Director, Information Technology & Security

Take Command Health · Dallas, Texas · Engineering

Posted 2026-09-02

Apply for this role →

About the Director, IT & Information Security Role:

We’re seeking a hands-on and strategic Director of Information Technology & Information Security to lead Take Command’s corporate IT operations and own our information security program end to end. Reporting to our VP, Enterprise Operations (with this reporting line expected to shift to our CTO as the function matures), you’ll keep our technology running smoothly for every employee while building the security controls, policies, and compliance posture — including HIPAA and SOC 2 — that protect our members, customers, and business. This is a unique opportunity for an experienced IT and security leader who thrives in a fast-paced, high-growth startup and is excited about building a best-in-class function from the ground up, managing a small team out of our Dallas, TX office (hybrid or onsite).

Key Responsibilities:

IT Operations & Infrastructure: Own the day-to-day operation, availability, and performance of our corporate IT environment — including endpoint management, identity and access management (IAM), collaboration tools, cloud services, and network systems. Develop and maintain an IT roadmap that aligns technology investments with our growth.

Information Security & Compliance: Own and continuously evolve Take Command’s information security program, including strategy, roadmap, policies, standards, and technical controls that protect company, employee, and member data, including protected health information (PHI). Establish clear security governance and decision-making frameworks, including risk escalation and acceptance processes, and advise executive leadership on material technology and security risks. Lead our HIPAA and SOC 2 compliance efforts.

Risk Management, Incident Response, & Business Continuity: Design and maintain a proactive security risk management program, including regular risk assessments and vulnerability management. Own incident response planning and execution — detection, containment, communication, and post-incident review. Lead technology business continuity and disaster recovery planning, ensuring we have practical, tested plans to restore critical systems and operations when disruptions occur.

Vendor & Budget Management: Manage relationships, contracts, and spend with IT vendors, managed service providers (MSPs), and SaaS providers. Own the IT budget and drive cost-effective technology decisions.

Third-Party Risk Management: Own the security assessment and ongoing risk management of third-party vendors with access to Take Command systems or data. Partner with internal stakeholders to establish appropriate security requirements, access controls, contractual protections, and remediation plans throughout the vendor lifecycle.

Cross-Functional Security Partnership: Partner with Engineering and Product to embed security best practices into the software development lifecycle (SDLC) and our cloud infrastructure. Serve as the primary point of contact for security questionnaires, audits, and customer due diligence.

Security Awareness & Training: Build and maintain a company-wide security awareness training program, and implement endpoint detection and response (EDR) and security monitoring capabilities.

Team Leadership & Development: Build, mentor, and manage a small team of IT and security professionals. Report on IT and security posture, risk, and roadmap progress to executive leadership and, as needed, the Board or external auditors.

Qualifications:

Required:

8+ years of progressive experience in IT operations and/or information security, including at least 2–3 years in a people-management or team-lead capacity.

Demonstrated experience building or maturing an information security program in a startup environment

Experience in a highly regulated industry such as health, insurance, financial services, etc.

Hands-on experience with HIPAA and/or SOC 2 compliance frameworks, including audit preparation and evidence management.

Experience managing IT vendors, budgets, and service-level agreements.

Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent practical experience.

Preferred (Optional):

One or more relevant certifications: CISSP, CISM, CISA, CompTIA Security+, or equivalent.

ITIL Foundation or similar IT service management certification.

Strong working knowledge of cloud infrastructure security, identity and access management, endpoint security, and network security fundamentals.

Experience with security and compliance tooling such as SIEM platforms, EDR/XDR, vulnerability scanners, and GRC/compliance automation platforms (e.g., Vanta, Drata).

Skills:

This role blends deep technical expertise with the ability to lead and communicate across the business.

Technical Skills:

Cloud infrastructure security

Identity & access management (IAM)

Endpoint detection & response (EDR) and network security

HIPAA / SOC 2 compliance frameworks

Security monitoring, logging, and SIEM tooling

Communication & Leadership Skills:

Translating technical risk into business terms for executives and the Board

Team building, mentorship, and performance management

Cross-functional collaboration with Engineering, People Ops, Legal, and Finance

Vendor and budget management

Problem-solving under pressure, especially during incidents

Apply for this role →

← Back to all jobs