Tonal Systems

Tonal Systems, Inc. is a technology company known for its personal training and fitness services and equipment. As an employer, the company strives to foster an

Director, IT and Security

Location

Texas

Posted

3 days ago

Salary

$178K - $220K / year

Seniority

Mid Level

Job Description

Director, IT and Security

Tonal Systems

Director, IT and Security Location Austin, TX Employment Type Full time Location Type Remote Department Operations - Business Technology & PMO - Business Technology Compensation - $178K – $220K Overview Tonal is the world's most intelligent strength training system, combining hardware, software, AI, computer vision, and world-class content to help people build strength and live healthier. Tonal is now expanding into healthcare and clinical applications, connecting strength training technology with providers, employers, and payers to deliver measurable health outcomes — raising the bar for what our IT and security function needs to deliver. We're looking for a Director of IT & Security to own this function end-to-end. This role carries the highest privileges across our most sensitive systems and direct accountability for IT and security outcomes company-wide. You'll report to the VP of Business Technology and work closely with senior leadership. The ideal candidate has a start-up mentality — comfortable moving fast in a lean, resource-constrained environment, while never losing sight of the security and compliance discipline a healthcare-adjacent company requires. What You Will Do - Own end-to-end IT operations, including device lifecycle, onboarding/offboarding, SaaS administration, identity and access management, help desk, and office infrastructure across all locations. - Lead the technical controls side of Tonal's HIPAA compliance program, implementing the safeguards required by the HIPAA Security Rule and HITECH Act — encryption, SIEM, MDM/EDR, and role-based access. - Own and execute Tonal's security program: penetration testing remediation, security policy, tabletop exercises, vendor security reviews, and incident response. - Govern Tonal's AI tool ecosystem, including licensing, spend, API key governance, corporate AI policy, and DLP and prompt injection protections. Drive AI training and best practices across the organization. - Administer Tonal's SaaS portfolio, owning contract renewals, license optimization, and vendor negotiations across critical platforms. - Drive automation and identity governance maturity, including Okta Identity Governance, expanding SCIM-based provisioning, building & enforcing RBAC frameworks, and driving workflow automation and system integration. - Lead and grow the IT & Security team, managing engineers and administrators, overseeing the virtual CISO engagement, owning the budget and aligning org structure to Tonal’s needs. - Own IT documentation and process improvement, maintaining runbooks and closing gaps in onboarding, offboarding, and incident response, and driving overall automation. - Manage global physical infrastructure — networking, Wi-Fi, AV, and physical access — across a distributed, multi-office footprint. - Serve as a trusted operator on Tonal's most sensitive matters, from executive access provisioning to security incidents and legal holds. - Report regularly to senior leadership and the C-suite, translating IT & Security roadmap priorities, progress, technical risk and incident management into clear, actionable narratives. Who You Are - 10+ years in IT and security leadership, with full functional ownership and experience across identity and access management, endpoint security, SaaS administration, network infrastructure, and security program management. - Hands-on HIPAA compliance implementation experience, beyond writing policies - Track record of building a security program from the ground up: policy, penetration testing, and real incident response - Broad expertise across identity and access management, endpoint security, SaaS administration, and network infrastructure - Equally comfortable configuring technical systems and presenting security risk to executive leadership - A start-up mindset: thrives in fast-moving, resource-constrained environments without cutting corners on security - Proven ability to prioritize with a lean team and limited budget, with outcomes to show for it. - Experience managing a large SaaS portfolio, including contract renewals, vendor negotiation, and license governance - Strong people leadership skills, setting clear expectations and developing team members - High standards of trust, integrity, and discretion, given access to the company's most sensitive systems Extra Credit - HIPAA compliance roll-out and execution, owning the technical controls end-to-end. - Experience with SOC 2 Type II, NIST CSF, or HITRUST in a hands-on implementation capacity - Background in healthcare technology, digital health, or clinical-grade software environments At Tonal, we believe that the unique and varied lived experiences of our teammates contribute to our overall strength. We don’t just appreciate differences, we celebrate them, and we always seek people that represent a wide variety of backgrounds. We’re dedicated to adding new perspectives to the team and designing employee experiences that contribute to your growth as much as you do to ours. If your experience aligns with what we’re looking for (even if you don’t check every single box), send us your application. We would love to hear from you! Tonal is committed to meeting the diverse needs of people with disabilities in a timely manner that is consistent with the principles of independence, dignity, integration, and equality of opportunity. Should you have any accommodation requests, please reach out to us via our confidential email. All requests will be addressed and responded to in accordance with Tonal’s Accessibility Policy and local legislation.

Related Categories

Related Job Pages

More Security Engineer Jobs

Network Security Architect

Redolent, Inc

ERM - Rina María Cabrera / Capgemini | North América External Resource Manager Tel.: +1 888 229 2961 Email: rina.cabrera@capgemini.com

Role Description The role involves providing subject matter expertise in the analysis, design, implementation, troubleshooting, and preparation of technology solutions to meet business needs. The candidate should have expert-level hands-on and design experience in various security technologies. - Hands-on experience with Palo Alto firewall, Fortigate Firewall, ClearPass, and Zscaler (Zscaler Internet Access, Zscaler Private Access). - Experience in implementing zero trust. - Recommends components for solutions that work well across business domains. - Accountable for timely and cost-effective delivery of projects/applications/infrastructure. - Expert level knowledge in implementing PCI4.0. - Perform Root Cause Analysis for Major P1/P2 incidents following ITIL process. - Ensures project artifacts are developed and documented properly. - Facilitates the creation of communication plans among key stakeholders. - Develops complete and robust test plans, cases, and scripts. - Acts as a communication point for infrastructure, application, and data changes. - Ensures integration of assigned business areas against critical business processing. - Thorough understanding of business strategy, operations, markets, and key stakeholders. - Reviews business processes to identify capability gaps and opportunities. - Recommends innovations and simplifications in business processes/systems. - Builds close relationships with function heads and their teams. - Works as 3rd level support to resolve issues within the area of responsibility. - Maintains a high level of individual contribution and professional growth. Qualifications - Expert-level hands-on experience with security technologies. - Strong understanding of business strategy and operations. - Ability to develop communication plans and test strategies. Requirements - Proven experience with Palo Alto and Fortinet Firewalls. - Experience with HPE Aruba Clearpass and Zscaler technologies. - Knowledge of PCI4.0 implementation. - Experience in ITIL processes. Benefits - 100% Remote work opportunity. - Flexible working hours.

