IT & Cybersecurity Compliance Specialist

Other Jobs To Apply

No other job posts for this day.

<p style="min-height:1.5em"><strong>About Pearl</strong></p><p style="min-height:1.5em">Pearl is shaping the future of dentistry with a suite of AI solutions developed to establish higher standards of quality and care for patients worldwide. Since 2019, our team has engineered FDA-cleared computer vision capabilities for interpretation of 2D and 3D dental imagery; industry-leading capabilities which clinicians, practice owners, labs, and insurers use to elevate the efficiency, accuracy, and consistency of dental care around the world.</p><p style="min-height:1.5em"></p><p style="min-height:1.5em"><strong>The Role</strong></p><p style="min-height:1.5em">We are seeking an experienced IT & Cybersecurity Compliance Specialist to manage our IT infrastructure and lead cybersecurity and privacy compliance efforts. This role combines hands-on IT administration with strategic compliance program ownership, ensuring our systems are secure, well-maintained, and aligned with global regulatory frameworks including SOC 2, HIPAA, and GDPR. The ideal candidate is a proactive, detail-oriented professional comfortable spanning both technical IT operations and formal compliance management within a SaaS medical device environment.</p><p style="min-height:1.5em"></p><p style="min-height:1.5em"><strong>Key Responsibilities</strong></p><p style="min-height:1.5em"><strong>IT Infrastructure & Systems Administration</strong></p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Administer and maintain core IT systems including endpoint management, identity and access management (IAM), and SaaS tooling (e.g., Google Workspace, Slack, Notion).</p></li><li><p style="min-height:1.5em">Manage employee onboarding and offboarding processes including provisioning and deprovisioning of accounts, hardware, and system access.</p></li><li><p style="min-height:1.5em">Maintain and enforce IT access controls, role-based permissions, and the principle of least privilege across all systems.</p></li><li><p style="min-height:1.5em">Serve as the first point of escalation for internal IT support requests and tickets, triaging and resolving technical issues.</p></li><li><p style="min-height:1.5em">Manage and maintain the company’s device fleet, including MDM (Mobile Device Management) enrollment, patching, and compliance monitoring.</p></li><li><p style="min-height:1.5em">Administer and monitor cloud infrastructure and SaaS platform configurations for security and availability.</p></li><li><p style="min-height:1.5em">Maintain IT asset inventory and manage software licensing.</p></li></ul><p style="min-height:1.5em"></p><p style="min-height:1.5em"><strong>Cybersecurity & Privacy Compliance</strong></p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Conduct gap assessments to evaluate compliance with security and privacy regulations (e.g., SOC 2, HIPAA, GDPR).</p></li><li><p style="min-height:1.5em">Develop, write, and revise Standard Operating Procedures (SOPs) for security and privacy programs.</p></li><li><p style="min-height:1.5em">Implement and monitor security-related Key Performance Indicators (KPIs) to measure and improve compliance performance.</p></li><li><p style="min-height:1.5em">Assess, document, and report security breaches or incidents, ensuring timely and accurate communication.</p></li><li><p style="min-height:1.5em">Perform security assessments of all new and existing suppliers, including annual reviews.</p></li><li><p style="min-height:1.5em">Conduct Information Security incident reviews and recommend corrective actions.</p></li><li><p style="min-height:1.5em">Manage Corrective and Preventive Actions (CAPAs) related to security and privacy.</p></li><li><p style="min-height:1.5em">Prepare for and manage security and privacy audits, ensuring readiness and compliance.</p></li><li><p style="min-height:1.5em">Complete security questionnaires for clients, vendors, and partners.</p></li><li><p style="min-height:1.5em">Stay current on evolving security and privacy regulations and recommend updates to policies and procedures as needed.</p></li></ul><p style="min-height:1.5em"></p><p style="min-height:1.5em"><strong>Compliance Tooling & Programs</strong></p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Administer and manage the Vanta platform (or equivalent GRC tool) to automate and streamline compliance monitoring and evidence collection.</p></li><li><p style="min-height:1.5em">Oversee the design, delivery, and management of security and privacy training programs for employees.</p></li><li><p style="min-height:1.5em">Design and execute phishing simulation campaigns and related training to enhance employee security awareness.</p></li><li><p style="min-height:1.5em">Host and facilitate recurring security committee meetings and management reviews to align stakeholders on compliance objectives.</p></li></ul><p style="min-height:1.5em"></p><p style="min-height:1.5em"><strong>Qualifications</strong></p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">3+ years of experience in IT administration, systems management, or a combined IT/security role.</p></li><li><p style="min-height:1.5em">3+ years of experience implementing and maintaining SOC 2 certification.</p></li><li><p style="min-height:1.5em">3+ years of experience with HIPAA, GDPR, and other global privacy frameworks.</p></li><li><p style="min-height:1.5em">Proven track record of managing compliance programs, including audits, risk assessments, and CAPAs.</p></li><li><p style="min-height:1.5em">Hands-on experience with compliance tools such as Vanta or similar platforms.</p></li><li><p style="min-height:1.5em">Demonstrated experience with endpoint management, IAM platforms, MDM solutions, and SaaS administration.</p></li><li><p style="min-height:1.5em">Strong understanding of cybersecurity best practices, incident response, and supplier risk management.</p></li><li><p style="min-height:1.5em">Excellent written and verbal communication skills, with the ability to translate complex requirements into actionable processes.</p></li><li><p style="min-height:1.5em">Ability to work independently and collaboratively in a fast-paced environment.</p></li><li><p style="min-height:1.5em">Relevant certifications (e.g., CISA, CISM, CISSP, CompTIA Security+, or equivalent) are a plus.</p></li></ul><p style="min-height:1.5em"></p><p style="min-height:1.5em"><strong>Preferred Qualifications</strong></p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Experience in a SaaS company is strongly preferred.</p></li><li><p style="min-height:1.5em">Experience in a medical device company and/or supporting FDA submissions.</p></li><li><p style="min-height:1.5em">Experience with ISO 27001, ISO 27701, CCPA, or other international security/privacy frameworks.</p></li><li><p style="min-height:1.5em">Background in managing phishing simulation programs and employee training initiatives.</p></li><li><p style="min-height:1.5em">Familiarity with SaaS-specific compliance challenges and customer-facing security requirements.</p></li><li><p style="min-height:1.5em">Experience with Google Workspace administration and IT helpdesk/ticketing workflows.</p></li><li><p style="min-height:1.5em">Comfort operating as a one-person or small-team IT function in a high-growth environment.</p></li></ul><p style="min-height:1.5em"></p><p style="min-height:1.5em"><strong>What We Offer</strong></p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Competitive Benefit and Compensation Offerings</p></li><li><p style="min-height:1.5em">Ongoing Training and Development Opportunities</p></li><li><p style="min-height:1.5em">Unaccrued, Flexible PTO</p></li><li><p style="min-height:1.5em">Remote Work</p></li></ul>

Back to blog