Director , Information Security and IT
Industry Other industries
Industry Other industries
How you will have an impact - Lead Luna's enterprise cybersecurity strategy, roadmap, and security operations, continuously strengthening our security posture across cloud infrastructure, endpoints, business systems, and enterprise applications. - Build, mature, and maintain a comprehensive information security program, including security policies, standards, governance, risk management, and security awareness initiatives. - Serve as the technical leader for enterprise IT operations, ensuring reliable, secure, and scalable technology services that support business growth and an exceptional employee experience. - Own Identity and Access Management (IAM), including SSO, MFA, provisioning/deprovisioning, privileged access management, and periodic access reviews. - Oversee endpoint management, Mobile Device Management (MDM), device lifecycle, asset management, and enterprise SaaS administration. - Lead vulnerability management, threat detection, penetration testing, incident response, disaster recovery, backup, and business continuity planning. - Partner with Engineering, Product, Compliance, Legal, Finance, Operations, and People teams to integrate security best practices into enterprise technology and business operations. - Ensure compliance with HIPAA, HITECH, and other applicable regulatory and security frameworks through technical safeguards, documentation, audits, and remediation activities. - Manage third-party security assessments, vendor risk reviews, customer security questionnaires, and ongoing technology vendor relationships. - Evaluate emerging technologies and recommend secure, scalable solutions that improve operational effectiveness while balancing risk, cost, and business priorities. - Mentor and develop a high-performing IT team while remaining actively involved in technical execution, architecture decisions, and day-to-day operational support. - Communicate technology strategy, cybersecurity risks, investment recommendations, and program progress to executive leadership.
What you need - 8+ years of progressive experience leading information security, enterprise IT, or blended technology functions, including hands-on ownership of enterprise cybersecurity programs. - Demonstrated success building, implementing, and maturing cybersecurity programs while balancing security, compliance, and business objectives in a healthcare or other highly regulated environment. - Direct experience supporting healthcare technology environments, including healthcare systems, enterprise applications, and technology platforms within HIPAA-regulated organizations. - Strong knowledge of healthcare security and compliance requirements, including HIPAA, HITECH, PHI protection, security governance, risk assessments, audits, and remediation activities. - Hands-on experience with cloud security (AWS, Azure, or GCP), identity and access management (IAM), Single Sign-On (SSO), Multi-Factor Authentication (MFA), endpoint management, Mobile Device Management (MDM), and enterprise infrastructure. - Experience leading enterprise IT operations, technology roadmaps, incident response, disaster recovery, business continuity, vulnerability management, and security operations. - Proven ability to lead and mentor technical teams while remaining hands-on with technical execution in a fast-paced, high-growth environment. - Previous experience as a Director, or as a Senior Manager operating with Director-level scope and responsibility. - Experience partnering with executive leadership to develop technology strategy, evaluate risk, and communicate complex technical concepts to both technical and non-technical audiences. - Experience managing third-party vendors, security assessments, customer security questionnaires, and enterprise technology implementations.