Director of IT Infrastructure and Security
Listed on 2026-06-04
-
IT/Tech
Cybersecurity, IT Project Manager
Job Title: Director, IT Infrastructure and Security
Department: Information Technology
Location:Hybrid, based in Washington, DC, or Durham, NC; or Remote in Illinois, Maryland, New Jersey, New York, North Carolina, or Virginia
Position OverviewThe Director, IT Infrastructure & Security is responsible for the strategy, performance, and security of the organization’s technology environment, including cloud infrastructure, networks, endpoints, and information security programs. This role leads a small internal team and manages an outsourced Managed Service Provider (MSP) to ensure reliable, secure, and scalable IT operations.
This leader partners across the organization to align infrastructure and security capabilities with business needs, risk tolerance, and growth priorities.
What You’ll Do Infrastructure Strategy & Operations- Define and execute the organization’s infrastructure strategy across cloud (Azure), network, endpoints, and collaboration platforms, in coordination with partner non-profit organizations. Ensure long term roadmap is aligned to business growth
- Ensure high availability, performance, and cost optimization of all infrastructure systems
- Oversee endpoint management, device lifecycle, and identity systems (e.g., Azure AD / Entra , Intune, group policy)
- Establish and maintain standards for system configuration, patching, and lifecycle management
- Lead evaluation, selection, and implementation of infrastructure technologies
- Establish infrastructure monitoring strategy (uptime, performance, etc.)
- Act as escalation point for critical incidents
- Continuously improve IT service management processes and user experience
- Develop and maintain a comprehensive information security strategy aligned with organizational risk tolerance and growth ambitions
- Define and track security KPIs and maturity benchmarks
- Act as in-house security expert, coordinating with an in-house security team, partner non-profits, and external vendors. Handle proactive and reactive issues related to technical, administrative, physical and virtual threats
- Establish and enforce security policies, standards, procedures, and trainings
- Lead risk management practices, including risk assessments, threat modeling, and remediation planning
- Oversee security architecture, including identity and access management, endpoint security, and cloud security posture
- Lead and evolve incident response processes, including detection, investigation, and recovery
- Oversee disaster recovery and business continuity planning and testing
- Ensure integration of security incident response with broader IT and business processes
- Conduct tabletop exercises and simulations for incident response and disaster recovery
- Ensure compliance with applicable frameworks (e.g., SOC 2, client requirements, regulatory needs)
- Coordinate internal and external audits and remediation efforts
- Maintain policies and documentation supporting governance and compliance
- Oversee day-to-day IT service delivery through internal staff and MSP, including establishment of clear operating model between internal teams and MSP
- Define and enforce SLAs, KPIs, and performance expectations for MSP and vendors
- Lead, mentor, and develop a small internal IT team
- Manage external partners including MSP, security vendors, and consultants
- Foster a culture of accountability, service excellence, and continuous improvement
- Partner with leadership within and across teams to align strategy with organizational priorities
- Bachelor’s degree or equivalent experience
- 15+ years of progressive experience in IT infrastructure and/or information security
- 5+ years of strategic leadership of infrastructure and security systems
- Experience managing cloud environments (Microsoft Azure preferred)
- Strong knowledge of:
- Identity & access management (Azure AD / Entra )
- Endpoint management (e.g., Intune)
- Networking fundamentals and cloud architecture
- Security frameworks and best practices
- Experience managing vendors and/or MSPs
- Demonstrated experience leading incident response and risk management efforts
- Certifications in one or more relevant…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).