Luna Physical Therapy Logo

Luna Physical Therapy

Director , Information Security and IT

Posted 7 Days Ago
Remote
Hiring Remotely in USA
120K-170K Annually
Senior level
Remote
Hiring Remotely in USA
120K-170K Annually
Senior level
Lead enterprise cybersecurity and IT operations for a HIPAA-regulated healthcare company: build and mature security programs, manage IAM/endpoint/cloud security, drive vulnerability management and incident response, ensure compliance (HIPAA/HITECH), oversee IT operations and vendor risk, and mentor a technical team while partnering with cross-functional leadership.
The summary above was generated by AI

Luna is seeking a Director of Information Security & IT to lead the strategy, execution, and continuous evolution of the company's enterprise technology and information security programs. Reporting to the Chief Strategy & Product Officer, this leader will be responsible for enterprise cybersecurity, IT operations, healthcare technology systems, identity and access management, infrastructure, and technology compliance, ensuring secure, scalable, and resilient technology solutions that support Luna's business operations and the delivery of high-quality patient care.

This role is a hands-on leadership position requiring a balance of strategic vision and technical execution. The Director will lead the continued maturation of Luna's cybersecurity and IT capabilities while remaining actively engaged in technical decision-making, operational leadership, and cross-functional partnership. Working closely with Engineering, Product, Compliance, Legal, and executive leadership, this individual will strengthen Luna's security posture, safeguard sensitive healthcare information, and build scalable technology programs that enable continued growth within a HIPAA-regulated environment.

How you will have an impact

  • Lead Luna's enterprise cybersecurity strategy, roadmap, and security operations, continuously strengthening our security posture across cloud infrastructure, endpoints, business systems, and enterprise applications.
  • Build, mature, and maintain a comprehensive information security program, including security policies, standards, governance, risk management, and security awareness initiatives.
  • Serve as the technical leader for enterprise IT operations, ensuring reliable, secure, and scalable technology services that support business growth and an exceptional employee experience.
  • Own Identity and Access Management (IAM), including SSO, MFA, provisioning/deprovisioning, privileged access management, and periodic access reviews.
  • Oversee endpoint management, Mobile Device Management (MDM), device lifecycle, asset management, and enterprise SaaS administration.
  • Lead vulnerability management, threat detection, penetration testing, incident response, disaster recovery, backup, and business continuity planning.
  • Partner with Engineering, Product, Compliance, Legal, Finance, Operations, and People teams to integrate security best practices into enterprise technology and business operations.
  • Ensure compliance with HIPAA, HITECH, and other applicable regulatory and security frameworks through technical safeguards, documentation, audits, and remediation activities.
  • Manage third-party security assessments, vendor risk reviews, customer security questionnaires, and ongoing technology vendor relationships.
  • Evaluate emerging technologies and recommend secure, scalable solutions that improve operational effectiveness while balancing risk, cost, and business priorities.
  • Mentor and develop a high-performing IT team while remaining actively involved in technical execution, architecture decisions, and day-to-day operational support.
  • Communicate technology strategy, cybersecurity risks, investment recommendations, and program progress to executive leadership.

What you need

  • 8+ years of progressive experience leading information security, enterprise IT, or blended technology functions, including hands-on ownership of enterprise cybersecurity programs.
  • Demonstrated success building, implementing, and maturing cybersecurity programs while balancing security, compliance, and business objectives in a healthcare or other highly regulated environment.
  • Direct experience supporting healthcare technology environments, including healthcare systems, enterprise applications, and technology platforms within HIPAA-regulated organizations.
  • Strong knowledge of healthcare security and compliance requirements, including HIPAA, HITECH, PHI protection, security governance, risk assessments, audits, and remediation activities.
  • Hands-on experience with cloud security (AWS, Azure, or GCP), identity and access management (IAM), Single Sign-On (SSO), Multi-Factor Authentication (MFA), endpoint management, Mobile Device Management (MDM), and enterprise infrastructure.
  • Experience leading enterprise IT operations, technology roadmaps, incident response, disaster recovery, business continuity, vulnerability management, and security operations.
  • Proven ability to lead and mentor technical teams while remaining hands-on with technical execution in a fast-paced, high-growth environment.
  • Previous experience as a Director, or as a Senior Manager operating with Director-level scope and responsibility.
  • Experience partnering with executive leadership to develop technology strategy, evaluate risk, and communicate complex technical concepts to both technical and non-technical audiences.
  • Experience managing third-party vendors, security assessments, customer security questionnaires, and enterprise technology implementations.

Luna Physical Therapy Seattle, Washington, USA Office

600 4th Ave, Seattle, United States, 98104

Similar Jobs

7 Days Ago
In-Office or Remote
150K-175K Annually
Senior level
150K-175K Annually
Senior level
AdTech • Marketing Tech • Consulting
Lead and mature the company's cybersecurity program for a distributed, remote workforce. Develop strategy, governance, risk management, incident response, compliance (SOC 2/ISO/NIST), vendor assessments, device and identity controls, security awareness, and executive reporting to reduce organizational cyber risk and enable growth.
Top Skills: Endpoint SecurityGoogle DriveGoogle WorkspaceIdentity And Access Management (Iam)Incident ResponseIso 27001KandjiMfaNetSuiteNist Cybersecurity FrameworkNotionOktaSalesforceSlackSoc 2StratosVulnerability ManagementZoom
24 Days Ago
Easy Apply
Remote
United States
Easy Apply
267K-360K Annually
Expert/Leader
267K-360K Annually
Expert/Leader
Big Data • Fintech • Mobile • Payments • Financial Services
The CISO will develop and manage the Bank's information security programs, ensuring compliance and protecting customer data while mitigating risks. They will also lead a security team, oversee third-party risk, and promote a culture of security awareness across the organization.
Top Skills: Cloud ComputingCompliance (FdicCybersecurityFfiec)Incident ResponseInformation Security FrameworksRisk ManagementSecurity Operations
4 Minutes Ago
Remote or Hybrid
Seattle, WA, USA
83K-157K Annually
Senior level
83K-157K Annually
Senior level
Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Own model observability for Auto Physical Damage data science products, including traditional ML and GenAI/LLM systems. Build monitoring pipelines, dashboards, metrics, thresholds, alerts, and remediation documentation. Detect drift, performance degradation, anomalies, and data-quality issues; support MLOps, LLMOps, governance, compliance, and audit reporting. Analyze business outcomes, identify improvement opportunities, and communicate model health findings to technical and non-technical stakeholders.
Top Skills: AWSAzureEmblemExcelGCPLlmopsMlopsPowerPointPythonSASSQLStreamlitTableauVBA

What you need to know about the Seattle Tech Scene

Home to tech titans like Microsoft and Amazon, Seattle punches far above its weight in innovation. But its surrounding mountains, sprinkled with world-famous hiking trails and climbing routes, make the city a destination for outdoorsy types as well. Established as a logging town before shifting to shipbuilding and logistics, the Emerald City is now known for its contributions to aerospace, software, biotech and cloud computing. And its status as a thriving tech ecosystem is attracting out-of-town companies looking to establish new tech and engineering hubs.

Key Facts About Seattle Tech

  • Number of Tech Workers: 287,000; 13% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Amazon, Microsoft, Meta, Google
  • Key Industries: Artificial intelligence, cloud computing, software, biotechnology, game development
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Madrona, Fuse, Tola, Maveron
  • Research Centers and Universities: University of Washington, Seattle University, Seattle Pacific University, Allen Institute for Brain Science, Bill & Melinda Gates Foundation, Seattle Children’s Research Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account