Luna Physical Therapy

Director , Information Security and IT

USA, United States full-time Mid Salary not listed
full-time Mid level Technology & IT Curated
Sign in to apply Free account — we bring you straight back to this role.

About the role

Luna is seeking a Director of Information Security & IT to lead the strategy, execution, and continuous evolution of the company's enterprise technology and information security programs. Reporting to the Chief Strategy & Product Officer, this leader will be responsible for enterprise cybersecurity, IT operations, healthcare technology systems, identity and access management, infrastructure, and technology compliance, ensuring secure, scalable, and resilient technology solutions that support Luna's business operations and the delivery of high-quality patient care.

This role is a hands-on leadership position requiring a balance of strategic vision and technical execution. The Director will lead the continued maturation of Luna's cybersecurity and IT capabilities while remaining actively engaged in technical decision-making, operational leadership, and cross-functional partnership. Working closely with Engineering, Product, Compliance, Legal, and executive leadership, this individual will strengthen Luna's security posture, safeguard sensitive healthcare information, and build scalable technology programs that enable continued growth within a HIPAA-regulated environment.

How you will have an impact

Lead Luna's enterprise cybersecurity strategy, roadmap, and security operations, continuously strengthening our security posture across cloud infrastructure, endpoints, business systems, and enterprise applications.

Build, mature, and maintain a comprehensive information security program, including security policies, standards, governance, risk management, and security awareness initiatives.

Serve as the technical leader for enterprise IT operations, ensuring reliable, secure, and scalable technology services that support business growth and an exceptional employee experience.

Own Identity and Access Management (IAM), including SSO, MFA, provisioning/deprovisioning, privileged access management, and periodic access reviews.

Oversee endpoint management, Mobile Device Management (MDM), device lifecycle, asset management, and enterprise SaaS administration.

Lead vulnerability management, threat detection, penetration testing, incident response, disaster recovery, backup, and business continuity planning.

Partner with Engineering, Product, Compliance, Legal, Finance, Operations, and People teams to integrate security best practices into enterprise technology and business operations.

Ensure compliance with HIPAA, HITECH, and other applicable regulatory and security frameworks through technical safeguards, documentation, audits, and remediation activities.

Manage third-party security assessments, vendor risk reviews, customer security questionnaires, and ongoing technology vendor relationships.

Evaluate emerging technologies and recommend secure, scalable solutions that improve operational effectiveness while balancing risk, cost, and business priorities.

Mentor and develop a high-performing IT team while remaining actively involved in technical execution, architecture decisions, and day-to-day operational support.

Communicate technology strategy, cybersecurity risks, investment recommendations, and program progress to executive leadership.

What you need

8+ years of progressive experience leading information security, enterprise IT, or blended technology functions, including hands-on ownership of enterprise cybersecurity programs.

Demonstrated success building, implementing, and maturing cybersecurity programs while balancing security, compliance, and business objectives in a healthcare or other highly regulated environment.

Direct experience supporting healthcare technology environments, including healthcare systems, enterprise applications, and technology platforms within HIPAA-regulated organizations.

Strong knowledge of healthcare security and compliance requirements, including HIPAA, HITECH, PHI protection, security governance, risk assessments, audits, and remediation activities.

Hands-on experience with cloud security (AWS, Azure, or GCP), identity and access management (IAM), Single Sign-On (SSO), Multi-Factor Authentication (MFA), endpoint management, Mobile Device Management (MDM), and enterprise infrastructure.

Experience leading enterprise IT operations, technology roadmaps, incident response, disaster recovery, business continuity, vulnerability management, and security operations.

Proven ability to lead and mentor technical teams while remaining hands-on with technical execution in a fast-paced, high-growth environment.

Previous experience as a Director, or as a Senior Manager operating with Director-level scope and responsibility.

Experience partnering with executive leadership to develop technology strategy, evaluate risk, and communicate complex technical concepts to both technical and non-technical audiences.

Experience managing third-party vendors, security assessments, customer security questionnaires, and enterprise technology implementations.

Compensation

Compensation will be commensurate with experience, qualifications, and geographic location, and will reflect the successful candidate's skills and overall fit for the role.

Additional Information

Physical therapy, delivered.www.getluna.com

#LUNACORP1

Interview prep

Walk in with sharper answers.

Use this as a quick practice sheet before you speak with the employer.

Mid
Technology & IT Data Analysis Finance Operations Writing Mid level full-time

Likely questions

  1. Tell us about work you have done that is close to the Director , Information Security and IT role.
  2. How would you approach your first 30 days at Luna Physical Therapy?
  3. Which of Data Analysis, Finance and Operations have you used recently, and what did it help you achieve?
  4. Describe a time you solved a problem without waiting to be told exactly what to do.
  5. How do you handle busy days, changing priorities, or pressure at work?

Prepare before the call

  • A recent example that proves your experience with Data Analysis, Finance and Operations.
  • One short story with a problem, your action, and the result.
  • Two examples that show the strengths listed on your CV.
  • A clear reason why this role and company interest you.
  • Your availability, preferred work style, and salary expectations.

Ask them

  • What would success look like in the first 90 days?
  • What are the main problems this hire should help solve?
  • How does the team give feedback and measure good work?
  • What does a normal working week look like for this role?
Practice line

I am interested in the Director , Information Security and IT role because I can bring practical experience in Data Analysis, Finance and Operations, learn the team quickly, and contribute to the outcomes Luna Physical Therapy needs from this hire.

Related jobs.

More roles from this company or category.