{"schemaVersion":"jobsearcher.job.v1","id":"a1d95b87f1c19c3eca20425f","url":"https://jobsearcher.com/jobs/a1d95b87f1c19c3eca20425f","canonicalUrl":"https://jobsearcher.com/jobs/a1d95b87f1c19c3eca20425f","title":"VP - Information Security & IT Operations","description":"DEPARTMENT\n\nInformation Security / Information Technology\n\nREPORTS TO\n\nChief Technology Officer\n\nFLSA STATUS\n\nExempt\n\nEMPLOYMENT TYPE\n\nFull-Time\n\nWORK MODEL\n\nHybrid/Remote\n\nLOCATION\n\nRemote — must reside in FL, GA, or TX. Candidates local to the Tampa Bay area may be required to work onsite occasionally.\n\nTRAVEL REQUIREMENT\n\nUp to 10%\n\nEDUCATION\n\nBachelor's degree in Information Security, Computer Science, Information Technology, or a related field, or equivalent professional experience.\n\nABOUT SIGHTVIEW\n\nSightview Software LLC provides a suite of industry-leading software specifically geared toward ophthalmology and optometry practices — practice management, surgical, revenue cycle management (RCM), MIPS reporting, and more. Sightview is a one-stop shop for eye care specialists and their patients.\n\nIntegrity • Collaboration • Accountability • Resilience • Engagement\n\nJOB SUMMARY\n\nThe VP, Information Security & IT Operations is the single accountable executive for Sightview's corporate technology infrastructure and its enterprise information security and privacy program. This role owns two interconnected mandates: (1) ensuring Sightview's internal IT systems, infrastructure, and operations run reliably, securely, and cost-effectively to support the business day-to-day, and (2) building, leading, and continuously maturing the company's cybersecurity, risk, and privacy program to protect the organization, its customers, and its data. The VP owns the security and privacy program, supported by a GRC Manager and Security Team Leads, and partners closely with DevOps, Engineering, and Product to embed security into how Sightview builds and operates.\n\nESSENTIAL DUTIES & RESPONSIBILITIES\n\nCorporate IT Operations & Infrastructure Leadership – 30%\nLead day-to-day corporate IT discussions, priorities, and decision-making across infrastructure, end-user computing, and business systems.\nOwn IT project plans and roadmaps, ensuring initiatives are scoped, resourced, sequenced, and delivered on schedule.\nServe as the escalation point and approver for IT systems changes, purchase requests, and operational expenses.\nOversee corporate network, systems, and infrastructure operations to ensure reliability, availability, and performance at an optimal level.\nManage the IT budget: forecasting, vendor contracts, licensing, and expense approvals, ensuring cost-effective use of resources.\nPartner with department leaders across the business to translate operational needs into IT solutions and support requests.\nEvaluate, select, and manage relationships with IT vendors, managed service providers, and technology partners.\nInformation Security & Privacy Program Leadership – 60%\nOwn the enterprise cybersecurity program end-to-end, acting as the accountable owner of security and privacy outcomes, supported by the GRC Manager and Security Team Leads.\nLead Sightview's SOC 2 Type II and HITRUST programs, including audit readiness, evidence collection, control testing, gap remediation, and ongoing certification maintenance.\nDevelop, maintain, and continuously improve security policies, processes, and standard operating procedures (SOPs) aligned to industry frameworks (e.g., NIST, ISO 27001, HITRUST CSF).\nCollaborate cross-functionally with DevOps and Engineering/Development teams to embed secure-by-design principles, secure SDLC practices, and security tooling into the development and deployment pipeline.\nOwn the enterprise risk management program: identify, assess, prioritize, track, and report on security and privacy risks to leadership.\nLead the third-party and vendor security risk assessment program, ensuring vendors and partners meet Sightview's security and privacy requirements before and during engagement.\nOwn budget decisions for security and privacy application/tooling services (e.g., SIEM, vulnerability management, WAF, endpoint/cloud security tooling, GRC platforms), prioritizing spend against risk and program maturity goals.\nOperate comfortably within Sightview's AWS infrastructure with deep, hands-on-level familiarity — reviewing CloudTrail logs, firewall rules, and WAF configurations, and asking the right technical questions of engineering/DevOps to confirm infrastructure integrity is maintained.\nEnsure security operations and network operations run at an optimal level; personally review and question any major red flags, anomalies, or emerging threats.\nOwn the design, deployment, and maturity of the Application Security program in partnership with Engineering and DevOps.\nGuide, mentor, and develop team members — including onboarding new hires, building team capability, and fostering a culture of security ownership.\nLead incident response for security events, coordinating investigation, containment, remediation, and post-incident reporting.\nMaintain the organization's privacy program in coordination with legal/compliance stakeholders, ensuring data handling practices meet regulatory and contractual obligations.\nServe as Sightview's subject matter expert on HIPAA, HITECH, and ONC (Office of the National Coordinator for Health IT) requirements, confidently and accurately answering compliance and security questions from customers, auditors, regulators, and internal stakeholders.