Core Sound Imaging, Inc. provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.
Director of Information Technology
Location
United States
Posted
12 days ago
Salary
Not specified
No structured requirement data.
Job Description
About the role
The Director of Information Technology is hands on to lead and scale our IT, security, cloud, and infrastructure capabilities as we continue to grow as a SaaS health technology company. This role is critical to ensuring the reliability, security, and compliance of our platforms while enabling productivity across the organization.
You will be responsible for corporate IT operations, cloud infrastructure, and DevOps practices, networking, and information security. The ideal candidate blends strong technical depth with strategic leadership, operational excellence, and a security-first mindset appropriate for regulated healthcare environments.
What you'll do
IT & Infrastructure Management
- Own and operate corporate IT systems including endpoint management, identity and access management, collaboration tools, and internal applications.
- Design, implement, and maintain scalable, secure, and reliable cloud infrastructure leveraging AWS, Entra, and or cloud native platforms.
- Oversee networking architecture including VPNs, firewalls, segmentation, and connectivity between cloud and corporate environments.
- Establish IT standards, policies, and procedures to support a growing, distributed workforce.
- Automation: Foster a culture of Infrastructure as Code (IaC) using tools like Terraform and Ansible to eliminate manual bottlenecks.
Security Compliance
- Lead the company’s information security program, including policies, risk management, incident response, and security operations.
- Ensure compliance with applicable regulatory and industry standards such as HIPAA, SOC 2, ISO 13485, and other customer or partner requirements.
- Partner with Compliance and Engineering teams to support audits, risk assessments, and vendor security reviews.
- Drive security awareness and training across the organization.
DevOps & Cloud Engineering
- Lead DevOps strategy including CI/CD pipelines, infrastructure as code, monitoring, logging, and reliability practices.
- Partner closely with Engineering to improve system availability, performance, scalability, and cost optimization.
- Establish and track SLOs, SLAs, and operational metrics for production systems.
- Own disaster recovery, business continuity, backup, and resiliency planning
Team Leadership & Cross-Functional Collaboration
- Build, mentor, and manage a high-performing team across IT operations, cloud engineering, and security.
- Serve as a trusted partner to Engineering, Product, Finance, and Operations leaders.
- Manage vendors and service providers, including MSPs, security tools, and cloud partners.
- Support due diligence and integration activities related to customer security reviews, partnerships, or acquisitions.
Strategy & Planning
- Develop and execute an IT and infrastructure roadmap aligned with company growth and business objectives.
- Own budgeting, forecasting, and cost management for IT, security, and cloud infrastructure.
- Evaluate and implement tools and technologies that improve efficiency, security, and scalability.
Qualifications
- Bachelor’s degree in a relevant field such as Computer Science, Information Technology, Management Information Systems, Engineering, or a related technology discipline.
- 8–12+ years of experience in IT, infrastructure, cloud engineering or DevOps, with at least 5 years in a leadership role.
- Strong experience operating SaaS platforms in cloud environments preferably AWS.
- Demonstrated ownership of security and compliance programs in regulated environments (healthcare strongly preferred).
- Hands-on knowledge of:
1) Identity and access management (SSO, MFA, RBAC)
2) Cloud networking and security architecture
3) CI/CD pipelines and infrastructure as code (Terraform, CloudFormation, etc.)
4) Endpoint management and corporate IT tooling
- Proven ability to scale systems and processes in a growing organization.
Preferred:
- Experience in health tech, medical devices, or regulated SaaS environments.
- Familiarity with HIPAA, SOC 2 Type II, ISO 13485, or similar frameworks.
- Experience supporting remote-first or distributed teams.
- Strong vendor management and audit support experience.
Leadership Competencies:
- Security-first and risk-aware mindset
- Strong operational discipline and attention to detail
- Clear communicator who can translate technical concepts for non-technical stakeholders
- Pragmatic, hands-on leader who balances speed with reliability and compliance
- Collaborative partner with a customer- and employee-centric approach
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Overview As a Principal Security Consultant, you will function as a Security Advisory Services lead Security Consultant for ePlus service solutions, reporting to the Managing Security Consultant, to drive Advisory Services delivery/revenue growth and capture security program serv...
Information Security Engineer III managing PCI-DSS compliance and audit governance.
This role is responsible for making our software secure by design and keeping it secure throughout its lifecycle — from architecture and development to deployment and operations. The Architect will define security standards, embed security into engineering workflows, and ensure o...
Key duties involve creating, modifying, and managing user accounts and access privileges across on-premises and cloud security directories, ensuring compliance with established rules and processes. The role also requires handling security incidents related to Identity and Access Management (IAM) and participating in the improvement and evolution of IAM practices.