IT Manager

4 days ago

Toronto ON, Toronto Census Division, ON; Ontario, Canada RXinsider LTD. Full-time €85,000 - €110,000 Temporary

The Opportunity

MedMe is building out a dedicated, in-house IT and internal security function to support our growing team. You'll step into a role with established tooling and processes already in place across device management, endpoint detection, email security, and access automation, and will take ownership of operating and evolving this function going forward. This is our first dedicated IT hire. You'll inherit a stack to deploy, a fleet across two countries, and a compliance path running from SOC 2 toward HITRUST. The role combines architecture and execution: you'll design how IT works here and also be the one running it day to day.

About MedMe Health

At MedMe, we are passionate about empowering pharmacists to provide services beyond just prescribing. Our mission is to build an all-in-one cloud-based platform that enables pharmacists to schedule, document, and manage clinical services at scale. With over 4,500 pharmacies using our software, we've facilitated more than 25 million patient services, transforming pharmacies into community health hubs across North America.

What You'll Do

Identity and access

  • Own access provisioning and deprovisioning across the SaaS environment, automating wherever it's safe to do so
  • Administer Google Workspace, SSO, and the password manager
  • Run access reviews to audit-ready standard, and govern contractor and offshore access against our customer commitments on PHI

Devices and endpoints

  • Own the MDM platform: migration off our current provider, configuration baselines, endpoint policy
  • Manage the device fleet lifecycle end to end, procurement support, cross-border logistics, secure disposal
  • Build endpoint controls to HITRUST-ready standard

Security operations

  • Operate email security, endpoint detection, and account protection tooling: detection tuning, alert triage
  • Own incident response, escalation, remediation, communication, post-incident review
  • Manage vulnerability and patch programs, external penetration testing, and security awareness training

Data protection and resilience

  • Close our current DLP gap, recommending tooling or compensating controls
  • Own backup coverage, restore testing, and documented recovery procedures
  • Maintain retention policies and support legal hold and discovery requests

Infrastructure and workplace technology

  • Own network, VPN, DNS, and certificate management
  • Administer the collaboration platforms the company runs on, permissions, external sharing controls
  • Govern AI tool adoption: sanctioned tools, data handling review, detection of unapproved use

Service delivery

  • Own IT onboarding and offboarding to a consistent, documented standard
  • Act as the point of contact for support, reducing recurring volume through automation and self-serve documentation
  • Report monthly on service performance, endpoint compliance, spend, and open risk

Compliance and vendor management

  • Gate new tooling through security and procurement review
  • Produce audit evidence for SOC 2 and HITRUST, and support customer security questionnaires alongside Security and Legal
  • Own the IT budget, including vendor negotiations and renewals

About You

  • 5+ years in IT operations or IT security, with hands-on ownership of endpoint management and identity for a distributed team
  • Direct experience deploying and operating email security and endpoint detection tooling
  • Strong Google Workspace administration, including security and conditional access controls
  • Practical networking experience: firewall, wireless, VPN, DNS, certificates
  • Working knowledge of SOC 2, HIPAA, HITRUST, or a comparable framework, including audit evidence requirements
  • Scripting or automation ability sufficient to build and maintain internal workflows
  • Comfort operating as the sole owner of a function
  • Nice to Have: Healthcare or another regulated environment handling PHI or PII; HITRUST readiness or certification experience; Vanta or comparable compliance automation; Multi-entity or cross-border operations

Success in This Role Looks Like

  • 30 days: Full visibility into current infrastructure, MSP scope, and vendor dependencies; MSP transition plan drafted and open-decision evaluation underway (DLP, backup/recovery, vulnerability management, MDR)
  • 60 days: MSP handover underway; device management and email security piloted on the fleet; recommendations on the open decisions taking shape with cost and rationale
  • 90 days: MSP relationship retired; device management and email security deployed across the fleet with provisioning automation live; reco