[![Image]() Meet Jobicy Copilot — free AI autofill for job applications + remote job alerts ›](#)   [All remote jobs](https://jobicy.com/jobs.md)Open role[![Luna Physical Therapy logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/07/fcb34e841928-221.webp)](https://jobicy.com/company/luna-physical-therapy.md)Remote opportunity at[Luna Physical Therapy](https://jobicy.com/company/luna-physical-therapy.md)

# Director , Information Security and IT

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

[Apply for this job](#job-application)[View company](https://jobicy.com/company/luna-physical-therapy.md)Share11 Sep 2026Published49Listing views3Application actions11 Oct 2026Apply before  Opportunity details

## About this role.

AI SummaryThis hands-on Director of Information Security & IT role leads Luna's enterprise cybersecurity strategy, IT operations, and healthcare technology environment. The position owns security governance, IAM, cloud and endpoint security, incident response, vendor risk, and business continuity. It requires close partnership with Engineering, Product, Compliance, Legal, and executive leadership to protect PHI and meet HIPAA/HITECH obligations. The successful candidate will also mentor an IT team while making architecture and operational decisions in a high-growth, regulated healthcare setting.

## Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

### Job Complexity

5/5EasyHard

### Pace & Pressure

5/5RelaxedFast-paced

### Autonomy Level

5/5GuidedFull ownership

### Communication Load

5/5IndependentCollaborative

AI insightThis is a senior, broad-scope leadership role spanning both strategic security program ownership and hands-on enterprise IT execution. The incumbent must manage material healthcare compliance and PHI risks while scaling infrastructure, teams, vendors, and security operations.

## Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianBelow market$145,000US market range$150k–$210k0$231k

AI insightThe disclosed annual base compensation range is USD 120,000 to USD 170,000, with a midpoint of USD 145,000. For a US-based Director of Information Security & IT with HIPAA-regulated healthcare, cloud security, and enterprise IT leadership responsibilities, a typical market range is estimated at USD 150,000 to USD 210,000 annually; actual pay varies by location, organization size, and total-equity or bonus structure.

## Core skills

Skills and capabilities most closely associated with this opportunity.

[Information Security Leadership](https://jobicy.com/jobs?search_keywords=Information%20Security%20Leadership.md)[Healthcare Cybersecurity](https://jobicy.com/jobs?search_keywords=Healthcare%20Cybersecurity.md)[HIPAA Compliance](https://jobicy.com/jobs?search_keywords=HIPAA%20Compliance.md)[HITECH](https://jobicy.com/jobs?search_keywords=HITECH.md)[Identity and Access Management](https://jobicy.com/jobs?search_keywords=Identity%20and%20Access%20Management.md)[Cloud Security](https://jobicy.com/jobs?search_keywords=Cloud%20Security.md)[Incident Response](https://jobicy.com/jobs?search_keywords=Incident%20Response.md)[IT Operations](https://jobicy.com/jobs?search_keywords=IT%20Operations.md)[Vendor Risk Management](https://jobicy.com/jobs?search_keywords=Vendor%20Risk%20Management.md)[Business Continuity](https://jobicy.com/jobs?search_keywords=Business%20Continuity.md)

Sample interview questionsHow would you assess and prioritize Luna's security program during your first 90 days?I would begin with an asset, data-flow, and control assessment focused on PHI, cloud infrastructure, identities, endpoints, and critical SaaS systems. I would map findings to HIPAA requirements and business risk, validate incident-response and recovery readiness, and produce a prioritized roadmap with accountable owners, timelines, and measurable outcomes.

Describe your approach to IAM in a fast-growing healthcare company.

I use a lifecycle-driven IAM model centered on SSO, MFA, least privilege, role-based access, automated joiner-mover-leaver processes, and recurring access reviews. For privileged access, I establish stronger authentication, logging, time-bound elevation where feasible, and clear ownership for exceptions.

How do you balance security controls with employee productivity and operational needs?

I involve business and technical stakeholders early, understand the workflow and risk being addressed, and implement controls that are proportionate and as frictionless as possible. I use risk-based decisions, phased rollouts, documented exceptions, and clear communication so security becomes an enabler rather than an obstacle.

