Director, IT & Security

Virtual (Remote)

About the Company:

Octave is a modern behavioral health practice creating a new standard for care delivery that’s both high-quality and accessible. With in-person and virtual clinics in multiple states, the company offers evidence-based individual, couples, and family therapy, while pioneering relationships with payers to make care more affordable through insurance. By raising the bar on how care is delivered and how providers are supported, we are building a sustainable system that values equity, affordability, and effectiveness.

Job Summary: 

As the Director of IT & Security, you are the primary architect of the company’s technological resilience and security posture. You provide the strategic vision for a scalable, secure corporate infrastructure that enables rapid business growth while maintaining rigorous compliance. You are not just managing systems; you are owning the overall strategy for risk mitigation, technical governance, and the evolution of the modern workplace.

Management Responsibilities: 

  • Develops, coordinates, and implements  systems, policies, procedures, and productivity standards.
  • Foster a positive and collaborative work environment.
  • Oversee the planning, execution, and completion of projects and initiatives within the team.
  • Establish and monitor operational processes and workflows to enhance efficiency and productivity.
  • Implement best practices, monitor key performance indicators (KPIs), and develop strategies to achieve operational excellence.
  • Ensures a safe, secure, and compliant work environment.
  • Build and manage a high-performing team, including hiring, training, and development.
  • Provide leadership to the team, including setting goals/objectives, providing guidance/feedback, and ensuring the team's overall success.
  • Identify skill gaps within the team and develop strategies for filling those gaps. Support employee development through training, mentoring, and coaching. Identify high-potential employees and create succession plans.

Duties & Responsibilities: 

  • Define and own the company IT and security strategy, aligning infrastructure, systems, and risk posture with company growth, product evolution, and regulatory requirements.
  • Build, lead, and scale a high-performing IT and Security organization, establishing clear operating models, priorities, and accountability across IT and security operations.
  • Oversee end-to-end IT operations and employee technology experience, including onboarding/offboarding, identity and access management, device lifecycle, and enterprise tooling.
  • Own and mature the security program, including governance, risk management, security architecture, vulnerability management, and threat detection and response (SOC).
  • Drive the management —in partnership with our compliance committee — of risk, compliance, and audit, leading HIPAA and SOC 2 readiness, managing audits, and ensuring continuous compliance through strong policies, controls, and documentation.
  • Partner cross-functionally with Engineering, Product, Data, Legal, and People teams to embed security and IT best practices into systems, development lifecycles, and business operations.
  • Drive company initiatives to enhance system reliability, scalability, security, and business continuity, including disaster recovery planning and resilience of critical systems.
  • Own the IT vendor and partner strategy, including selection, negotiation, performance management, and cost optimization while maintaining high security and service standards.
  • Establish and report on KPIs and metrics for IT performance, security posture, and risk, providing actionable insights to executive leadership.
  • Act as a trusted advisor to leadership, guiding decisions on technology investments, emerging threats, and trade-offs between risk, cost, and speed.
  • Own the company's AI governance framework, including acceptable use policies, tool evaluation processes, and an enterprise-wide AI inventory and risk register.
  • Define standards for embedding AI tools into workflows and business processes, ensuring integration architecture, data flows, and security controls align with compliance obligations.
  • Own data classification standards and data loss prevention strategy, ensuring sensitive data — including PHI — is identified, categorized, and protected in alignment with HIPAA and other regulatory requirements.
  • Leverage AI tools as a core part of daily work (drafting, research, iteration) to improve efficiency, quality, and decision-making.

Required Skills:

  • Deep expertise across enterprise security, cloud infrastructure, networking, and IT systems.
  • Strong background in security governance, risk management, and compliance frameworks (HIPAA, SOC 2, or similar).
  • Proven ability to set strategy and influence executive stakeholders, translating technical concepts into business impact.
  • Demonstrated success building and leading high-performing, multi-functional teams.
  • Strong cross-functional leadership and systems thinking in complex environments.
  • Experience developing AI governance frameworks, acceptable use policies, or responsible AI programs.
  • Excellent communication skills, including experience with executive-level presentations and company-wide initiatives.
  • Expertise in identity and access management and enterprise tooling (Google Workspace, JAMF/MDM, Okta/OneLogin, Slack, etc.).
  • Experience defining and operationalizing metrics and performance frameworks.
  • Comfort using AI tools in day-to-day workflows, with a willingness to continuously rethink and improve how work gets done.
  • Curiosity and openness to experimenting with new tools and approaches; prior experience with AI tools is a plus.

Education & Experience:

  • Minimum 10 years of IT or technical security experience, with at least 6 years in a leadership role.
  • Proven track record of scaling enterprise IT and security programs in high-growth startup environments.
  • Experience partnering with executive teams on strategic technology decisions.
  • Hands-on experience managing enterprise security operations, cloud environments, and IT infrastructure.
  • Proven track record of leading security audits, risk assessments, and compliance initiatives.
  • Experience with scripting, automation, and system integrations to streamline IT operations.

Preferred Qualifications: 

  • IT or security certifications (CISSP, CISM, CompTIA Security+, or equivalent).
  • Prior experience in healthcare or HIPAA-regulated environments.
  • Experience leading remote or hybrid IT teams.
  • Advanced knowledge of security automation, threat detection, and response tools.

Octave's Company Values:

The below values drive our day-to-day operations.

