Director of IT, Infrastructure & Security
Remote, FinTech, Azure Environment
About the role
Our client is a growing B2B software company undergoing a significant technology transformation. They are modernizing their technology environment, strengthening their security and compliance programs, and building scalable infrastructure to support continued growth. This is a hands-on leadership and builder role for someone who enjoys creating and maturing an IT organization rather than simply maintaining an established environment.
The Director will have broad ownership across cloud infrastructure, cybersecurity, IT operations, compliance, business continuity, and technology governance. The ideal candidate can operate strategically while remaining technical enough to jump into the details when needed. You will establish scalable processes, automate wherever possible, introduce the right technology, and lead a lean team of experienced technical professionals.
Why join us
Success in this role means building an IT and security organization that becomes more scalable, automated, secure, and cost-efficient as the company grows. You will establish the infrastructure and security foundation needed to support growth, reduce operational friction, strengthen customer trust, improve compliance readiness, and enable employees and Engineering to move faster without compromising security or reliability.
Responsibilities
- Infrastructure & Cloud
- Lead the company's cloud infrastructure, networking, internal IT, hardware, and technology platforms, with a strong preference for Microsoft Azure.
- Build and manage automated infrastructure across development, testing, UAT, staging, and production environments.
- Establish infrastructure-as-code, automation, and self-service provisioning as core operating practices.
- Oversee AI infrastructure, tooling, access, subscriptions, and related controls.
- Own the API gateway and platform layer, including routing, access management, rate limiting, security enforcement, and observability.
- Develop an integrated observability strategy across infrastructure, databases, APIs, and applications.
- Manage the company's SaaS and software portfolio, including licensing, renewals, vendors, and cost optimization.
- Establish FinOps practices to improve visibility and efficiency across cloud and SaaS spending.
- Cybersecurity
- Own the organization's infrastructure and cybersecurity strategy.
- Build and mature SIEM, detection, monitoring, and security response capabilities.
- Manage relationships with external MDR/MSSP providers supporting 24/7 security coverage.
- Implement endpoint security and modern device management for a primarily Windows-based remote workforce.
- Lead identity and access governance through Microsoft Entra ID, including least privilege, access reviews, privileged access, and segregation of duties.
- Governance, Risk & Compliance
- Own the company's SOC 2 program, including controls, evidence collection, audits, and auditor relationships.
- Lead SOX IT general controls and ensure effective design and execution.
- Develop data protection, classification, retention, and residency policies for an international customer base.
- Ensure compliance with applicable privacy requirements, including GDPR and CCPA.
- Establish an AI governance framework using recognized standards such as NIST AI RMF, NIST SSDF, and OWASP guidance.
- Develop practical governance around the responsible use of AI throughout the organization.
- IT Operations & Reliability
- Own business continuity and disaster recovery, including backups, RTO/RPO objectives, and regular testing.
- Establish incident management processes covering security, IT, and platform availability.
- Develop severity models, escalation procedures, runbooks, on-call processes, and post-incident reviews.
- Own release management and deployment governance, including release calendars, go/no-go decisions, deployment coordination, validation, and rollback procedures.
- Manage IT assets, hardware, software, licenses, and technology vendors.
- Establish scalable onboarding, offboarding, access management, and internal IT processes.
Requirements
- 8+ years of experience across IT infrastructure, cybersecurity, cloud engineering, or a related discipline.
- 3+ years of experience leading and developing technical teams.
- Experience in a B2B SaaS, multi-tenant software, or technology environment strongly preferred.
- Deep hands-on experience with cloud infrastructure, ideally Microsoft Azure.
- Strong experience with infrastructure-as-code, automation, and modern cloud operations.
- Demonstrated success building or significantly maturing cybersecurity capabilities, including SIEM, detection, identity/access governance, and endpoint security.
- Experience leading SOC 2, SOX ITGC, or comparable compliance programs.
- Understanding of cloud and SaaS cost management and FinOps principles.
- An automation-first mindset with strong judgment around technology investments.
- Strong operational discipline and the ability to turn policies into repeatable processes, documentation, runbooks, and automation.
- Excellent leadership, communication, and cross-functional collaboration skills.
Preferred Qualifications
- Experience implementing AI governance using frameworks such as NIST AI RMF or OWASP LLM/GenAI guidance.
- Experience with API gateway or API management platforms.
- Experience implementing modern observability platforms.
- Experience managing an MDR or MSSP relationship.
- Experience with zero-trust and remote-first technology environments.
- Experience supporting hybrid SaaS and on-premise deployment models.
- Strong Azure security and architecture experience.
- Certifications such as CISSP, CISM, Azure Solutions Architect, or Azure Security Engineer.
Pay
$180,000 - $225,000 per year