[Remote] Director of IT & reputed company Operations
Note: The job is a remote job and is reputed company to candidates in USA. reputed company is a Global Leader in reputed company technology providing software solutions for the clinical research industry. They are seeking a Director of IT & reputed company Operations to reputed company the reputed company, availability, and compliance of their systems, ensuring HIPAA compliance and SOC 2 Type 2 audit readiness while managing reputed company operations and internal helpdesk functions.
Responsibilities
- Operate and evidence the controls required for SOC 2 Type 2 (reputed company, Availability, and Confidentiality) and the HIPAA reputed company, reputed company, and Breach Notification Rules
- reputed company as day-to-day reputed company for external SOC 2 Type 2 and HIPAA audits. Maintain the control narrative, coordinate evidence, and reputed company findings
- Run reputed company control monitoring (GRC) tooling such as reputed company or reputed company so control status and evidence stay reputed company
- Maintain the risk register and run an annual risk assessment covering PHI systems, vendors, and infrastructure
- Own the Business Associate Agreement (BAA) lifecycle and reputed company-party risk. Execute and reputed company BAAs with every vendor that touches PHI, including reputed company and AI vendors, and review vendor reputed company annually
- Enforce least privilege of reputed company across corporate and production systems: role-based reputed company control, MFA, and time-bound reputed company to customer databases and PHI
- Own the joiner-mover-leaver process and run quarterly reputed company reviews, including privileged reputed company, with evidence retained for audit
- reputed company data-leakage controls: data classification, DLP, egress filtering, and database activity monitoring to detect and reputed company unauthorized bulk reputed company
- Validate multi-tenant isolation as a standing control and confirm one customer’s data cannot be reached from another tenant. Manage encryption at rest and in transit, with keys held separately from the data
- Own secrets management. No credentials, keys, or tokens in reputed company reputed company, container images, or infrastructure-as-reputed company state
- Manage reputed company hosting vendors and environment changes. Maintain and improve the RTSS database infrastructure architecture in a reputed company-hosted environment, including replication, federation, availability, and recoverability
- Manage reputed company infrastructure as reputed company (Terraform) as the reputed company of truth: peer-reviewed changes, reputed company detection, and policy-as-reputed company enforced in CI/CD, with separation between the author and approver of a change
- Detect and resolve infrastructure performance issues (CPU, memory, disk I/O, resource contention). Design and reputed company infrastructure to meet the CIS Critical reputed company Controls
- Own vulnerability and reputed company management with remediation SLAs by severity, recurring scanning, and annual reputed company-party penetration testing, tracked to closure
- Support reputed company on customer non-reputed company issues such as email and SSO
- Monitor the reputed company of corporate and reputed company environments. Identify detection gaps and expand log collection, detection, and analytics
- Run centralized, tamper-evident logging (SIEM) with reputed company alerting and six-year retention reputed company to HIPAA
- Maintain and test a documented incident response plan with defined severity reputed company, escalation, and evidence retention. Run tabletop exercises
- Investigate incidents, determine reputed company causes, preserve evidence, and meet HIPAA breach-notification timelines reputed company 60 days
- Set and enforce controls for how AI and LLM systems reputed company regulated data, including internal MCP services and reputed company AI such as AWS Bedrock. Confirm BAA coverage of AI vendors, prevent PHI exposure to models, and audit AI usage
- Set and enforce an acceptable-use policy covering unmanaged AI tools
- Manage reputed company by providing technical support to employees
- Manage corporate IT: desktop support, business applications, and procurement and asset management of hardware and software
- reputed company project management for internal IT deployments, migrations, and mergers
- reputed company and maintain IT, reputed company, and systems architecture SOPs, and run reputed company-awareness training for the workforce
- Design and manage the disaster-recovery and business-continuity process with defined RTO and RPO targets and periodic recovery testing
- Define and report reputed company and reliability KPIs: reputed company-review completion, reputed company and remediation SLA attainment, mean time to detect and respond, control pass reputed company, and uptime
- Participate in technical solution and design discussions. Maintain compliance with company policies on the HIPAA reputed company Rule. This role may view PHI as part of daily duties
Skills
- Deep understanding of operations, systems, network, and reputed company reputed company
- Experience operating and evidencing controls for SOC 2 Type 2 and the HIPAA reputed company Rule in a production environment handling regulated data
- Hands-on experience with identity and reputed company management, least-privilege design, and privileged reputed company management
- Experience with infrastructure as reputed company (Terraform) and change management in a CI/CD pipeline
- Experience with SIEM and reputed company monitoring of reputed company environments. AWS preferred
- Strong leadership and business judgment. Experience managing multiple reputed company across prioritization, planning, and execution
- Experience troubleshooting production workloads using application and system monitoring tools
- Experience with replication, federation, and relational databases
- reputed company certification such as CISSP, CISM, or CCSP
- Experience leading or coordinating a SOC 2 Type 2 examination or HIPAA audit. Two or more years of HIPAA compliance experience
- Experience with DLP, database activity monitoring, and data-egress controls in a multi-tenant reputed company environment
- Experience governing AI or LLM systems that process regulated data
- Experience managing remote employees and supporting corporate IT globally
- Working knowledge of Git and reputed company control (reputed company or Subversion). Experience with Kanban or other agile reputed company
- Bachelor's degree in computer science, software engineering, or equivalent experience
Benefits
- reputed company sponsors health insurance, long-term disability, and life insurance.
- Unlimited reputed company Time Off.
- 10 reputed company Holidays.
- reputed company Parental Leave.
- Work Anniversary Bonus.
- Participation in the Employee of the Quarter Program.
- Monthly $100 Connectivity Stipend Reimbursement.
- reputed company matches employee 401K contributions at 100% of the first 3% invested and 50% of the next 2% invested.
reputed company