Tonic

Head of Information Security

Remote

Not SpecifiedCompensation
Senior (5 to 8 years), Expert & Leadership (9+ years)Experience Level
Full TimeJob Type
UnknownVisa
Cybersecurity, Information TechnologyIndustries

Position Overview

  • Location Type: Remote
  • Employment Type: Full-Time
  • Salary: (Not provided in the description)

Tonic.ai is seeking a dynamic leader to define, communicate, and execute Tonic’s information security and Technology roadmap. This role is ideal for someone interested in guiding the overall security and compliance program to reduce security risk across the company.

Responsibilities

  • Security Management & Operations:
    • Evaluate and drive updates and/or migration of the application and infrastructure portfolio to achieve Tonic’s security and resiliency requirements.
    • Own security operations and incident responses to continuously monitor, defend, and respond to the security status of the organization.
    • Identify, negotiate, and select outside services, computer hardware, and software services with a clear framework of selection criteria.
  • Governance & Compliance:
    • Oversee Tonic’s governance frameworks and compliance with relevant regulations and standards (e.g., SOC 2, GDPR, HIPAA).
    • Ensure continuous readiness for audits and certifications, partnering closely with external auditors and internal stakeholders.
    • Develop and maintain company-wide security and compliance policies, ensuring they remain current and well-communicated.
  • Security & Risk Strategy:
    • Define, implement, and maintain Tonic’s overall security, compliance, privacy, and IT strategy and roadmap in alignment with business goals.
    • Continuously evaluate emerging threats and industry trends, adapting the security strategy to anticipate and mitigate risks.
  • IT Infrastructure:
    • Own and manage day-to-day IT operations, ensuring our tools, systems and infrastructure meet the needs of a growing, global workforce.
    • Manage vendor relationships, contract negotiations, and service-level agreements for critical technology services.
  • Sales and Go-to-Market Support:
    • Ensure Tonic’s security and compliance posture aligns with the requirements of the company’s existing and target customers, as well as with industry best practices.
    • Collaborate with Tonic’s leadership team to ensure proper data governance practices and compliance are fulfilled throughout the organization.
    • Ensure that Tonic employees adhere to and are compliant with the security requirements of our company.
    • Work with Tonic’s Sales, Customer Success, and Solutions Architect teams to answer customer third-party risk management questionnaires to protect Tonic’s liability while simultaneously supporting sales.

Requirements

  • Experience: 10+ years of experience with at least 5 in information security, and 3+ years within a high-growth startup.
  • Skills: Demonstrated success running an enterprise-wide information security program that has achieved SOC2 and HIPAA attestation.
  • Knowledge: Ideally, knowledge and some experience with security and compliance obligations required for government contracting (e.g., FedRAMP, NIST 800-171, DFARS).
  • Cloud Computing: Working knowledge of securing cloud computing environments (specifically AWS).

Company Information

  • Company: Tonic.ai

Skills

Information Security
Security Management
Incident Response
SOC 2
GDPR
HIPAA
Compliance
Risk Management
IT Infrastructure
Vendor Management
Contract Negotiation

Tonic

Data management solutions for developers and teams

About Tonic

Tonic.ai provides data management solutions aimed at software developers, data scientists, and quality assurance teams. Their platform enables users to de-identify, subset, and synthesize data, which helps protect sensitive information while still making it useful for testing and development. Tonic.ai operates on a subscription-based model, offering various service tiers to accommodate different organizational needs. This approach allows clients, ranging from small startups to large enterprises, to automate data pipelines and generate realistic demo data, ultimately saving time and reducing bugs in software development. Tonic.ai stands out from competitors by seamlessly integrating with both SQL and NoSQL databases, making it a versatile choice for data-driven organizations. The company's goal is to enhance data privacy and streamline data management processes to accelerate software development cycles.

San Francisco, CaliforniaHeadquarters
2018Year Founded
$45.6MTotal Funding
SERIES_BCompany Stage
Data & Analytics, Enterprise SoftwareIndustries
51-200Employees

Benefits

Competitive salary and equity
Unlimited paid time off
401k plan with employer contribution
Medical, dental, and vision insurance
One Medical membership
Generous parental leave policy
Remote-friendly work environment

Risks

Competition from CustomGPT.ai threatens Tonic's position in AI-driven data solutions.
Shift towards RAG may require Tonic to adapt its offerings to stay competitive.
Pay-as-you-go model could pressure Tonic's subscription-based business model.

Differentiation

Tonic specializes in synthetic data for privacy-preserving software development and testing.
The company offers tools for database subsetting, de-identification, and data synthesis.
Tonic's platform integrates with SQL and NoSQL databases, enhancing its versatility.

Upsides

Growing interest in synthetic data boosts Tonic's AI development opportunities.
Rising adoption of RAG systems aligns with Tonic's data synthesis capabilities.
Cloud-based solutions drive demand for Tonic's scalable, flexible platforms.

Land your dream remote job 3x faster with AI