VICE PRESIDENT OF INFORMATION TECHNOLOGY & SECURITY
About the role
The Vice President of Information Technology & Security provides strategic and operational leadership over BS&A Software’s internal technology and security functions. Reporting to the Chief Technology Officer (CTO), this role holds end-to-end accountability for IT infrastructure, business applications, enterprise security, internal support services, vendor management, and enterprise security governance, risk, and compliance (GRC). The role also provides oversight of the Project Management Office (PMO), ensuring technology initiatives are prioritized, coordinated, and aligned with business objectives. The role owns the data foundation, infrastructure, and security standards that BS&A's enterprise AI initiatives depend on, working in close partnership with the VP of AI Transformation, who owns the company's AI vision, roadmap, and governance. The VP serves as BS&A’s senior operational leader for IT and security strategy and operations, working in close alignment with the CTO to enable secure organizational growth, technology modernization, and operational resilience. This position blends high-level planning with hands-on technical execution, leading a hybrid team of internal professionals and external MSP/MSSP partners to deliver a scalable, secure, and supportable enterprise environment.
Responsibilities
Technology Strategy & Organizational Leadership
- Develop and execute an integrated technology and security roadmap aligned with BS&A’s growth strategy and operational objectives.
- Lead a unified organization that includes Infrastructure, End-User Support, Security, Business Applications, IT Governance, and PMO.
- Champion a culture of service excellence, security accountability, and operational scalability across the IT and security domains.
- Oversee workforce planning and talent development, including role design, career progression frameworks, mentorship, and skills development.
- Ensure alignment between IT resources and evolving business priorities through structured intake, prioritization, and planning.
- Foster cross-functional collaboration and executive alignment to ensure technology strategy enables and accelerates business goals.
- Lead IT and security activities across all phases of mergers and acquisitions, including pre-acquisition due diligence, integration planning, and post-acquisition execution. Ensure secure and scalable integration of infrastructure, applications, identity platforms, and support models while managing risk and minimizing disruption.
- Own the full IT and Security budget, operating and capital, including planning, forecasting, and in-year management of all spend across the IT and Security functions.
Enterprise Applications & Project Governance
- Own the Enterprise Applications function and team, including the PMO, driving application governance, modernization, migration initiatives, lifecycle planning, vendor management, and technology roadmaps to support business growth and operational excellence.
- Lead the Project Management Office (PMO), with responsibility for project intake, prioritization, resource coordination, and delivery oversight in alignment with business objectives.
- Provide architectural oversight and vendor coordination for system integrations, upgrades, and lifecycle planning.
- Define and maintain application governance frameworks, including access controls, change management policies, and business continuity standards.
- Establish and enforce a system ownership model across business applications, ensuring alignment between IT, business stakeholders, and external vendors for functionality, support, and data integrity.
- Govern software license compliance and lifecycle across internal SaaS platforms and desktop applications, including procurement governance, renewals, usage monitoring, and cost optimization.
- Promote project and portfolio transparency through reporting, stakeholder engagement, and delivery metrics that support prioritization and executive visibility.
- Oversee internal IT change and release management processes—including coordination with development teams—to ensure secure, compliant, and minimally disruptive deployment of infrastructure, application, and configuration changes across environments.
- Serve as the data, infrastructure, and security enabler to BS&A's AI Center of Excellence, ensuring the systems and access that internal AI initiatives run on are secure, governed, and dependable.
IT Operations & Infrastructure Management
- Own end-to-end responsibility for all IT infrastructure—on-premise and cloud—including servers, networking, endpoint management, databases, and communication systems. Oversight of BS&A’s SaaS infrastructure is exercised in partnership with Engineering and DevOps, ensuring alignment on security, access, change management, and compliance priorities.
- Oversee a modern, scalable approach to endpoint management, user provisioning, and virtual desktop infrastructure based on cloud-first and identity-driven principles.
- Oversee the operational lifecycle, performance, and cost efficiency of core infrastructure services—including networks, storage, compute, and cloud platforms—while maintaining documentation of system architecture, directory services, and access control configurations.
- Lead a formal change control process aligned with ITIL principles to manage infrastructure changes, patch management, access configurations, and operational risk.
- Maintain accurate configuration records and enforce version-controlled documentation and approval workflows for all changes.
- Lead the lifecycle management of all IT assets (e.g., laptops, servers, mobile devices, network equipment), ensuring accurate inventory, secure provisioning/decommissioning, and alignment with the annual budgeting, procurement, and refresh cycles.
- Monitor infrastructure KPIs, vendor SLAs, and capacity plans to support availability, performance, and long-term scalability.
- Monitor and optimize cloud infrastructure spend through cost governance practices, utilization analysis, and collaboration with finance teams to align resource usage with budget targets.
- Own the strategy for where BS&A's corporate and internal data lives, how it's structured, and how it's made discoverable, governed, and consumable by AI systems and agents, ensuring the underlying data foundation is AI-ready.
- Partner with the VP of AI Transformation to enable enterprise AI initiatives, providing the secure data access, integration points, and infrastructure that internal AI agents and tooling depend on, including responsibility for data and infrastructure readiness in the production-readiness review of AI solutions.
Security, Governance, Risk and Compliance (GRC)
- Lead BS&A’s enterprise security program and architecture, overseeing internal security staff and co-managed MSSP partners to ensure comprehensive threat defense and incident readiness.
- Drive the implementation of Zero Trust principles, identity governance frameworks, role-based access controls, and modern endpoint protection strategies.
- Oversee technical security operations including firewall standards, configurations, threat detection systems, inter-network segmentation, anti-spoofing protections, and key and certificate management.
- Lead incident response and threat mitigation activities, including vulnerability assessments, penetration testing, structured remediation, regular posture reviews, and post-incident analysis to proactively reduce exposure, improve resiliency, and defend against evolving threats.
- Ensure ongoing alignment with SOC 1 Type 2, SOC 2 Type 2, PCI-DSS, and other regulatory frameworks through technical control framework implementation, policy alignment, and continuous evidence collection for both internal and external audits, including ownership of the payments environment and the controls that keep it compliant.
- Define and own the security and data standards that enterprise AI systems and agents operate within, serving as a key consulted partner to the VP of AI Transformation on enterprise AI governance and guardrails.
- Own the company’s data privacy program, including privacy policy and posture, in partnership with Legal.
- Continuously assess and evolve the Security program through maturity models, performance metrics, and stakeholder reporting, ensuring alignment with evolving threats, emerging compliance obligations, and organizational growth.
- Lead company-wide security awareness efforts, including role-based training programs, simulated phishing campaigns, and education initiatives that reinforce a strong internal security culture.
- Maintain and continuously improve Disaster Recovery (DR) and Business Continuity Plans (BCP), ensuring readiness through regular testing and alignment with business risk tolerance.
- Collaborate with Facilities to ensure physical and environmental security of on-premise infrastructure, including office building access controls, server room safeguards, and environmental protections aligned with PCI requirements.
- Own and maintain the lifecycle of IT and security policies, including version control, stakeholder alignment, and documentation management. Ensure execution of access reviews, role matrices, and evidence collection workflows that support audit readiness and regulatory compliance.
- Lead IT-related audit readiness efforts and coordinate regulatory interface in collaboration with Legal, Finance, and other departments. This includes quarterly compliance reporting, internal control mapping, and supporting external audit activities.
- Maintain a centralized IT risk register and control matrix to support continuous control monitoring, risk identification, and maturity tracking.
- Maintain audit-ready documentation of security configurations, infrastructure diagrams, and control effectiveness.
- Maintain alignment between change management documentation and compliance control requirements, ensuring traceability and approval workflows are enforced.
- Monitor and evolve the security program using maturity models, program KPIs, and stakeholder reporting to ensure sustained alignment with organizational growth and threat evolution.
Service Delivery, End-User Support & Workplace Technology
- Oversee a structured End-User Support function focused on delivering exceptional internal service, timely issue resolution, and continuous improvement in employee technology experience.
- Define team roles, escalation protocols, and ownership across support tiers, ensuring clarity of responsibilities and alignment with SLAs and service expectations.
- Establish and track performance metrics (e.g., response times, resolution rates, satisfaction scores) to drive operational accountability and identify areas for improvement.
- Uphold strict separation between internal IT support and external customer support, ensuring that client-facing requests are routed through designated BS&A support channels.
- Uphold service level agreements (SLAs), satisfaction tracking, and documentation standards that drive accountability and responsiveness within the support organization.
- Promote self-service enablement through the development and maintenance of internal knowledge bases, documentation hubs, and automation pathways for common support requests.
- Lead the execution and continuous improvement of employee onboarding and offboarding processes, ensuring timely provisioning, account setup, and deprovisioning aligned with security and compliance standards.
- Collaborate with infrastructure and security teams to support endpoint compliance, including MDM enrollment, patching standards, encryption standards, and secure baseline configurations.
- Continuously evaluate tools, workflows, and delivery models to enhance the scalability, quality, and consistency of internal IT support services.
- Drive modernization of the digital workplace by introducing and optimizing collaboration platforms, productivity tools, and device strategies that support hybrid work, streamline communication, and enhance employee experience.
Vendor & Partner Oversight
- Serve as the primary executive owner for all IT and security vendor relationships, including MSPs, MSSPs, SaaS providers, and infrastructure partners.
- Define vendor governance frameworks, including performance metrics, contractual obligations, and service level expectations.
- Lead vendor selection, contract negotiation, and ongoing performance management to ensure alignment with business needs and cost efficiency.
- Oversee vendor risk assessments, compliance reviews, and security evaluations to mitigate third-party risks.
- Ensure vendor deliverables align with BS&A’s technology roadmap, security standards, and operational requirements.