SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Pearl is an AI-driven dental technology company that has developed FDA-cleared computer vision solutions for dental imaging interpretation since 2019. The company serves clinicians, practice owners, labs, and insurers globally.
You will manage Pearl's IT infrastructure and lead cybersecurity and privacy compliance efforts in a SaaS medical device environment. This role uniquely combines hands-on IT administration with strategic compliance program ownership, requiring expertise across both technical operations and formal regulatory compliance.
IT Infrastructure & Systems Administration:
- Administer and maintain core IT systems including endpoint management, identity and access management (IAM), and SaaS tooling (Google Workspace, Slack, Notion).
- Manage employee onboarding and offboarding, including account provisioning/deprovisioning, hardware, and system access.
- Maintain IT access controls, role-based permissions, and principle of least privilege across all systems.
- Serve as first point of escalation for internal IT support requests, triaging and resolving technical issues.
- Manage device fleet including MDM enrollment, patching, and compliance monitoring.
- Administer and monitor cloud infrastructure and SaaS platform configurations.
- Maintain IT asset inventory and manage software licensing.
Cybersecurity & Privacy Compliance:
- Conduct gap assessments for SOC 2, HIPAA, GDPR, and other regulatory frameworks.
- Develop and revise Standard Operating Procedures (SOPs) for security and privacy programs.
- Implement and monitor security KPIs to measure compliance performance.
- Assess, document, and report security incidents with timely communication.
- Perform security assessments of suppliers with annual reviews.
- Conduct information security incident reviews and recommend corrective actions.
- Manage Corrective and Preventive Actions (CAPAs) related to security and privacy.
- Prepare for and manage security and privacy audits.
- Complete security questionnaires for clients, vendors, and partners.
- Stay current on evolving regulations and recommend policy updates.
Compliance Tooling & Programs:
- Administer Vanta platform (or equivalent GRC tool) for compliance monitoring and evidence collection.
- Oversee design and delivery of security and privacy training programs.
- Design and execute phishing simulation campaigns and related training.
- Host and facilitate recurring security committee meetings and management reviews.
Requirements:
- 3+ years of experience in IT administration, systems management, or combined IT/security role.
- 3+ years implementing and maintaining SOC 2 certification.
- 3+ years with HIPAA, GDPR, and other global privacy frameworks.
- Proven track record managing compliance programs including audits, risk assessments, and CAPAs.
- Hands-on experience with compliance tools such as Vanta or similar platforms.
- Demonstrated experience with endpoint management, IAM platforms, MDM solutions, and SaaS administration.
- Strong understanding of cybersecurity best practices, incident response, and supplier risk management.
- Excellent written and verbal communication skills; ability to translate complex requirements into actionable processes.
- Ability to work independently and collaboratively in fast-paced environment.
- Relevant certifications (CISA, CISM, CISSP, CompTIA Security+, or equivalent) are a plus.
Preferred Qualifications:
- Experience in a SaaS company.
- Experience in a medical device company and/or supporting FDA submissions.
- Experience with ISO 27001, ISO 27701, CCPA, or other international security/privacy frameworks.
- Background managing phishing simulation programs and employee training initiatives.
- Familiarity with SaaS-specific compliance challenges and customer-facing security requirements.
- Experience with Google Workspace administration and IT helpdesk/ticketing workflows.
- Comfort operating as a one-person or small-team IT function in high-growth environment.