  • We’re human beings first. We operate with empathy and kindness – with our clients, with our collaborators, and with ourselves.
  • People deserve better than status quo. We’re willing to tackle the intractable problems, no matter how big, because someone should. We ask big questions, we craft big solutions, and we challenge ourselves and others to make it happen.
  • No bystanders. No stars. No tourists. Each person has been selected to be here, and with that comes a responsibility to bring your expertise, share your ideas, and help make this company better.
  • Partnership paves the path ahead. We don’t operate in a silo, internally or externally. To transform the system, we believe in working with others to create something bigger, better, and stronger.
  • Quality is crucial at scale. Quality is core to our business, and we refuse to sacrifice it as we grow.
  • Progress is a process. In the pursuit of progress, we iterate, reflect, learn, adjust – and always leave things better than we found them.
  • There are people behind every data point. We recognize that numbers tell only one part of the story, and we also do the work to understand impacts at the individual level.

Physical Requirements:

  • Prolonged periods sitting at a desk and working on a computer. 
  • Must be able to frequently communicate with others through virtual meeting applications such as Zoom and Google Meet. 
  • Must be able to observe and communicate information on company provided laptop. 
  • Move up to 10 pounds on occasion. 
  • Must be eligible to work in the United States without sponsorship now or in the future.

Compensation, Equity & Incentives:

Base Salary Range Octave is committed to pay equity and transparency. Our salary ranges are determined by role, level, and location/ zone. Final pay within the posted range will be decided based on a combination of job-related factors, including education, training, experience, and market demands.

  • Geo 1 (All other states & D.C.): $190,200 - $206,500
  • Geo 2 (CO, HI, MD, RI): $209,200 - $220,000
  • Geo 3 (AK, CA, CT, MA, NJ, NY, WA): $218,700 - $220,000

Variable Compensation & Equity

  • Performance Bonus: This role is not currently eligible for bonus incentives.
  • Equity Awards: This role is eligible to participate in Octave’s equity program via Stock Options, subject to the terms of the applicable Equity Incentive Plan.
  • Remote Work Stipend: New full-time employees receive a $300 equipment reimbursement to support a home office setup.
  • Internet & Phone Reimbursement: Full-time employees are eligible for a monthly reimbursement of up to $75 for internet and cell phone related expenses.

Octave is committed to pay equity and transparency. Octave will not discharge or in any other manner coerce, intimidate, threaten, discriminate or retaliate against employees or applicants because they have: (i)  inquired about, discussed, compared, or disclosed their own wages, benefits, or other compensation, or the wages, benefits, or other compensation of another employee or applicant; (ii) asked Octave to provide a reason for the employee's wages or lack of opportunity for advancement; or (iii) aided or encouraged others in exercising their rights to discuss wages, compensation, or benefits, or to seek pay equity.

However, except as otherwise provided by law, employees who have access to the compensation information of other employees or applicants as part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) in compliance with the company's legal duty to furnish information under applicable law .

Comprehensive Benefits:

At Octave, we believe in supporting the "human being first". Here’s a snapshot of the benefits available to eligible employees:

  • Health & Wellness: Choose what works best for you with one High Deductible Health Plan (HDHP) and two PPO medical plan options, plus comprehensive Dental and Vision coverage.
  • Medical Support: Enjoy access to a company-sponsored membership with One Medical for convenient, modern care.
  • Retirement: Plan for your future with a 401(k) that offers both traditional and Roth options. 
  • Paid Time Off: Time to recharge matters. Take advantage of a generous time off policy, up to 15 paid company holidays, and accrued sick time.
  • Financial Protection: We’ve got you covered with company-paid Life, AD&D, and Disability insurance, plus optional extras like Pet, Legal, and Worksite plans (Critical Illness, Hospital Indemnity, and Accident).
  • Parental Leave (Bonding Time): Growing your family? Full-time employees can take paid bonding leave after 6 months, whether it’s a new baby, adoption, or foster placement. Time off increases with tenure.
  • Growth: Keep learning and leveling up with professional development reimbursement for role-related growth opportunities.

How We Use Technology in Hiring:

As part of our hiring process, we may use technology tools, including AI-supported systems, to assist with reviewing applications or documenting interviews. These tools are designed to support our team, not replace human judgment, and final hiring decisions are always made by our team.

This job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice.

Application Instructions:

Please complete the following application. Please note that the U.S. Equal Opportunity Employment Information questions below are used for the purposes of EEOC reporting and are optional to complete. Octave is unable to change these questions and we acknowledge that many of the U.S. Equal Opportunity Employment Information questions are not inclusive or affirming of all aspects of cultural identity. Octave is committed to an inclusive workplace environment, and this information will not inform how we approach hiring or employment.

Create a Job Alert

Interested in building your career at Octave? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Education

Select...
Select...
Select...
Select...
Select...

What's your preferred method of contact?
Select...
Select...
Select...
Select...
Select...

Note: Selecting “no” will not eliminate you from consideration for this role.Message and data rates may apply, depending on your mobile phone service plan. At any time you can get more help by replying HELP to these texts, or you can opt out completely by replying STOP.Our Terms and Conditions


U.S. Standard Demographic Questions

We invite applicants to share their demographic background. If you choose to complete this survey, your responses may be used to identify areas of improvement in our hiring process.
Select...
Select...
Select...
Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Octave’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.