\nLeadership, Governance & Executive Reporting – 10%\nReport program status, risk posture, and key metrics to executive leadership and, where applicable, the board or audit committee.\nSet the strategic direction and annual roadmap for both IT operations and the security/privacy program, aligned to business goals.\nOwn and manage the combined IT and security budget, staffing plan, and resource allocation.\nRepresent security and IT operations in customer, auditor, and regulator conversations as needed.\n\nREQUIRED QUALIFICATIONS\n\n9-11 years of progressive experience in information security and/or IT leadership, including 3+ years in a senior/executive-level role owning both a security program and IT operations.\nDemonstrated experience leading organizations through SOC 2 Type II and HITRUST certification and audit cycles.\nStrong working knowledge of security frameworks (NIST CSF, ISO 27001, HITRUST CSF) and risk management methodologies.\nExperience partnering with DevOps and Engineering teams on secure SDLC, cloud security, and application security programs.\nProven track record managing third-party/vendor risk assessment programs.\nExperience owning corporate IT infrastructure, end-user computing, and business systems in a growing organization.\nStrong budget management experience across both IT and security spend, including direct ownership of budget decisions for security and privacy application/tooling services.\nExcellent stakeholder management and communication skills, with the ability to translate technical risk into business terms for executive audiences.\nDemonstrated people leadership: hiring, mentoring, and developing security and IT talent.\nAWS & Cloud Infrastructure Expertise\nExtensive, hands-on experience operating within AWS infrastructure, with the technical depth to engage directly rather than rely solely on reports from engineering teams.\nDemonstrated proficiency reading and interpreting AWS CloudTrail logs to investigate activity, trace changes, and identify anomalous or unauthorized behavior.\nStrong working knowledge of firewall and Web Application Firewall (WAF) configuration, rule sets, and log review.\nAbility to ask precise, informed technical questions of DevOps and Engineering to validate that infrastructure integrity and security controls remain intact.\nRegulatory & Compliance Subject Matter Expertise\nRecognized subject matter expert in HIPAA, HITECH, and ONC (Office of the National Coordinator for Health IT) requirements as they apply to a healthcare SaaS environment.\nAble to confidently and accurately field compliance and security questions from customers, auditors, regulators, and internal teams without needing to escalate.\n\nPREFERRED QUALIFICATIONS\n\nCISSP, CISM, or CRISC\nHITRUST Certified Practitioner (or equivalent HITRUST assessment experience)\nAWS Certified Security – Specialty or equivalent AWS security certification\n\nPHYSICAL REQUIREMENTS & WORK ENVIRONMENT\n\nProlonged periods of sitting at a desk and working on a computer\nRegular use of a keyboard, mouse, and monitor, requiring repetitive hand and wrist motion\nAbility to communicate clearly by phone, video conference, and in person\nAbility to read and interpret information on a computer screen and in printed documents\nOccasional standing, walking, bending, and reaching within an office environment\nAbility to occasionally lift and move office supplies or equipment weighing up to 15 pounds\n\nCOMPENSATION & BENEFITS\n\nThe anticipated pay range for this role is $140,000 – $180,000 per year, based on experience, qualifications, location, and internal equity. Actual pay may vary from the posted range.\n\nThis role participates in Sightview's management bonus plan, with an annual bonus of 15% of base salary.\n\nSightview offers a comprehensive benefits package that includes medical, dental, and vision coverage; a 401(k) plan with company match; and a selection of additional voluntary benefits. Eligibility and plan details are provided during onboarding.\n\nBACKGROUND CHECK & DRUG-FREE WORKPLACE\n\nEmployment with Sightview is contingent upon successful completion of a pre-employment background check. Sightview also conducts drug testing as a condition of employment. Our screening panel includes marijuana; however, a positive marijuana result alone will not disqualify an applicant from employment.\n\nEQUAL EMPLOYMENT OPPORTUNITY\n\nSightview Software LLC is an Equal Opportunity Employer. We recruit, hire, train, and promote without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, veteran status, or any other characteristic protected by applicable federal, state, or local law.\n\nREASONABLE ACCOMMODATION\n\nSightview is committed to providing reasonable accommodations to qualified individuals with disabilities throughout the application and employment process. If you require an accommodation, please contact Human Resources to make your request.","company":"Sightview Software","rawCompany":"sightview software","city":"Tampa","state":"FL","isRemote":false,"isActive":false,"createdAt":"2026-08-23T09:51:55.875Z","occupations":[{"code":"11-3021.00","title":"Computer and Information Systems Managers","slug":"computer-and-information-systems-managers"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"11-3013.01","title":"Security Managers","slug":"security-managers"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"621111","title":"Offices of Physicians (except Mental Health Specialists)","slug":"offices-of-physicians-except-mental-health-specialists"},{"code":"621320","title":"Offices of Optometrists","slug":"offices-of-optometrists"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"VP - Information Security & IT Operations","description":"DEPARTMENT\n\nInformation Security / Information Technology\n\nREPORTS TO\n\nChief Technology Officer\n\nFLSA STATUS\n\nExempt\n\nEMPLOYMENT TYPE\n\nFull-Time\n\nWORK MODEL\n\nHybrid/Remote\n\nLOCATION\n\nRemote — must reside in FL, GA, or TX. Candidates local to the Tampa Bay area may be required to work onsite occasionally.