Head of IT & Cybersecurity

Eko•Emeryville, CA
•$229,500 - $256,000•Hybrid

About The Position

Eko Health is seeking a Head of Information Technology & Cybersecurity to oversee the company's corporate IT operations and cybersecurity program. This role is responsible for ensuring the reliability and security of Eko's internal systems and managing corporate compliance obligations such as SOC 2. While the security of Eko's product is managed by the Product Security team, this role will support them by executing security testing as required. This is a hands-on leadership position that involves building and running the IT and cybersecurity programs, and representing them to auditors, customers, and executive leadership.

Requirements

  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or a related field, or equivalent practical experience.
  • 10+ years of experience in IT and/or cybersecurity roles, including leadership experience, ideally at a growth-stage company.
  • Experience in a regulated healthcare, digital health, or medical device company, with familiarity with HIPAA/HITECH, HITRUST, or FDA cybersecurity expectations for connected devices.
  • Hands-on experience owning SOC 2 from scoping through audit, including evidence collection and direct management of the external auditor relationship.
  • Strong working knowledge of identity and access management, endpoint management, cloud workplace platforms (e.g., Google Workspace or Microsoft 365), and modern security tooling (EDR, MDM, SSO/IdP, DLP).
  • Track record of building or maturing a security program — policies, a risk register, incident response, and security awareness training — largely from the ground up.
  • Excellent written, verbal, and executive presentation skills, with the ability to translate technical risk for executive and non-technical audiences.

Nice To Haves

  • Relevant certification such as CISSP, CISM, or CRISC.
  • Experience supporting compliance needs tied to international expansion (e.g., UK/EU GDPR).

Responsibilities

  • Own Eko's corporate IT strategy, infrastructure, and day-to-day operations, including employee endpoints (MDM), identity and access management (SSO/MFA), corporate network, cloud workplace tools, helpdesk/support, and asset management.
  • Manage software and SaaS procurement, licensing, and lifecycle, including vendor selection and renewal negotiations in partnership with Finance.
  • Own the IT budget and technology roadmap, and build or manage the team responsible for day-to-day IT support.
  • Design, implement, and continuously mature Eko's corporate cybersecurity program, including security policies, endpoint and email security, data loss prevention, identity governance, security awareness training, and incident response planning.
  • Own and maintain the corporate security risk register, and drive remediation of identified gaps.
  • Act as Eko's primary point of contact for corporate-level security incidents, coordinating investigation, containment, communication, and post-incident review.
  • Own SOC 2 (Type I/II) end to end, including scoping, control design and implementation, evidence collection, and management of the external audit relationship.
  • Own or contribute to other applicable corporate compliance obligations such as HIPAA/HITECH, HITRUST, and relevant privacy regulations (e.g., CCPA, UK/EU GDPR).
  • Serve as the primary liaison for customer and partner security questionnaires, vendor security due-diligence requests, and audit committee or board reporting on IT/security posture.
  • Maintain the compliance calendar to ensure timely renewals, audits, and control testing.
  • Own the timely delivery of all corporate compliance and security documentation requested by health systems, clinicians, and other customers.
  • Maintain a current, ready-to-share documentation package to support Sales and Customer Success.
  • Partner with Sales, Customer Success, and Legal to support customer security calls and due-diligence sessions.
  • Partner with People/HR on secure onboarding and offboarding, device provisioning, and access provisioning/deprovisioning.
  • Partner with Legal on vendor security reviews and data processing agreements.
  • Partner with Product Security as a testing resource, executing tests against procedures defined by that team.

Benefits

  • The opportunity to work on products that impact the health of millions of people.
  • Generous paid-time off
  • Stock incentive plans
  • Medical/Dental/Vision, Disability + Life Insurance
  • One Medical membership
  • Parental Leave
  • 401k Matching
  • Learning and Development stipend
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service