VIA HealthTech

IT Security & Compliance Lead

Remote, United States remote Entry Salary not listed
remote Technology & IT Curated
Sign in to apply Free account — we bring you straight back to this role.

About the role

VIA HealthTech automates psychotherapy documentation — from session notes to psychological reports — so therapists spend less time on admin and more time with patients.

We work at the intersection of mental healthcare, AI, and software. Security is central to what we build: we process highly sensitive data and already hold C5 and ISO27001 certification.

Tasks

We are looking for a hands-on IT Security & Compliance Lead to own security and compliance end-to-end at VIA.

This is a broad role in a small team. You will not only define policies — you will implement systems, configure tools, improve cloud and product security, run audits, and work directly with engineering to make security a practical part of how we build.

Your goal is to make VIA more secure while helping the team move faster, not slower.

What you’ll do

Own internal IT security end-to-end: devices, access management, 2FA, endpoint protection, policies, onboarding and offboarding

Professionalize and operate our internal IT setup

Own IT Compliance (ISO27001 and C5), including audits, evidence management, policies, risk management, corrective actions, auditor communication, and internal training

Improve cloud security across infrastructure, access control, encryption, logging, monitoring, and operational processes

Work closely with engineering on product security across web, desktop, mobile, backend, and AI-related systems

Help embed security into the development lifecycle without creating unnecessary overhead

Coordinate external security work such as penetration tests, security reviews, and vendor assessments where needed

Identify security gaps, prioritize what matters, and implement pragmatic improvements

Requirements

Required:

Strong hands-on experience in IT Security, Information Security, Cloud Security, or a closely related field

Practical experience securing cloud-based software products and internal IT environments

Solid understanding of IAM, endpoint security, device management, encryption, logging, access control, and incident response

Experience with ISO27001 and/or C5, ideally including audit ownership or major audit involvement

Ability to work directly with engineering teams on technical security topics

Strong operational ownership: you see what needs to be done and make it happen

Pragmatic judgment: you know how to raise the security bar without blocking a fast-moving team

Clear communication and comfort working in an async-first startup environment

Nice to have:

Experience in healthcare, regulated environments, or companies handling highly sensitive data

Experience with application security, secure SDLC, threat modeling, or vulnerability management

Experience with desktop app, mobile app, or AI security

Experience setting up or improving security processes in an early-stage or fast-growing company

What matters beyond the checklist

We are a 10-person startup. This role requires breadth, ownership, and hands-on execution.

You should be comfortable moving between strategic questions and operational details: one day improving cloud security architecture, another day tightening access policies, preparing audit evidence, reviewing product security, or configuring internal IT tools.

We are not looking for someone who only writes policies. We are looking for someone who builds and operates the security foundation VIA needs as it scales.

Benefits

Office in Berlin Mitte, flexible hours

Direct access to founders, CTO, and the full multidisciplinary team

Broad ownership over a core company function

Equity participation

No micromanagement — results over hours logged

Work at the intersection of AI, healthcare, software, and security

Find more English Speaking Jobs in Germany on Arbeitnow

Interview prep

Walk in with sharper answers.

Use this as a quick practice sheet before you speak with the employer.

Role
Technology & IT Writing Security Compliance Technology remote

Likely questions

  1. Tell us about work you have done that is close to the IT Security & Compliance Lead role.
  2. How would you approach your first 30 days at VIA HealthTech?
  3. Which of Writing, Security and Compliance have you used recently, and what did it help you achieve?
  4. Describe a time you solved a problem without waiting to be told exactly what to do.
  5. How do you stay organised and communicate clearly when working remotely?

Prepare before the call

  • A recent example that proves your experience with Writing, Security and Compliance.
  • One short story with a problem, your action, and the result.
  • Two examples that show the strengths listed on your CV.
  • A clear reason why this role and company interest you.
  • Your availability, preferred work style, and salary expectations.

Ask them

  • What would success look like in the first 90 days?
  • What are the main problems this hire should help solve?
  • How does the team give feedback and measure good work?
  • What does a normal working week look like for this role?
Practice line

I am interested in the IT Security & Compliance Lead role because I can bring practical experience in Writing, Security and Compliance, learn the team quickly, and contribute to the outcomes VIA HealthTech needs from this hire.

Related jobs.

More roles from this company or category.