Director of Infrastructure & Cybersecurity

Advitaortho — United States · Posted ~2 hours ago

Head Full-time Onsite

Skills

IT infrastructure Cybersecurity Network architecture Server administration Cloud infrastructure Endpoint management Security risk management IT leadership Budget management Network infrastructure Servers Storage Cloud

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A director-level technology leadership role responsible for both enterprise infrastructure and cybersecurity in a regulated manufacturing environment. The position oversees network, server, storage, endpoint, and cloud architecture as well as security strategy, risk, budgets, and executive communication, while remaining technically engaged in major decisions.

Highlights

Director-level working leadership role combining infrastructure and cybersecurity responsibilities with equal emphasis. The position owns architecture, operations, security, risk, budgeting, and executive-level technology direction in a regulated manufacturing environment.

Description

Department: Information Technology Location: Gainesville, FL Description The Director of Infrastructure and Cybersecurity leads both disciplines for Advita with equal weight. The role owns the systems that keep manufacturing, quality, and commercial operations running, and it owns the security program that protects Advita’s intellectual property, design and production data, and regulated electronic records. This is a working leadership role in a validated, FDA-regulated manufacturing environment. The Director is expected to be close enough to the technology to make sound architecture and risk decisions, and senior enough to set direction, own the budget, and represent both agendas to the executive team. Neither mandate is treated as secondary to the other. Key Responsibilities InfrastructureOwn the architecture, deployment, and operation of network, server, storage, endpoint, and cloud environments across all Advita sites.Prioritize infrastructure work by its effect on production uptime, quality system availability, and the ability to ship. Manufacturing continuity is the first test of any infrastructure decision.Own disaster recovery and business continuity for critical systems. Define recovery objectives with the business, test them on a published schedule, and report the results.Direct lifecycle management, capacity planning, and modernization. Maintain a rolling multi-year plan for hardware, operating systems, and platforms approaching end of support.Manage the infrastructure supporting validated and GxP-relevant systems in coordination with Quality. Ensure changes move through validation and change control rather than around them.Bring the plant floor under a defined standard. Establish segmentation, patching, backup, monitoring, and remote access requirements for manufacturing equipment, historians, and OT networks.Own the service desk and end-user computing experience. Publish response and resolution targets and hold internal staff and outside providers to them.Ensure infrastructure changes conform to organization-wide change management standards and are documented, reversible, and communicated in advance. CybersecurityOwn Advita’s cybersecurity program: roadmap, policies, standards, procedures, and controls, measured against a named framework such as ISO 27001 or NIST CSF rather than against opinion.Own identity and access management, including privileged access, joiner and leaver processes, and periodic access reviews for systems holding regulated or confidential data.Own enterprise security controls across network defense, endpoint protection, email security, logging, and monitoring. Maintain a clear view of what is covered, what is not, and what closing the gap costs.Lead vulnerability management across both IT and OT, with remediation targets by severity and regular reporting against them.Own incident response. Maintain and exercise the plan, define escalation and notification paths, and lead the response when an incident occurs.Maintain a risk register leadership can act on, with named owners, treatment decisions, and dates. Lead periodic risk assessments and report movement over time.Ensure controls over electronic records and signatures meet FDA 21 CFR Part 11 expectations, and that IT controls supporting the quality system hold up under audit.Support internal audits, customer security questionnaires, and regulatory inspections. Keep evidence and documentation current so audits do not become projects.Manage third-party and supply chain risk. Assess vendors and service providers before they receive access to Advita systems or data, and reassess on a defined schedule.Partner with business leaders so controls fit how the work is actually done. Where a control creates real friction, propose a workable alternative rather than an exception.Leadership, Vendor & Financial ResponsibilitiesProvide direction and leadership to the infrastructure and security teams. Recruit, develop, and retain staff, and build enough depth that no critical system depends on one person.Develop and manage the operating and capital budgets for both mandates. Make spend tradeoffs and defend them.Evaluate, select, and manage technology vendors and managed service providers. Hold contracts and service levels accountable and be prepared to change providers who underperform.Communicate infrastructure and security risk to technical and non-technical audiences. Give the executive team a current, usable picture without requiring them to interpret technical detail.Maintain regular written and in-person communication with executives, department heads, and end users regarding planned work, outages, and changes.Act as the liaison between IT, Quality, Operations, and Commercial on technology decisions affecting regulated processes.Support applicable regulatory and contractual obligations across Advita’s markets, including FDA 21 CFR Part 11 and Part 820, ISO 13485, and, where relevant to Advita’s data and geographies, HIPAA, GDPR, and EU MDR requirements. Skills, Knowledge & Expertise EducationBachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field, or an equivalent combination of education and experience.Required Experience10+ years in IT infrastructure and cybersecurity, including at least 5 years leading teams.Direct accountability for both infrastructure operations and a security program. Candidates who have led only one of the two should be prepared to show how the other was covered under their ownership.Working depth across networking, server and storage, virtualization, Microsoft 365 and Azure or comparable cloud platforms, and backup and recovery.Experience running a security program on a recognized framework, including risk assessment, vulnerability management, and incident response.Experience in a regulated environment with formal change control and documentation requirements.Experience owning budgets and managing vendors and managed service providers.Skills, Credentials, and KnowledgeSound risk judgment. Able to separate what must be fixed now from what can be scheduled, and to explain the difference to a non-technical audience.Clear writing. Policies, standards, and executive updates that people can act on without translation.Ability to balance technical priorities against business and financial objectives.Ability to lead through outside service providers as well as direct staff.Comfort declining a request with a workable alternative attached.PreferredMedical device, pharmaceutical, or other FDA-regulated manufacturing experience.Working knowledge of FDA 21 CFR Part 11, 21 CFR Part 820 and the transition to QMSR, and ISO 13485 as they apply to IT systems.Experience securing manufacturing or OT environments, including segmentation of production networks and equipment running unsupported operating systems.Experience supporting ERP and MES platforms in a manufacturing setting.CISSP, CISM, CISA, or an equivalent security certification. PMP or equivalent project management credential.Experience in a private equity backed or acquisitive company.