Practice Better - Senior Manager, Infosec, IT & Compliance
Requirements
• 6+ years of relevant experience in information security, IT operations, privacy, and compliance roles, with at least 2+ years in healthcare SaaS or regulated industry • Deep expertise in HIPAA/HITECH compliance, including Business Associate obligations, breach notification requirements, and Covered Entity vs. Business Associate determination frameworks • Strong working knowledge of GDPR/UK GDPR and cross-border data transfer mechanisms • Proven ability to negotiate and finalize vendor BAAs and DPAs, with a strong understanding of must-have vs. nice-to-have contractual terms • Experience implementing security frameworks (SOC 2, ISO 27001, or equivalent) and managing third-party audits or certifications • Hands-on experience leading IT operations for remote-first organizations, including identity & access management, device provisioning, and SaaS vendor management • Prior experience building or scaling InfoSec, IT, and compliance functions from scratch in high-growth SaaS companies • Technical grounding in SaaS architecture, APIs, data flows, infrastructure (cloud environments like AWS), and identity providers (Google Workspace, Okta, Microsoft 365) • Exceptional communication skills - you can translate legal jargon into plain language for practitioners, write concise vendor negotiation emails, and present compliance strategies to executive leadership with clarity and confidence • Bias for action and pragmatic risk management - you know when to escalate to legal counsel and when to make judgment calls independently • Comfortable operating in a fast-moving, high-growth environment where priorities shift and ambiguity is the norm • Organizational context - The role would manage both the security/compliance function AND day-to-day IT operations, reporting directly to the VP of Engineering • Organizational context • Professional certifications (CIPP/US, CIPP/E, CIPM, CISSP, CISM, or equivalent) • Experience with Canadian provincial privacy laws (PIPEDA, Quebec Law 25, PHIPA) and emerging US state privacy frameworks • Hands-on experience with compliance automation tooling (Vanta, Drata, Secureframe, etc.) and IT service management platforms • Background in fraud prevention, identity verification workflows
Responsibilities
• Information Security & Compliance • Manage multi-jurisdictional compliance execution - Support implementation of HIPAA/HITECH, GDPR/UK GDPR, and many more existing and emerging privacy laws and coordinate with legal counsel on complex regulatory matters. • Manage multi-jurisdictional compliance execution • Drive vendor risk management and BAA/DPA lifecycle - Negotiate and finalize Business Associate Agreements and Data Processing Agreements with subprocessors, ensuring breach notification timelines meet calendar-day standards, data deletion commitments are defined, and subprocessor transparency obligations are satisfied. • Drive vendor risk management and BAA/DPA lifecycle • Mature security posture and operational resilience - Partner with Engineering to implement security controls that support SOC 2 Type II and ISO 27001 readiness, lead incident response planning and mature monitoring/alerting. • Mature security posture and operational resilience • Embed privacy-by-design across product and engineering - Collaborate with Product and Engineering leadership to assess PHI exposure in new features, define data minimization strategies, and guide architecture decisions that reduce compliance risk. • Embed privacy-by-design across product and engineering • IT Operations & Infrastructure • Lead IT operations and service delivery - Own user onboarding / offboarding workflows, device provisioning and management, and IT service delivery for a remote-first team, partnering with HR on seamless employee lifecycle management. • Lead IT operations and service delivery • Drive Identity & Access Management (IAM) strategy - Own identity provider configuration and access control policies, implementing least-privilege access principles, periodic access reviews, and role-based access control (RBAC) frameworks. • Drive Identity & Access Management (IAM) strategy • Manage endpoint security and device management - Define and enforce endpoint security standards (MDM, disk encryption, antivirus, patching). Establish laptop procurement standards and remote device management policies. Coordinate with Engineering on developer tooling and access requirements. • Manage endpoint security and device management • Own SaaS vendor rationalization and procurement hygiene - Conduct regular vendor intelligence audits to identify tool overlaps, license waste and procurement gaps. Partner with Finance on SaaS spend optimization. • Own SaaS vendor rationalization and procurement hygiene • Leadership & Cross-Functional Partnership • Strengthen the InfoSec, IT & Compliance function • Develop and refine processes, tooling, and documentation to support organizational growth. • Manage and mentor the IT Operations team. • Partner with third-party compliance advisors to accelerate maturity. • Act as the bridge between Legal, Engineering, IT, and the business — Translate complex legal language into actionable engineering requirements. Partner with Customer Success on practitioner-facing compliance communications. Coordinate cross-functional responses to regulatory inquiries, audits, and customer due diligence requests. • Act as the bridge between Legal, Engineering, IT, and the business