\n\nTRAVEL REQUIREMENT\n\nUp to 10%\n\nEDUCATION\n\nBachelor's degree in Information Security, Computer Science, Information Technology, or a related field, or equivalent professional experience.\n\nABOUT SIGHTVIEW\n\nSightview Software LLC provides a suite of industry-leading software specifically geared toward ophthalmology and optometry practices — practice management, surgical, revenue cycle management (RCM), MIPS reporting, and more. Sightview is a one-stop shop for eye care specialists and their patients.\n\nIntegrity • Collaboration • Accountability • Resilience • Engagement\n\nJOB SUMMARY\n\nThe VP, Information Security & IT Operations is the single accountable executive for Sightview's corporate technology infrastructure and its enterprise information security and privacy program. This role owns two interconnected mandates: (1) ensuring Sightview's internal IT systems, infrastructure, and operations run reliably, securely, and cost-effectively to support the business day-to-day, and (2) building, leading, and continuously maturing the company's cybersecurity, risk, and privacy program to protect the organization, its customers, and its data. The VP owns the security and privacy program, supported by a GRC Manager and Security Team Leads, and partners closely with DevOps, Engineering, and Product to embed security into how Sightview builds and operates.\n\nESSENTIAL DUTIES & RESPONSIBILITIES\n\nCorporate IT Operations & Infrastructure Leadership – 30%\nLead day-to-day corporate IT discussions, priorities, and decision-making across infrastructure, end-user computing, and business systems.\nOwn IT project plans and roadmaps, ensuring initiatives are scoped, resourced, sequenced, and delivered on schedule.\nServe as the escalation point and approver for IT systems changes, purchase requests, and operational expenses.\nOversee corporate network, systems, and infrastructure operations to ensure reliability, availability, and performance at an optimal level.\nManage the IT budget: forecasting, vendor contracts, licensing, and expense approvals, ensuring cost-effective use of resources.\nPartner with department leaders across the business to translate operational needs into IT solutions and support requests.\nEvaluate, select, and manage relationships with IT vendors, managed service providers, and technology partners.\nInformation Security & Privacy Program Leadership – 60%\nOwn the enterprise cybersecurity program end-to-end, acting as the accountable owner of security and privacy outcomes, supported by the GRC Manager and Security Team Leads.\nLead Sightview's SOC 2 Type II and HITRUST programs, including audit readiness, evidence collection, control testing, gap remediation, and ongoing certification maintenance.\nDevelop, maintain, and continuously improve security policies, processes, and standard operating procedures (SOPs) aligned to industry frameworks (e.g., NIST, ISO 27001, HITRUST CSF).\nCollaborate cross-functionally with DevOps and Engineering/Development teams to embed secure-by-design principles, secure SDLC practices, and security tooling into the development and deployment pipeline.\nOwn the enterprise risk management program: identify, assess, prioritize, track, and report on security and privacy risks to leadership.\nLead the third-party and vendor security risk assessment program, ensuring vendors and partners meet Sightview's security and privacy requirements before and during engagement.\nOwn budget decisions for security and privacy application/tooling services (e.g., SIEM, vulnerability management, WAF, endpoint/cloud security tooling, GRC platforms), prioritizing spend against risk and program maturity goals.\nOperate comfortably within Sightview's AWS infrastructure with deep, hands-on-level familiarity — reviewing CloudTrail logs, firewall rules, and WAF configurations, and asking the right technical questions of engineering/DevOps to confirm infrastructure integrity is maintained.\nEnsure security operations and network operations run at an optimal level; personally review and question any major red flags, anomalies, or emerging threats.\nOwn the design, deployment, and maturity of the Application Security program in partnership with Engineering and DevOps.\nGuide, mentor, and develop team members — including onboarding new hires, building team capability, and fostering a culture of security ownership.\nLead incident response for security events, coordinating investigation, containment, remediation, and post-incident reporting.\nMaintain the organization's privacy program in coordination with legal/compliance stakeholders, ensuring data handling practices meet regulatory and contractual obligations.