Founding IT Operations
Job description
About the role
Rilla is seeking a foundational IT Operations specialist to build and manage our compliance and IT infrastructure from the ground up. This role involves transforming manual compliance processes into automated, AI-driven systems to ensure efficiency and scalability. You will be responsible for establishing the company's entire IT foundation, including security protocols, device management, and infrastructure setup, all while ensuring adherence to regulatory standards. This position is critical in supporting the company's growth by providing reliable, scalable, and secure IT and compliance operations. The ideal candidate will have a strong technical background, experience with compliance frameworks, and a proactive approach to building systems that support rapid expansion.
Key facts
What you'll do
- Manage and maintain SOC 2 compliance, ensuring all controls are implemented and functioning correctly. Lead efforts to achieve additional certifications such as HIPAA, GDPR, and ISO 27001, coordinating with auditors and internal teams.
- Implement AI-powered automation solutions to streamline compliance workflows, reducing manual effort and increasing audit readiness. Develop and deploy systems that automatically collect, organize, and verify evidence required for regulatory audits.
- Develop and establish the company's IT infrastructure from scratch, including selecting appropriate hardware, software, and cloud services to support current needs and future growth. Design scalable solutions for device management, network security, and data storage.
- Serve as a key liaison between engineering, HR, legal, and leadership teams, translating complex technical and compliance requirements into clear, actionable tasks and policies. Facilitate communication and collaboration across departments to ensure alignment on security and compliance initiatives.
- Oversee daily IT operations, including device management, network troubleshooting, and resolving technical issues promptly to minimize downtime. Maintain an inventory of hardware and software assets, ensuring all systems are up-to-date and secure.
- Develop, document, and enforce security protocols and IT policies that align with industry standards and regulatory requirements. Regularly review and update these policies to adapt to evolving threats and compliance standards.
- Lead efforts to implement and monitor security measures such as firewalls, encryption, and access controls to protect sensitive data and systems. Conduct periodic security assessments and respond to incidents swiftly.
- Assist in onboarding new employees by setting up their IT environment, including hardware, software, and access permissions. Provide training on security best practices and compliance procedures.
- Coordinate with external vendors and auditors to ensure timely delivery of required documentation, evidence, and assessments. Manage vendor relationships to ensure service quality and compliance adherence.
- Monitor the security and operational health of all IT systems, providing regular reports to leadership on compliance status, system performance, and potential vulnerabilities.
- Build and refine automation workflows that reduce manual effort, improve accuracy, and ensure continuous compliance. AI tools to identify anomalies or potential issues proactively.
- Support the development of disaster recovery and business continuity plans, ensuring data integrity and availability in case of emergencies.
- Stay informed about the latest developments in compliance standards, security best practices, and emerging technologies relevant to IT operations and regulatory requirements.
- Collaborate with the product and engineering teams to integrate security and compliance considerations into product development and deployment processes.
- Contribute to creating a security-aware culture within the organization through training, documentation, and regular updates.
- Provide technical guidance and mentorship to team members involved in compliance and IT infrastructure projects.
- Participate in strategic planning for IT growth, scalability, and security enhancements aligned with company objectives.
Requirements
- A strong technical background, such as a degree in computer science, information technology, or a related field, or equivalent practical experience.
- Proven experience in managing and maintaining compliance frameworks, especially SOC 2, with a track record of achieving and sustaining certifications.
- Hands-on experience with implementing and automating compliance workflows using AI tools or automation platforms.
- Deep understanding of security protocols, including firewalls, encryption, access controls, and incident response.
- Experience with device management systems, network troubleshooting, and infrastructure setup.
- Excellent communication skills, capable of translating technical concepts into clear language for non-technical stakeholders.
- Ability to operate effectively in ambiguous or undefined situations, bringing clarity and problem-solving skills to complex challenges.
- Strong organizational skills with attention to detail, ensuring all compliance and security measures are documented and maintained properly.
- Ability to work on-site in New York City, with a flexible approach to managing multiple priorities.
- Demonstrated ability to develop and implement IT infrastructure from scratch, including hardware, software, and cloud services.
- Experience working in fast-paced, high-growth environments is a plus.
- Knowledge of relevant regulations such as HIPAA, GDPR, and ISO 27001 is highly desirable.
- Familiarity with automation tools and scripting languages to enhance efficiency and accuracy in compliance processes.
Nice to have
- Prior experience managing compliance frameworks like SOC 2, including preparing for audits and maintaining controls.
- Direct experience with HIPAA, GDPR, or ISO 27001 implementations and ongoing compliance management.
- Experience setting up IT and device management systems for startups or rapidly growing organizations.
- Knowledge of cloud infrastructure providers such as AWS, GCP, or Azure.
- Familiarity with security assessment tools and vulnerability management platforms.
- Previous experience working in a startup or high-growth company environment, adapting quickly to changing priorities.
Skills & tools
- AI automation tools for workflow optimization
- Compliance frameworks including SOC 2, HIPAA, GDPR, ISO 27001
- Device management systems and protocols
- Network troubleshooting and security tools
- Cloud services and infrastructure management
- Security protocols and best practices
- Documentation and policy development tools
- Vendor management platforms
Practical notes
- Compensation includes comprehensive medical, dental, and vision insurance coverage.
- The company provides in-office meals, including breakfast, lunch, and dinner, along with snacks throughout the day.
- Employees have access to an in-office gym, sauna, and cold plunge for wellness and relaxation.
- Commuter benefits and relocation assistance are available to support new hires.
- The company maintains a flexible paid time off policy, encouraging employees to take time off as needed for rest and personal matters.
- A $1,000 stipend is provided for learning and professional development activities.
- Monthly rent stipend of $1,500 helps offset housing costs for employees working on-site.
- Necessary tech equipment, including hardware and software, will be provided to support your work.
- The role requires working approximately 60 hours per week in the office to meet project and compliance deadlines.
- The position is on-site in New York City, emphasizing the importance of physical presence for collaboration and infrastructure management.
- The company values proactive, detail-oriented individuals capable of building systems from scratch and maintaining high standards of security and compliance.
- Candidates should be prepared for a dynamic environment where rapid development and iteration are common.