United States
Map Ssg logo

Founding Security Engineer

Map Ssg

A venture-backed startup building a modern data platform for the real estate industry, enabling automation, analytics, and AI-powered workflows for real estate operators. The team includes engineers and leaders from companies such as major fintech, cloud, and consumer technology platforms, and is focused on solving complex infrastructure and data challenges in a large, underserved industry.

Role Description This is the company’s first dedicated security hire. You will define and build the company’s security program from scratch, working directly with a security-minded co-founder. This role spans product security, application security, corporate security, compliance, incident response, and detection. Over time, this person may build and lead the security function. - Own the company’s security posture across product, infrastructure, and internal systems - Lead security reviews, threat modeling, and secure design work - Build foundational security systems such as secrets management, audit logging, vulnerability management, and certificate infrastructure - Drive compliance programs such as SOC 2, ISO 27001, GDPR, and CCPA - Define incident response processes and detection capabilities - Partner closely with engineering to embed security into product development - Help shape security culture across a small, high-caliber team Qualifications - 5+ years of security engineering experience - Strong application security background - Experience with secure SDLC, threat modeling, vulnerability management, and security architecture - Experience contributing to or running security programs - Compliance experience, ideally SOC 2, ISO 27001, GDPR, or similar - Backend or systems engineering fluency; Go experience is a plus - Ability to operate with high ownership in an early-stage environment - Low-ego, collaborative mindset and willingness to wear multiple hats Nice to Have - First or second security hire experience at a startup - Detection engineering experience - Identity, access management, enterprise IT, or security software background - Kubernetes, GCP, cloud security, or infrastructure security experience - Published security research, talks, or open-source security work

United States
$180K - $230K / year
Bayview Asset Management logo

IT Security Database Engineer

Bayview Asset Management

Founded in 1993, Bayview Asset Management is an investment management firm focused on investments in mortgage and consumer credit, including whole loans, asset-backed securities, mortgage servicing rights, and other credit-related assets.

Full TimeRemoteTeam 1,001-5,000

Role Description The Database Security Engineer is responsible for securing and protecting the organization’s enterprise databases, database platforms, and related data assets. This role combines database administration expertise with information security best practices to ensure the confidentiality, integrity, and availability of sensitive company and customer data. The role is part of the Security Engineering team and will work closely with Infrastructure, Application Development, Information Security, Compliance, and business stakeholders to: - Implement database security controls - Monitor database activity - Support regulatory compliance initiatives - Reduce organizational risk The ideal candidate will have a strong background in database administration (DBA) along with hands-on experience in: - Database security - Auditing - Vulnerability management - Data protection technologies in on-premise data center and public cloud environments The candidate must be familiar with a variety of database technologies, security concepts, practices, and procedures. Qualifications - BA/BS in Computer Science, Computer Engineering, Information Systems, or equivalent experience - 7+ years of experience in database administration, database engineering, or database security - Strong hands-on experience administering enterprise database platforms such as SQL Server, Oracle, PostgreSQL, or MySQL - Experience implementing database security controls including encryption, auditing, access controls, and privileged access management - Experience with database vulnerability scanning, monitoring, and remediation processes - Experience in highly regulated environments, preferably Financial Services or similar industries - Experience supporting cloud database technologies and security best practices in AWS, Oracle and/or Azure Requirements - Strong understanding of database architecture, database administration, backup/recovery, and performance concepts - Knowledge of methods to secure databases, applications, and sensitive data assets - In-depth knowledge of data protection engineering principles, DLP, encryption, masking, and tokenization - Strong research and troubleshooting skills - Strong verbal and written communication skills - Skill with SQL, Python, Bash, or PowerShell scripting Benefits - This role will be remote based anywhere in the US - The base compensation will be based on experience - There will be an opportunity for an incentive-based bonus Certifications, Licenses, and/or Registration - Preferred: CISSP, CISA, Security+, Microsoft Certified: Azure Database Administrator Associate, Oracle Database Security Certified Implementation Specialist, AWS Certified Security – Specialty, GIAC certifications, Microsoft SQL certifications, or equivalent database/security certifications

United States
PROSTAFF Schweiz logo

Full Stack Engineer – IAM Security, German speaking

PROSTAFF Schweiz

We provide freelance jobs in IT and data science in Switzerland. Moreover we provide payrolling services.

Full TimeRemoteTeam 51-200Since 2007H1B No Sponsor

• Analyse und Behebung von Vulnerabilities im IAM-Umfeld • Weiterentwicklung und Optimierung bestehender Full-Stack-Anwendungen • Umsetzung sicherheitsrelevanter Anpassungen im Backend und Frontend • Betrieb und Deployment von Anwendungen auf einer OpenShift-Plattform • Durchführung von Code Reviews • Sicherstellung von Qualität, Stabilität und Wartbarkeit der Software

Switzerland