stakeholders to establish appropriate security requirements, access controls, contractual protections, and remediation plans throughout the vendor lifecycle.
  • Cross-Functional Security Partnership: Partner with Engineering and Product to embed security best practices into the software development lifecycle (SDLC) and our cloud infrastructure. Serve as the primary point of contact for security questionnaires, audits, and customer due diligence.
  • Security Awareness & Training: Build and maintain a company-wide security awareness training program, and implement endpoint detection and response (EDR) and security monitoring capabilities.
  • Team Leadership & Development: Build, mentor, and manage a small team of IT and security professionals. Report on IT and security posture, risk, and roadmap progress to executive leadership and, as needed, the Board or external auditors.


Qualifications:

Required:
  • 8+ years of progressive experience in IT operations and/or information security, including at least 2-3 years in a people-management or team-lead capacity.
  • Demonstrated experience building or maturing an information security program in a startup environment
  • Experience in a highly regulated industry such as health, insurance, financial services, etc.
  • Hands-on experience with HIPAA and/or SOC 2 compliance frameworks, including audit preparation and evidence management.
  • Experience managing IT vendors, budgets, and service-level agreements.
  • Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience.

Preferred (Optional):
  • One or more relevant certifications: CISSP, CISM, CISA, CompTIA Security+, or equivalent.
  • ITIL Foundation or similar IT service management certification.
  • Strong working knowledge of cloud infrastructure security, identity and access management, endpoint security, and network security fundamentals.
  • Experience with security and compliance tooling such as SIEM platforms, EDR/XDR, vulnerability scanners, and GRC/compliance automation platforms (e.g., Vanta, Drata).

Skills:

This role blends deep technical expertise with the ability to lead and communicate across the business.

Technical Skills:
  • Cloud infrastructure security
  • Identity & access management (IAM)
  • Endpoint detection & response (EDR) and network security
  • HIPAA / SOC 2 compliance frameworks
  • Security monitoring, logging, and SIEM tooling

Communication & Leadership Skills:
  • Translating technical risk into business terms for executives and the Board
  • Team building, mentorship, and performance management
  • Cross-functional collaboration with Engineering, People Ops, Legal, and Finance
  • Vendor and budget management
  • Problem-solving under pressure, especially during incidents


Working at Take Command

We're excited to build a team and culture that reflects our values! We offer competitive pay and health benefits to share with this position.
  • A generously funded ICHRA for medical, dental, and vision premiums and medical expenses. You get to use our own product and we think that's so exciting and rare!
  • Unlimited personal vacation in addition to regular company holidays.
  • 401(k): 90-day eligibility for 4% match that vests over 4 years with a one year cliff!
  • We have two beautiful offices in Richardson, Texas (City Line) and Austin, Texas. The kitchen is well-stocked and we've designed the space to have lots of different areas to work--lounge on the couch, stand near your colleague at a kiosk desk or hole up in one of our phone rooms!
  • Competitive parental leave for new parents.
  • Up to two paid days of Paw-ternity leave. We recognize that pets are family too - and supporting life outside of work (including four-legged members) matters!
  • ClassPass corporate membership with access to over 73,000 fitness and wellness options.
  • Flexible on where you work - we believe in the power of connecting with intention! While we hope to see you around the office on a regular basis, you also have the ability to work from home some when you need to get focus work done.

About Take Command Health

Take Command Health is a healthcare technology company that provides a platform for individuals and small businesses to compare and purchase health insurance plans. The company was founded in 2014 by Jack Hooper and Laura Brenner and is headquartered in Dallas, Texas. The platform offers personalized recommendations based on the user's healthcare needs and budget, as well as access to telemedicine services and other healthcare resources. Take Command Health aims to simplify the health insurance purchasing process and help individuals and small businesses save money on healthcare costs.
Learn more about Take Command Health
Size
25 employees
Industry
Founded
2014
5 Year Trend
+50%
Revenue
$1 million

Similar Jobs

More Jobs at Take Command Health

More Information Technology Jobs

Find similar Director, Information Technology & Security jobs: