Eko

Head of IT & Cybersecurity

Eko • $229K — $256K *
Healthcare
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in IT, Computer Science, Cybersecurity, or related field, or equivalent experience.
  • 10+ years in IT and/or cybersecurity roles, with leadership experience in a growth-stage company.
  • Experience in regulated healthcare or medical device sectors, familiar with HIPAA/HITECH and FDA cybersecurity.
  • Hands-on experience managing SOC 2 from scoping to audit, including evidence collection.
  • Strong knowledge of identity/access management, endpoint management, and cloud platforms like Google Workspace or Microsoft 365.
  • Proven track record of building or maturing security programs from the ground up.
  • Excellent communication skills for translating technical risks to non-technical audiences.

Responsibilities

  • Own corporate IT strategy, infrastructure, and daily operations including employee endpoints and helpdesk support.
  • Manage software procurement, licensing, and vendor negotiations in collaboration with Finance.
  • Oversee the IT budget and technology roadmap, building or managing the support team.
  • Design and mature the corporate cybersecurity program, including policies and incident response planning.
  • Maintain the corporate security risk register and drive remediation efforts for identified gaps.
  • Act as the primary contact for corporate-level security incidents, coordinating investigations and communications.
  • Deliver compliance and security documentation to customers and partners during procurement and audits.

Benefits

  • Opportunity to work on impactful health products.
  • Generous paid-time off.
  • Stock incentive plans.
  • Comprehensive medical, dental, and vision insurance, plus disability and life insurance.
  • One Medical membership.
  • Parental leave.
  • 401k matching.
  • Learning and development stipend.
Full Job Description
Role Summary

Eko is hiring a Head of Information Technology & Cybersecurity to own the company's corporate IT operations and cybersecurity program end to end. In this role, you will be the single accountable owner for keeping Eko's internal systems reliable and secure, and for corporate compliance obligations including SOC 2 and related frameworks.

This is a corporate-facing role. The security of Eko's product - its FDA-cleared device software and AI platform - is owned by our Product Security team. This role does not set product security strategy; you will serve as a resource to Product Security, executing security testing against that team's pre-defined product security procedures as required.

This is a hands-on and highly visible leadership role for someone who can build a program, run it day to day, and represent it credibly to auditors, customers, and executive leadership.
Essential Functions:
Corporate IT Operations & Infrastructure
  • Own Eko's corporate IT strategy, infrastructure, and day-to-day operations: employee endpoints (MDM), identity and access management (SSO/MFA), corporate network, cloud workplace tools, helpdesk/support, and asset management.
  • Manage software and SaaS procurement, licensing, and lifecycle, including vendor selection and renewal negotiations in partnership with Finance.
  • Own the IT budget and technology roadmap, and build or manage the team (internal hires and/or outsourced providers) responsible for day-to-day IT support.
Cybersecurity Program & Governance
  • Design, implement, and continuously mature Eko's corporate cybersecurity program: security policies, endpoint and email security, data loss prevention, identity governance, security awareness training, and incident response planning.
  • Own and maintain the corporate security risk register, and drive remediation of identified gaps with clear ownership and timelines.
  • Act as Eko's primary point of contact for corporate-level security incidents - coordinating investigation, containment, communication, and post-incident review.
Compliance & Audit Management
  • Own SOC 2 (Type I/II) end to end: scoping, control design and implementation, evidence collection, and management of the external audit relationship.
  • Own or contribute to other applicable corporate compliance obligations as the company's needs require - for example HIPAA/HITECH administrative and technical safeguards, HITRUST, and relevant privacy regulations (e.g., CCPA, UK/EU GDPR) tied to Eko's customer base and international footprint.
  • Serve as the primary liaison for customer and partner security questionnaires, vendor security due-diligence requests, and audit committee or board reporting on IT/security posture.
  • Maintain the compliance calendar so renewals, audits, and control testing happen on schedule, with no last-minute scrambles.
Customer & Health-System Documentation
  • Own the timely delivery of all corporate compliance and security documentation requested by health systems, clinicians, and other customers during sales procurement, vendor risk review, and ongoing account management - including SOC 2 reports, HIPAA/BAA materials, security questionnaires (e.g., SIG, CAIQ), penetration test summaries, and policy attestations.
  • Maintain a current, ready-to-share documentation package so Sales and Customer Success can respond to procurement and security-review requests without delay.
  • Partner with Sales, Customer Success, and Legal to support customer security calls and due-diligence sessions when a technical point of contact is needed.
Cross-Functional Collaboration
  • Partner with People/HR on secure onboarding and offboarding, device provisioning, and access provisioning/deprovisioning.
  • Partner with Legal on vendor security reviews and data processing agreements.
  • Partner with Product Security as a testing resource, executing tests against procedures that team defines - see note above on where this role's scope ends.

Note: Job duties may change at any time with or without notice.
Required Qualifications:
  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or a related field, or equivalent practical experience.
  • 10+ years of experience in IT and/or cybersecurity roles, including leadership experience, ideally at a growth-stage company.
  • Experience in a regulated healthcare, digital health, or medical device company, with familiarity with HIPAA/HITECH, HITRUST, or FDA cybersecurity expectations for connected devices.
  • Hands-on experience owning SOC 2 from scoping through audit, including evidence collection and direct management of the external auditor relationship.
  • Strong working knowledge of identity and access management, endpoint management, cloud workplace platforms (e.g., Google Workspace or Microsoft 365), and modern security tooling (EDR, MDM, SSO/IdP, DLP).
  • Track record of building or maturing a security program - policies, a risk register, incident response, and security awareness training - largely from the ground up.
  • Excellent written, verbal, and executive presentation skills, with the ability to translate technical risk for executive and non-technical audiences.
Preferred Qualifications:
  • Relevant certification such as CISSP, CISM, or CRISC.
  • Experience supporting compliance needs tied to international expansion (e.g., UK/EU GDPR).


Benefits and Perks We Offer:
  • The opportunity to work on products that impact the health of millions of people.
  • Generous paid-time off
  • Stock incentive plans
  • Medical/Dental/Vision, Disability + Life Insurance
  • One Medical membership
  • Parental Leave
  • 401k Matching
  • Learning and Development stipend

Work Experience & Location Requirements

  • This role is based out of our office in Emeryville, CA
  • This is a Hybrid role (In-Office days are Tuesday, Wednesday and Thursday)
  • Prolonged periods of sitting and working at a computer
  • Must be able to perform job duties with or without reasonable accommodation


$229,500 - $256,000 a year

About Eko

Eko is a healthcare technology company that develops and manufactures digital stethoscopes and other medical devices. The company's products use artificial intelligence and machine learning algorithms to help healthcare professionals diagnose and treat patients more effectively. Eko's products are used by hospitals, clinics, and other healthcare providers around the world. The company was founded in 2013 and is headquartered in New York, NY.
Learn more about Eko
Size
51 employees
Industry
Founded
2012

Similar Jobs

More Jobs at Eko

More Healthcare Jobs

Find similar Head of IT & Cybersecurity jobs: