Director, IT, Security & Compliance

PurpleLab, Inc.
Wayne, PA, United States
2 months ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$165,000.0 - $185,000.0
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Software System Penetration Testing Microsoft Azure Cloud Computing Cloud Computing Security Cyber Security DevOps Disaster Recovery Identity and Access Management Information Technology Operations Cloud Services Software Licensing
+2 more
Reliability of Systems Information Technology

Job description

The Director, Information Technology & Security/Compliance is responsible for the day-to-day management of the company’s IT operations and security/compliance programs. This includes overseeing the relationship with the company’s managed IT service provider, ensuring the security and reliability of IT systems, and leading the company’s compliance efforts under frameworks including HIPAA, SOC 2, and HiTrust. This role reports to the VP, Information Technology and serves as the primary operational lead for IT infrastructure and regulatory compliance.

  • Manage the day-to-day relationship with the company’s managed IT service provider, serving as the primary point of contact for service delivery, escalations, and performance management.
  • Oversee IT operations including cloud operations, endpoint management, and identity and access management.
  • Lead a group of dev ops and system reliability engineers for cloud operations.
  • Lead and maintain the company’s HiTrust certification program, including gap assessments, remediation tracking, and audit coordination.
  • Own and manage the SOC 2 compliance program, including evidence collection, control monitoring, and coordination with external auditors.
  • Develop, implement, and maintain IT security policies, procedures, and controls in alignment with applicable regulatory and contractual requirements.
  • Conduct and coordinate risk assessments, such as penetration testing; develop and track remediation plans for identified vulnerabilities and gaps.
  • Manage incident response activities including identification, containment, investigation, and documentation of security events.
  • Maintain and test disaster recovery (DR) and business continuity plans.
  • Ensure ongoing HIPAA compliance across systems, processes, and third-party relationships.
  • Manage IT vendor relationships and contracts, including software licensing, cloud services, and security tooling.
  • Prepare and maintain compliance documentation.
  • Perform other duties as assigned to support business needs and company objectives.

Requirements

  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity or a related field is required.
  • 5+ years of experience in IT operations, security, or compliance roles, with at least 2 years in a management or leadership capacity.
  • Demonstrated experience managing a HiTrust certification program (HITRUST CSF).
  • Demonstrated experience managing a SOC 2 audit and compliance program.
  • Experience managing a third-party managed IT services or helpdesk provider.
  • Strong working knowledge of HIPAA Security and Privacy Rules.
  • Experience conducting risk assessments and implementing security controls.
  • Experience with incident response and disaster recovery planning.
  • Strong understanding of cloud computing security and infrastructure (AWS, Azure, or GCP).
  • Strong analytical and problem-solving skills.
  • Excellent communication and interpersonal skills; ability to translate technical risk into business terms.
  • Experience in healthcare, life sciences, or health data industries strongly preferred.
  • Relevant certifications (CISSP, CISM, CRISC, HITRUST CCSFP, or equivalent) a plus.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:03 min

Platform compliance and security certifications for sensitive data

Chad Carlson · World Congress 2021

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:41 min

Transitioning artificial intelligence infrastructure into scalable commodity cloud services

juarezjunior juarezjunior · World Congress 2024

2:07 min

Leveraging cloud infrastructure for security and healthcare compliance

Leo Lindhorst · World Congress 2022

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

Videos

See all

Related articles

See all