Chief Technology Officer
About eMed
eMed is a digital health company focused on chronic care, with a US entity alongside its UK operations, and expanding internationally footprint
Role Summary
eMed is looking for a US-based VP of IT to build and lead the technology infrastructure, security, and systems function that underpins a fast-growing, multi-market digital health business. This is a hands-on leadership role covering IT infrastructure, information security, data governance, business systems, and vendor management. Given eMed's US operations, HIPAA/HITECH compliance and safeguarding of protected health information (PHI) sit at the core of this role, alongside supporting other markets' regimes (eg NHS DSPT in the UK and equivalent standards elsewhere).
Key Responsibilities
IT Strategy & Infrastructure
- Own eMed's IT strategy and roadmap, aligning infrastructure investment with the pace and shape of international expansion.
- Lead commercial supplier negotiations
- Oversee corporate IT: device management, networking, telephony, identity and access management, and workplace technology across all office locations.
- Build scalable IT processes and documentation that can support new-market launches without adding proportional headcount.
Security & Compliance
- Own HIPAA/HITECH compliance as the primary security and privacy framework for the business, including the Security Rule, Privacy Rule, breach notification requirements, and the Business Associate Agreement (BAA) program with vendors and partners.
- Own broader information security strategy, policy, and operational controls, including certifications such as SOC 2 Type II, HITRUST, Cyber Essentials Plus, and ISO 27001 as needed by market.
- Track and maintain compliance with US state-level health and consumer privacy laws (e.g. CCPA/CPRA and state 'health data' privacy statutes), alongside the NHS Data Security and Protection Toolkit (DSPT) in the UK and equivalent frameworks in other markets.
- Lead incident response, vulnerability management, and third-party security risk assessment for vendors and pharmacy/clinical partners.
- Act as a key stakeholder in privacy and security risk assessments alongside Legal and Clinical teams.
Data Governance & Privacy
- Partner with Legal, Clinical, and Engineering to ensure data handling meets GDPR, UK data protection law, and market-specific requirements (e.g. Germany's DiGA data hosting rules).
- Own the data classification, retention, and access control framework for patient and business data across regions.
- Support regulatory and audit engagements, including those tied to NHS partnerships and international regulators.
Business Systems & Vendor Management
- Own core business systems (e.g. NetSuite, Google Workspace, Slack, CRM, and analytics/BI tooling such as Tableau) and their integration into a coherent internal platform.
- Manage relationships and commercial terms with key infrastructure and software vendors, balancing cost, reliability, and security.
- Evaluate and onboard new systems required to support new markets, sub-brands, and B2B/NHS partnerships.
Enterprise & B2B Client Onboarding
- Act as technical support for onboarding large, blue-chip B2B clients (employers, insurers, and healthcare partners), owning the technical and security workstream of the sales and procurement cycle.
- Own responses to enterprise security questionnaires, RFPs, and vendor risk assessments (e.g. SIG, CAIQ-style reviews), and keep a current library of audit evidence (SOC 2/HITRUST/ISO 27001 reports, pen test summaries, DSPT status) ready for due diligence.
- Lead execution of Business Associate Agreements (BAAs) and other data protection terms required by blue-chip US employers, insurers, and health systems before go-live.
- Partner with Commercial and Legal on data processing agreements, uptime/support SLAs, and information security addenda in enterprise contracts.
- Build a repeatable enterprise onboarding playbook so client go-lives are predictable and don't rely on ad hoc engineering support.
Business Continuity & Risk
- Own disaster recovery and business continuity planning for IT systems, with regular testing.
- Maintain an IT risk register and report on IT and security risk to the leadership team and board as required.
Team Leadership
- Build and lead the IT function as eMed scales, including hiring, mentoring, and structuring the team appropriately for a multi-market healthcare business.
- Act as a trusted advisor to the CEO, CFO, and senior leadership on technology risk, investment, and capability.
What We're Looking For
Experience
- Significant experience in a senior IT leadership role (Head of IT, Director of IT, or VP of IT), ideally in a scaling company.
- Hands-on experience owning HIPAA compliance and PHI security in a US healthcare, digital health, or health-tech company is required.
- Track record owning information security programmes and compliance frameworks (SOC 2, HITRUST, ISO 27001, or equivalent) and running enterprise/blue-chip client security due diligence.
- Experience supporting multi-country or multi-entity operations, ideally including EU data residency considerations.
- Comfortable operating in a lean, fast-moving environment — this role will need to be both strategic and hands-on.
Skills & Attributes
- Excellent stakeholder management skills, able to work closely with Clinical, Legal, Commercial, and Engineering leadership.
- Clear, pragmatic communicator able to translate technical risk into business terms for the CEO and board.
- Comfortable with ambiguity and building processes from scratch rather than inheriting a mature function.
Nice to Have
- Experience negotiating and managing BAAs at scale with large enterprise clients (employers, health plans, or health systems).
- Familiarity with UK/EU frameworks (NHS DSPT, DTAC, GDPR, DiGA) given eMed's international footprint.
- Experience supporting due diligence processes (major partner/enterprise contracts).