Director, Information Security and IT
Job description
Director , Information Security and IT at Lunaphysicaltherapy.
About the role
The Director of Information Security and IT at Lunaphysicaltherapy is entrusted with owning the complete lifecycle of the organization's security strategy and operational execution. You will architect and govern the enterprise cybersecurity program, driving initiatives that protect critical assets while enabling scalable business innovation. This position requires hands-on leadership to evolve security controls, processes, and tooling in alignment with a dynamic threat landscape and stringent regulatory obligations. You will be responsible for establishing the standards, policies, and governance that define how technology operates securely and efficiently across the entire enterprise. The role demands close collaboration with technology and business stakeholders to ensure security is embedded into every initiative rather than treated as an afterthought. You will serve as the central authority for technology risk, advising leadership on complex decisions that impact the organization's reputation, continuity, and growth. Ultimately, this position owns the end-to-end delivery of secure, reliable, and high-performing technology services that empower the workforce and uphold the mission of Lunaphysicaltherapy.
Key facts
What you'll do
- Lead Luna's enterprise cybersecurity strategy, roadmap, and security operations, continuously strengthening our security posture across cloud infrastructure, endpoints, business systems, and enterprise applications.
- Build, mature, and maintain a comprehensive information security program, including security policies, standards, governance, risk management, and security awareness initiatives.
- Serve as the technical leader for enterprise IT operations, ensuring reliable, secure, and scalable technology services that support business growth and an exceptional employee experience.
- Own Identity and Access Management (IAM), including SSO, MFA, provisioning/deprovisioning, privileged access management, and periodic access reviews.
- Oversee endpoint management, Mobile Device Management (MDM), device lifecycle, asset management, and enterprise SaaS administration.
- Lead vulnerability management, threat detection, penetration testing, incident response, disaster recovery, backup, and business continuity planning.
- Partner with Engineering, Product, Compliance, Legal, Finance, Operations, and People teams to integrate security best practices into enterprise technology and business operations.
- Ensure compliance with HIPAA, HITECH, and other applicable regulatory and security frameworks through technical safeguards, documentation, audits, and remediation activities.
- Manage third-party security assessments, vendor risk reviews, customer security questionnaires, and ongoing technology vendor relationships.
- Evaluate emerging technologies and recommend secure, scalable solutions that improve operational effectiveness while balancing risk, cost, and business priorities.
- Mentor and develop a high-performing IT team while remaining actively involved in technical execution, architecture decisions, and day-to-day operational support.
- Communicate technology strategy, cybersecurity risks, investment recommendations, and program progress to executive leadership.
Requirements
- Possess + years of progressive experience leading information security, enterprise IT, or blended technology functions, including hands-on ownership of enterprise cybersecurity programs.
- Demonstrate a proven track record of building, implementing, and maturing cybersecurity programs while balancing security, compliance, and business objectives in a healthcare or other highly regulated environment.
- Bring direct experience supporting healthcare technology environments, including healthcare systems, enterprise applications, and technology platforms within HIPAA-regulated organizations.
- Exhibit strong knowledge of healthcare security and compliance requirements, including HIPAA, HITECH, PHI protection, security governance, risk assessments, audits, and remediation activities.
- Show hands-on experience with cloud security (AWS, Azure, or GCP), identity and access management (IAM), Single Sign-On (SSO), Multi-Factor Authentication (MFA), endpoint management, Mobile Device Management (MDM), and enterprise infrastructure.
- Have experience leading enterprise IT operations, technology roadmaps, incident response, disaster recovery, business continuity, vulnerability management, and security operations.
- Prove ability to lead and mentor technical teams while remaining hands-on with technical execution in a fast-paced, high-growth environment.
- Hold a previous position as a Director, or as a Senior Manager operating with Director-level scope and responsibility.
- Demonstrate experience partnering with executive leadership to develop technology strategy, evaluate risk, and communicate complex technical concepts to both technical and non-technical audiences.
- Have experience managing third-party vendors, security assessments, customer security questionnaires, and enterprise technology implementations.
Skills & tools
You will use IAM. You will use SSO. You will use MFA. You will use HIPAA. You will use HITECH.
Practical notes
Note: HIPAA-regulated environment.