What would your incident-response process look like for a suspected PHI security incident?

I would activate a documented response process covering containment, evidence preservation, triage, eradication, recovery, and executive and legal escalation. I would coordinate closely with Compliance and Legal on breach assessment and notification obligations, then conduct a blameless post-incident review to remediate root causes and strengthen controls.

How have you communicated cybersecurity investment needs to executive leadership?

I translate technical issues into business impact, likelihood, regulatory exposure, operational dependency, and the cost of inaction. I present a small number of prioritized options with investment requirements, expected risk reduction, implementation milestones, and metrics that leadership can use to make informed decisions.

Luna is seeking a Director of Information Security & IT to lead the strategy, execution, and continuous evolution of the company’s enterprise technology and information security programs. Reporting to the Chief Strategy & Product Officer, this leader will be responsible for enterprise cybersecurity, IT operations, healthcare technology systems, identity and access management, infrastructure, and technology compliance, ensuring secure, scalable, and resilient technology solutions that support Luna’s business operations and the delivery of high-quality patient care.

This role is a hands-on leadership position requiring a balance of strategic vision and technical execution. The Director will lead the continued maturation of Luna’s cybersecurity and IT capabilities while remaining actively engaged in technical decision-making, operational leadership, and cross-functional partnership. Working closely with Engineering, Product, Compliance, Legal, and executive leadership, this individual will strengthen Luna’s security posture, safeguard sensitive healthcare information, and build scalable technology programs that enable continued growth within a HIPAA-regulated environment.

### How you will have an impact

* Lead Luna’s enterprise cybersecurity strategy, roadmap, and security operations, continuously strengthening our security posture across cloud infrastructure, endpoints, business systems, and enterprise applications.
* Build, mature, and maintain a comprehensive information security program, including security policies, standards, governance, risk management, and security awareness initiatives.
* Serve as the technical leader for enterprise IT operations, ensuring reliable, secure, and scalable technology services that support business growth and an exceptional employee experience.
* Own Identity and Access Management (IAM), including SSO, MFA, provisioning/deprovisioning, privileged access management, and periodic access reviews.
* Oversee endpoint management, Mobile Device Management (MDM), device lifecycle, asset management, and enterprise SaaS administration.
* Lead vulnerability management, threat detection, penetration testing, incident response, disaster recovery, backup, and business continuity planning.
* Partner with Engineering, Product, Compliance, Legal, Finance, Operations, and People teams to integrate security best practices into enterprise technology and business operations.
* Ensure compliance with HIPAA, HITECH, and other applicable regulatory and security frameworks through technical safeguards, documentation, audits, and remediation activities.
* Manage third-party security assessments, vendor risk reviews, customer security questionnaires, and ongoing technology vendor relationships.
* Evaluate emerging technologies and recommend secure, scalable solutions that improve operational effectiveness while balancing risk, cost, and business priorities.
* Mentor and develop a high-performing IT team while remaining actively involved in technical execution, architecture decisions, and day-to-day operational support.
* Communicate technology strategy, cybersecurity risks, investment recommendations, and program progress to executive leadership.

### What you need

* 8+ years of progressive experience leading information security, enterprise IT, or blended technology functions, including hands-on ownership of enterprise cybersecurity programs.
* Demonstrated success building, implementing, and maturing cybersecurity programs while balancing security, compliance, and business objectives in a healthcare or other highly regulated environment.
* Direct experience supporting healthcare technology environments, including healthcare systems, enterprise applications, and technology platforms within HIPAA-regulated organizations.
* Strong knowledge of healthcare security and compliance requirements, including HIPAA, HITECH, PHI protection, security governance, risk assessments, audits, and remediation activities.
* Hands-on experience with cloud security (AWS, Azure, or GCP), identity and access management (IAM), Single Sign-On (SSO), Multi-Factor Authentication (MFA), endpoint management, Mobile Device Management (MDM), and enterprise infrastructure.
* Experience leading enterprise IT operations, technology roadmaps, incident response, disaster recovery, business continuity, vulnerability management, and security operations.
* Proven ability to lead and mentor technical teams while remaining hands-on with technical execution in a fast-paced, high-growth environment.
* Previous experience as a Director, or as a Senior Manager operating with Director-level scope and responsibility.
* Experience partnering with executive leadership to develop technology strategy, evaluate risk, and communicate complex technical concepts to both technical and non-technical audiences.
* Experience managing third-party vendors, security assessments, customer security questionnaires, and enterprise technology implementations.

### Compensation

Compensation will be commensurate with experience, qualifications, and geographic location, and will reflect the successful candidate’s skills and overall fit for the role.

### Additional Information

Physical therapy, [delivered.www.getluna.com](http://delivered.www.getluna.com/)

#LUNACORP1

Show more

[Apply now >](https://jobicy.com/jobs/153041-director-information-security-and-it.md)

*

![Upload CV](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NSIgaGVpZ2h0PSI2NSIgZmlsbD0ibm9uZSIgeG1sbnM6dj0iaHR0cHM6Ly92ZWN0YS5pby9uYW5vIj48ZyBjbGlwLXBhdGg9InVybCgjQSkiPjxwYXRoIGQ9Ik0wIDBINjVWNjVIMFYwWiIgZmlsbD0iIzAyOWFlYiIvPjxnIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2ZmZiIgc3Ryb2tlLXdpZHRoPSIyIj48cGF0aCBkPSJNMzMuMDQ5IDE1LjQ1NGExLjQzIDEuNDMgMCAwIDAtMi4wOTcgMGwtNy41NzkgOC4xNDdhMS4zOCAxLjM4IDAgMCAwIC4wOSAxLjk3MyAxLjQ0IDEuNDQgMCAwIDAgMi4wMDgtLjA4OGw1LjEwOS01LjQ5MnYyMC42MWExLjQxIDEuNDEgMCAwIDAgMS40MjEgMS4zOTdjLjc4NSAwIDEuNDIxLS42MjUgMS40MjEtMS4zOTd2LTIwLjYxbDUuMTA5IDUuNDkyYTEuNDQgMS40NCAwIDAgMCAyLjAwOC4wODggMS4zOCAxLjM4IDAgMCAwIC4wOS0xLjk3M2wtNy41NzktOC4xNDZ6TTE2Ljc2OSAzOC40YzAtLjc3My0uNjItMS40LTEuMzg1LTEuNFMxNCAzNy42MjcgMTQgMzguNHYuMTAybC4yMTUgNi4yMjljLjIyMyAxLjY4LjcwMSAzLjA5NSAxLjgxMyA0LjIxOHMyLjUxIDEuNjA3IDQuMTcyIDEuODMzYzEuNi4yMTggMy42MzYuMjE4IDYuMTYuMjE4aDExLjI4bDYuMTYtLjIxOGMxLjY2Mi0uMjI2IDMuMDYxLS43MDkgNC4xNzItMS44MzNzMS41ODktMi41MzggMS44MTMtNC4yMThDNTAgNDMuMTEzIDUwIDQxLjA1NSA1MCAzOC41MDNWMzguNGMwLS43NzMtLjYyLTEuNC0xLjM4NS0xLjRzLTEuMzg1LjYyNy0xLjM4NSAxLjRsLS4xOSA1Ljk1OGMtLjE4MiAxLjM3LS41MTUgMi4wOTUtMS4wMjYgMi42MTJzLTEuMjI4Ljg1My0yLjU4MyAxLjAzOGMtMS4zOTUuMTktMy4yNDMuMTkzLTUuODkzLjE5M0gyNi40NjJjLTIuNjUgMC00LjQ5OC0uMDAzLTUuODkzLS4xOTMtMS4zNTUtLjE4NC0yLjA3Mi0uNTIxLTIuNTgzLTEuMDM4cy0uODQ0LTEuMjQyLTEuMDI2LTIuNjEyYy0uMTg3LTEuNDEtLjE5MS0zLjI3OS0uMTkxLTUuOTU4eiIvPjwvZz48L2c+PGRlZnM+PGNsaXBQYXRoIGlkPSJBIj48cGF0aCBmaWxsPSIjZmZmIiBkPSJNMCAwaDY1djY1SDB6Ii8+PC9jbGlwUGF0aD48L2RlZnM+PC9zdmc+)

### Upload your resume now

To unlock remote work opportunities and be discovered by global employers.

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

## Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Keep exploring

## Related remote jobs.

Matched by job category10 related opportunities[Cybersecurity](https://jobicy.com/categories/cybersecurity.md) [Browse all jobs](https://jobicy.com/jobs.md)
*
![Stripe logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/10/WRILS-201011073943-272457.png)
Stripe  Sep 11

### [Abuse Research Engineer](https://jobicy.com/jobs/153053-abuse-research-engineer.md)

Who we are About Stripe Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow…

*
![Ping Identity logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/09/63e8d5a6-221.png)
Ping Identity  Sep 11

### [Cyber Security Engineer II](https://jobicy.com/jobs/153056-cyber-security-engineer-ii.md)

About Ping Identity: At Ping Identity, we believe in making digital experiences both secure and seamless for all users, without compromise. We call this digital freedom. And it’s not just…

*
![CertiK logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/03/Jobicy-210308091023-955845.jpg)
CertiK  Sep 10

### [Blockchain Security Expert Intern – AI Track](https://jobicy.com/jobs/152979-blockchain-security-expert-intern-ai-track.md)

About the Company Founded in 2018 by professors of Yale University and Columbia University, CertiK is a pioneer in blockchain security, utilizing best-in-class AI technology to secure and monitor blockchain…

*
![CertiK logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/03/Jobicy-210308091023-955845.jpg)
CertiK  Sep 10

### [Blockchain Security Expert – Security Audit Track](https://jobicy.com/jobs/152975-blockchain-security-expert-security-audit-track.md)

About You You’re a self-starter. You believe in tackling the most important problems, even if they are the most difficult problems. You’re comfortable with the unknown and understand that #startuplife…

*
![CertiK logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/03/Jobicy-210308091023-955845.jpg)
CertiK  Sep 10

### [Blockchain Security Expert – Chain Security Evaluation Track](https://jobicy.com/jobs/152970-blockchain-security-expert-chain-security-evaluation-track.md)

About You You’re a self-starter who thrives on tackling the toughest and most meaningful problems, even if they are the most difficult problems. You’re comfortable with the unknown and understand…

*
![Synthesia logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/06/c69aad11-221.webp)
Synthesia  Sep 10

### [SecOps Security Engineer (Staff-level, L6)](https://jobicy.com/jobs/152968-secops-security-engineer-staff-level-l6.md)

Synthesia is the world’s leading AI video platform for business, used by over 90% of the Fortune 100. Founded in 2017, the company is headquartered in London, with offices and…

*
![CertiK logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/03/Jobicy-210308091023-955845.jpg)
CertiK  Sep 10

### [Blockchain Security Expert – Anti Defect Track](https://jobicy.com/jobs/152966-blockchain-security-expert-anti-defect-track.md)

About the Company Founded in 2018 by professors of Yale University and Columbia University, CertiK is a pioneer in blockchain security, utilizing best-in-class AI technology to secure and monitor blockchain…

*
![Fortive logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/06/08ee6cc3-221.webp)
Fortive  Sep 10

### [Chief Information Security Officer](https://jobicy.com/jobs/149008-chief-information-security-officer.md)

Position Summary The Chief Information Security Officer (CISO) owns enterprise security strategy, risk management, and compliance for the FAL Group of companies under Fortive (Accruent, Gordian, and ServiceChannel) all of…

*
![Vercel logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/a6aded72-221.png)
Vercel  Sep 9

### [Security Engineer, Cloud](https://jobicy.com/jobs/152929-security-engineer-cloud.md)

About Vercel: Vercel is the agentic infrastructure company. We free people and agents to ship what’s next. For more than a decade, Vercel has shaped how the web is built….

*
![Tremendous logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/01/c2bd8be5-221.jpeg)
Tremendous  Sep 9

### [Head of Security](https://jobicy.com/jobs/152862-head-of-security.md)

Tremendous is the global platform built for businesses to send payouts—gift cards and money—to anyone, anywhere, instantly. We’re trusted by 20,000+ organizations, from startups to giants like Atlassian, MIT, and…