\nServe as Sightview's subject matter expert on HIPAA, HITECH, and ONC (Office of the National Coordinator for Health IT) requirements, confidently and accurately answering compliance and security questions from customers, auditors, regulators, and internal stakeholders.\nLeadership, Governance & Executive Reporting – 10%\nReport program status, risk posture, and key metrics to executive leadership and, where applicable, the board or audit committee.\nSet the strategic direction and annual roadmap for both IT operations and the security/privacy program, aligned to business goals.\nOwn and manage the combined IT and security budget, staffing plan, and resource allocation.\nRepresent security and IT operations in customer, auditor, and regulator conversations as needed.\n\nREQUIRED QUALIFICATIONS\n\n9-11 years of progressive experience in information security and/or IT leadership, including 3+ years in a senior/executive-level role owning both a security program and IT operations.\nDemonstrated experience leading organizations through SOC 2 Type II and HITRUST certification and audit cycles.\nStrong working knowledge of security frameworks (NIST CSF, ISO 27001, HITRUST CSF) and risk management methodologies.\nExperience partnering with DevOps and Engineering teams on secure SDLC, cloud security, and application security programs.\nProven track record managing third-party/vendor risk assessment programs.\nExperience owning corporate IT infrastructure, end-user computing, and business systems in a growing organization.\nStrong budget management experience across both IT and security spend, including direct ownership of budget decisions for security and privacy application/tooling services.\nExcellent stakeholder management and communication skills, with the ability to translate technical risk into business terms for executive audiences.\nDemonstrated people leadership: hiring, mentoring, and developing security and IT talent.\nAWS & Cloud Infrastructure Expertise\nExtensive, hands-on experience operating within AWS infrastructure, with the technical depth to engage directly rather than rely solely on reports from engineering teams.\nDemonstrated proficiency reading and interpreting AWS CloudTrail logs to investigate activity, trace changes, and identify anomalous or unauthorized behavior.\nStrong working knowledge of firewall and Web Application Firewall (WAF) configuration, rule sets, and log review.\nAbility to ask precise, informed technical questions of DevOps and Engineering to validate that infrastructure integrity and security controls remain intact.\nRegulatory & Compliance Subject Matter Expertise\nRecognized subject matter expert in HIPAA, HITECH, and ONC (Office of the National Coordinator for Health IT) requirements as they apply to a healthcare SaaS environment.\nAble to confidently and accurately field compliance and security questions from customers, auditors, regulators, and internal teams without needing to escalate.\n\nPREFERRED QUALIFICATIONS\n\nCISSP, CISM, or CRISC\nHITRUST Certified Practitioner (or equivalent HITRUST assessment experience)\nAWS Certified Security – Specialty or equivalent AWS security certification\n\nPHYSICAL REQUIREMENTS & WORK ENVIRONMENT\n\nProlonged periods of sitting at a desk and working on a computer\nRegular use of a keyboard, mouse, and monitor, requiring repetitive hand and wrist motion\nAbility to communicate clearly by phone, video conference, and in person\nAbility to read and interpret information on a computer screen and in printed documents\nOccasional standing, walking, bending, and reaching within an office environment\nAbility to occasionally lift and move office supplies or equipment weighing up to 15 pounds\n\nCOMPENSATION & BENEFITS\n\nThe anticipated pay range for this role is $140,000 – $180,000 per year, based on experience, qualifications, location, and internal equity. Actual pay may vary from the posted range.\n\nThis role participates in Sightview's management bonus plan, with an annual bonus of 15% of base salary.\n\nSightview offers a comprehensive benefits package that includes medical, dental, and vision coverage; a 401(k) plan with company match; and a selection of additional voluntary benefits. Eligibility and plan details are provided during onboarding.\n\nBACKGROUND CHECK & DRUG-FREE WORKPLACE\n\nEmployment with Sightview is contingent upon successful completion of a pre-employment background check. Sightview also conducts drug testing as a condition of employment. Our screening panel includes marijuana; however, a positive marijuana result alone will not disqualify an applicant from employment.\n\nEQUAL EMPLOYMENT OPPORTUNITY\n\nSightview Software LLC is an Equal Opportunity Employer. We recruit, hire, train, and promote without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, veteran status, or any other characteristic protected by applicable federal, state, or local law.\n\nREASONABLE ACCOMMODATION\n\nSightview is committed to providing reasonable accommodations to qualified individuals with disabilities throughout the application and employment process. If you require an accommodation, please contact Human Resources to make your request.","datePosted":"2026-08-23T09:51:55.875Z","dateModified":"2026-08-23T09:51:55.875Z","hiringOrganization":{"@type":"Organization","name":"Sightview Software","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Tampa","addressRegion":"FL","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"a1d95b87f1c19c3eca20425f"},"url":"https://jobsearcher.com/jobs/a1d95b87f1c19c3eca20425f"}}