Join our mission to make quality healthcare understandable, accessible and affordable for all.
The Role
Lead IT and security operations for a distributed workforce: manage ITSM, device provisioning, vendor/BAA management, HIPAA compliance, risk assessments, incident response, DR/BC planning, audits, and employee security training.
Summary Generated by Built In
Sana’s vision is simple yet bold: make healthcare easy.
All of us can agree that healthcare is simply too hard in the US. And our members feel that pain day in and day out. We aim to create an experience that simply feels easy when you need to access our healthcare system. If you need something, you know where to go to get it with care that is a click (or as few clicks as possible!) away.
What’s beautiful about a vision oriented toward “easy” is how it imparts a singular feeling. We instinctively know as humans when something is easy versus hard, even if we can’t explain why. We fight as a company to make an easy pathway available to all our members at every stage of their healthcare journey. If you feel passionate about delivering better healthcare to small businesses through a seamless care experience and affordable benefits, join us!
Sana is looking for a Senior IT Manager to join our small but growing team. As a successful candidate, you will be accountable for the overall implementation, management, security, and documentation of company IT systems, as well as the growth of ITSM and information security practices across the organization. This includes partnering cross-functionally to maintain strong security controls, supporting compliance initiatives, and ensuring company systems and data are protected through thoughtful governance and best-in-class tooling.
You will also own the IT, security, and data components of HIPAA compliance—maintaining administrative, technical, and physical safeguards; managing access controls and audit readiness; supporting vendor security reviews and BAAs; and ensuring the secure handling of PHI across systems and workflows. You are an enthusiastic, warm individual who loves to provide support to your fellow peers, can collaborate effectively with teams across the business, and are knowledgeable about SaaS-based IT and security tools.
We are building a distributed team and encourage all applicants to apply, regardless of location.
What you will do:
- Lead IT Support for a remotely distributed workforce through implementing ITSM best practices
- Fully manage the installation, configuration, and maintenance of physical and virtual assets and serve as the go-to IT resource for company employees
- Manage onboarding and off-boarding processes of employees, including computer/hardware procurement, setup, and account provisioning on Apple and Windows Devices.
- Create accurate and clear technical, security, and HIPAA-related documentation, develop support playbooks and process governance, own data flow maps and systems inventory
- Build and maintain vendor relationships, including tracking vendors, contract terms, security requirements, Business Associate Agreements (BAAs) maintenance, and policies
- Oversee and manage the organization's security strategy and initiatives to protect its assets, employees, and stakeholders and ensure compliance with industry standards and regulations
- Conduct regular risk assessments to identify potential security and HIPAA vulnerabilities, develop mitigation plans, and lead the response to security incidents, coordinating efforts to minimize impact and recover from breaches
- Develop and test business continuity and disaster recovery plans
- Own and support the IT, security, and data infrastructure required to maintain HIPAA compliance across the organization as required under HIPAA Security and Privacy Rules
- Partner with Legal, People, Operations, and Engineering to ensure appropriate safeguards are in place for the protection of PHI and other sensitive data
- Support internal and external audits, security questionnaires, and customer due diligence related to HIPAA and data protection practices
- Develop and deliver employee security and HIPAA awareness training in partnership with People Ops and Legal
- Assist in investigation and response to potential security or privacy incidents involving PHI, including documentation and remediation tracking
- Continuously improve controls and processes to strengthen Sana’s security posture and ensure ongoing HIPAA compliance as the organization scales
About you:
- Bachelor’s degree in Information Security, Computer Science, or a related field preferred; Master’s degree is a plus.
- Minimum of 8 years’ experience in the IT industry, with at least 5 years in information security roles.
- 5+ years of experience with management of IT Assets, Services and Cloud applications, procurement, and employee on-boarding/off-boarding workflows
- Experience working in a small company going through hyper-growth
- Strong analytical and problem-solving abilities.
- Exposure to HIPAA compliance highly desirable.
- Advanced certifications such as CISSP, CISM, or CISA are highly desirable.
- In-depth knowledge of information security standards, frameworks, and best practices (e.g., ISO 27001, NIST, CIS Controls).
- In-depth knowledge of IT standards, frameworks, and best practices (e.g., ITIL, COBIT).
- Solid understanding of networking, systems, and information security principles.
- Strong project management skills.
Benefits:
- Remote company with a fully distributed team – no return-to-office mandates
- Flexible vacation policy (and a culture of using it)
- Medical, dental, and vision insurance with 100% company-paid employee coverage
- 401(k), FSA, and HSA plans
- Paid parental leave
- Short and long-term disability, as well as life insurance
- Competitive stock options are offered to all employees
- Transparent compensation & formal career development programs
- Paid one-month sabbatical after 5 years
- Stipends for setting up your home office and an ongoing learning budget
- Direct positive impact on members’ lives – wait until you see the positive feedback members share every day
About Sana
Founded in 2017, Sana is a health plan solution built for small and midsize businesses — designed around our integrated primary care service, Sana Care. It’s the foundation of everything we build: ensuring members can easily access high-quality, affordable care while employers and brokers have the tools they need to manage company benefits with confidence.We’ve been remote-first since day one, with a fully distributed team across the U.S. We value curiosity, ownership, and speed — and we build in the open, together. If you’re energized by solving complex, meaningful problems and want to help reshape how healthcare works from the inside out, we’d love to meet you.
Top Skills
Macos,Windows,Saas,Cloud Applications,Itsm,Baa,Hipaa,Iso 27001,Nist,Cis Controls,Itil,Cobit
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
We know dealing with insurance carriers can be frustrating. Long hold-times on the phone for support, confusing benefits that leave you uncertain about your coverage and paperwork that would stump anyone.
From providing simplified plans, to ensuring you pay an honest price, to prioritizing personalized customer service, Sana is on a mission to create a more human health plan that has your back every step of the way.
Sana is hiring in Operations, Product, Engineering, Sales and more - APPLY TODAY!
http://bit.ly/joinsana
Gallery