Benefits
• At Practice Better, we believe in pay transparency, equity, and fairness. We benchmark compensation against similar-stage, high-growth SaaS companies in both Canada and the United States and review our salary bands regularly to ensure they remain competitive and aligned with market trends. • Each role has a defined pay range based on its level, scope, and geographic location. Final offers are determined by several factors, including experience, demonstrated skills, and location, to ensure consistency and equity across our team. • Anticipated Base Salary Range (Canada): $165,000 – $180,000/yr CAD • We take a holistic approach to compensation, combining salary, benefits, and flexibility. Our goal is to provide total rewards that support both your professional growth and personal well-being. • Comprehensive BenefitsWe offer a robust benefits package for full-time, permanent employees, including health, dental, and vision coverage from day 1, as well as RRSP matching, generous paid parental leave, and annual learning stipends. • Remote-First, Connected CultureOur remote-first model gives you autonomy and flexibility, with optional access to our downtown Toronto office for in-person collaboration. We also host regular off-sites and team gatherings across North America, because connection, creativity, and shared moments matter. • Remote-First, Connected Culture • Wellness and Growth • Wellness and Growth • Unlimited vacation, built on trust, clear expectations, and real support for taking time off • Company RRSP program with employer-matched contributions • Comprehensive health and dental benefits from day 1 • $750 annual Health & Wellness Allowance • $1,000 annual Learning & Development Allowance to support your growth • $500 annual Home Office Allowance to set up a productive remote workspace • Sprout Family: personalized support for family-building and fertility journeys • Inkblot: confidential, digital mental health support from licensed professionals • Company-wide holiday closure in December • Regular virtual company-wide events, lunches, and team socials to stay connected • Thriving at Practice Better • At Practice Better, you are not just an employee. You are part of a mission-driven community dedicated to helping others thrive. You will be trusted with autonomy, encouraged to take ownership, and supported by a team that values curiosity, compassion, and meaningful results. • We believe great culture and great performance go hand in hand. Delivering on our commitments is how we earn the trust of our practitioners and continue to expand our impact. Here, you will find the freedom to experiment, a focus on follow-through, and the opportunity to grow, along with the satisfaction of knowing your work directly improves lives every day. • Our Commitment to Diversity, Equity & Belonging • We know innovation happens when diverse perspectives come together. Practice Better is committed to fostering an inclusive environment where every team member feels valued, supported, and empowered to contribute their best. • If you do not meet every requirement listed above, we still encourage you to apply. Research shows that underrepresented groups often hesitate unless they feel 100% qualified. We are far more interested in your potential, curiosity, and alignment with our values. • We are committed to building a workplace where everyone can do the best work of their careers. We welcome applicants of all backgrounds, experiences, and abilities. Accommodations are available throughout the interview process upon request. • Ready to Apply? • Ready to Apply? • If this sounds like your next step, we would love to hear from you. Join us in shaping the future of health and wellness for practitioners, their clients, and communities worldwide. • Vacancy Status: This posting is for an existing vacancy • Vacancy Status • Official Recruitment Notice & AI at Practice Better • All applications are reviewed directly by Practice Better’s internal Talent Acquisition team - no bots, no outsourcing. Legitimate communication from our hiring team will only come from email addresses ending in @practicebetter.io or @greenhouse.com. • @practicebetter.io • @greenhouse.com • Practice Better will never ask for payment, banking details, or personal financial information during the recruitment process. If you receive suspicious communication claiming to represent Practice Better, please contact our team at [email protected] to verify its legitimacy.AI in Recruitment at Practice BetterWe use AI thoughtfully to take some of the repetitive work off our team’s plate: early drafts of job descriptions, first-round interview questions, and help reviewing larger applicant pools. It’s there to make the process smoother and more efficient for everyone. • never • [email protected] • AI in Recruitment at Practice Better • What AI doesn’t do is make decisions. Every hiring decision is made by real people, using structured and consistent practices designed to reduce bias and ensure fairness. • What AI doesn’t do is make decisions. • We’re committed to using AI responsibly and reviewing our approach regularly so it stays aligned with best practices, legal guidance, and the kind of candidate experience we want to deliver. • Candidate Privacy PolicyAI Policy
Apply in one click
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT