Director, IT
Job description
About the role
Stepful is seeking its first Director, IT and Security to transition our infrastructure from third-party management to an internal function. You will lead our security strategy, manage our SOC 2 certification, and oversee the full lifecycle of our technical operations. This is a hybrid position that starts as an individual contributor role with the mandate to build and lead a team as the company expands. You will own the design and execution of our security posture while bridging the gap between technical teams and business stakeholders. Your work will directly influence the reliability and integrity of the platforms that power our healthcare education mission. You will be responsible for establishing the standards, processes, and governance that define how our technology operates at scale. This role requires a leader who can translate complex requirements into actionable plans for a growing organization. You will set the vision for IT and security while ensuring that every project aligns with our compliance and operational goals.
Key facts
What you'll do
- Direct the end-to-end security program and maintain SOC 2 compliance across all systems and processes.
- Establish and enforce security policies, including identity management, multi-factor authentication, single sign-on, and least-privilege access controls.
- Manage security questionnaires, vendor risk assessments, and audit requests for our B2B healthcare partners to ensure regulatory alignment.
- Oversee hardware procurement, mobile device management deployment, and comprehensive inventory management for all endpoints.
- Handle full lifecycle onboarding and offboarding procedures for all staff to ensure secure and efficient access management.
- Administer our Software-as-a-Service application stack, focusing on access governance, vendor relationship reviews, and ongoing cost optimization.
- Serve as the primary escalation point for IT support issues and collaborate with Engineering on endpoint security monitoring and incident response workflows.
- Coordinate IT requirements and infrastructure planning across our New York City office, St. Louis campus, and nationwide lab sites to ensure consistency.
- Develop the long-term IT roadmap that supports current operations and future growth, including the recruitment and development of team members as the organization scales.
- Implement best practices for security operations, monitoring, and continuous improvement of IT service delivery.
- Partner with legal, compliance, and procurement teams to standardize contracts, security addendums, and data handling requirements.
- Drive initiatives to improve user experience, reduce friction in technology adoption, and increase operational efficiency across teams.
Requirements
- Possess 8+ years of professional IT experience, with a background leading IT or security functions in a high-growth startup environment.
- Demonstrate a proven track record of driving SOC 2 Type I and Type II certifications from initial readiness assessments through successful final audit completion.
- Show proficiency with modern IT tooling, specifically Mobile Device Management platforms such as Kandji or Jamf, and identity providers like Okta or Google Workspace.
- Exhibit the ability to function effectively as both a strategic leader defining long-term vision and a hands-on technical contributor solving complex problems.
- Have direct experience managing relationships with hardware vendors, software vendors, and external audit firms across multiple initiatives.
- Maintain strong communication skills to explain intricate security and compliance concepts clearly to non-technical stakeholders and executive leadership.
- Demonstrate meticulous attention to detail when managing policies, configurations, and documentation required for audits and assessments.
- Commit to working within the constraints of a hybrid schedule that requires in-office presence on specific days to support team collaboration.
Nice to have
- Background in healthcare data compliance, including experience with HIPAA frameworks and requirements.
- Experience building an IT department from the ground up during a scaling phase of a high-growth company.
- Previous work history in EdTech or other mission-oriented sectors that align with healthcare and education.
Skills & tools
- MDM (Kandji, Jamf)
- Identity Providers (Okta, Google Workspace)
- Endpoint Security
- SOC 2 Compliance
- SaaS Vendor Management
Practical notes
- The interview process consists of an initial conversation, a hiring manager interview, a take-home assignment with presentation, and an on-site panel interview to evaluate fit and technical depth.
- Benefits include subsidized medical, dental, and vision insurance, a 401(k) plan, and FSA/HSA/commuter benefits to support total wellbeing.
- Time off is structured around an open vacation policy with a 15-day annual guidance, 15 work-from-anywhere days per year, 10 public holidays for 2026, and a company-wide closure during the last week of December to allow for rest and reflection.
- All candidates must be willing to work from New York City with the specified hybrid schedule and comply with onboarding requirements related to background checks and security clearance levels.