Logo for Luna Physical Therapy

Director , Information Security and IT

Role overview

Qualifications

  • 8+ years of progressive experience leading information security, enterprise IT, or blended technology functions
  • Demonstrated success building, implementing, and maturing cybersecurity programs in healthcare or highly regulated environments
  • Strong knowledge of healthcare security and compliance requirements, including HIPAA and HITECH
  • Hands-on experience with cloud security, IAM, SSO, MFA, and enterprise infrastructure

Responsibilities

  • Lead Luna's enterprise cybersecurity strategy, roadmap, and security operations
  • Build, mature, and maintain a comprehensive information security program
  • Serve as the technical leader for enterprise IT operations
  • Own Identity and Access Management (IAM) and oversee endpoint management

Key facts

Other skills

  • Leadership
  • Communication
  • Mentorship
  • Strategic Planning

About the company

Luna Physical Therapy logo

Luna Physical Therapy

Physical, Occupational & Speech Therapy

Luna is the leading in-home physical therapy platform, offering 1:1 personalized care at home that is covered by insurance. By shifting treatment from the clinic to the home, Luna is reinventing outpatient physical therapy and improving convenience, access, safety, and adherence. Luna’s licensed therapists are available seven days a week and can be requested via the app. Luna is proud to partner with outstanding healthcare providers like Emory Health, Scripps Health, UCLA Health, and Intermountain Healthcare.

Company details

Company typeLarge
IndustryPhysical, Occupational & Speech Therapy
Company size1001 - 5000

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Luna is seeking a Director of Information Security & IT to lead the strategy, execution, and continuous evolution of the company's enterprise technology and information security programs. Reporting to the Chief Strategy & Product Officer, this leader will be responsible for enterprise cybersecurity, IT operations, healthcare technology systems, identity and access management, infrastructure, and technology compliance, ensuring secure, scalable, and resilient technology solutions that support Luna's business operations and the delivery of high-quality patient care.

This role is a hands-on leadership position requiring a balance of strategic vision and technical execution. The Director will lead the continued maturation of Luna's cybersecurity and IT capabilities while remaining actively engaged in technical decision-making, operational leadership, and cross-functional partnership. Working closely with Engineering, Product, Compliance, Legal, and executive leadership, this individual will strengthen Luna's security posture, safeguard sensitive healthcare information, and build scalable technology programs that enable continued growth within a HIPAA-regulated environment.


How you will have an impact
  • Lead Luna's enterprise cybersecurity strategy, roadmap, and security operations, continuously strengthening our security posture across cloud infrastructure, endpoints, business systems, and enterprise applications.
  • Build, mature, and maintain a comprehensive information security program, including security policies, standards, governance, risk management, and security awareness initiatives.
  • Serve as the technical leader for enterprise IT operations, ensuring reliable, secure, and scalable technology services that support business growth and an exceptional employee experience.
  • Own Identity and Access Management (IAM), including SSO, MFA, provisioning/deprovisioning, privileged access management, and periodic access reviews.
  • Oversee endpoint management, Mobile Device Management (MDM), device lifecycle, asset management, and enterprise SaaS administration.
  • Lead vulnerability management, threat detection, penetration testing, incident response, disaster recovery, backup, and business continuity planning.
  • Partner with Engineering, Product, Compliance, Legal, Finance, Operations, and People teams to integrate security best practices into enterprise technology and business operations.
  • Ensure compliance with HIPAA, HITECH, and other applicable regulatory and security frameworks through technical safeguards, documentation, audits, and remediation activities.
  • Manage third-party security assessments, vendor risk reviews, customer security questionnaires, and ongoing technology vendor relationships.
  • Evaluate emerging technologies and recommend secure, scalable solutions that improve operational effectiveness while balancing risk, cost, and business priorities.
  • Mentor and develop a high-performing IT team while remaining actively involved in technical execution, architecture decisions, and day-to-day operational support.
  • Communicate technology strategy, cybersecurity risks, investment recommendations, and program progress to executive leadership.

  • What you need
  • 8+ years of progressive experience leading information security, enterprise IT, or blended technology functions, including hands-on ownership of enterprise cybersecurity programs.
  • Demonstrated success building, implementing, and maturing cybersecurity programs while balancing security, compliance, and business objectives in a healthcare or other highly regulated environment.
  • Direct experience supporting healthcare technology environments, including healthcare systems, enterprise applications, and technology platforms within HIPAA-regulated organizations.
  • Strong knowledge of healthcare security and compliance requirements, including HIPAA, HITECH, PHI protection, security governance, risk assessments, audits, and remediation activities.
  • Hands-on experience with cloud security (AWS, Azure, or GCP), identity and access management (IAM), Single Sign-On (SSO), Multi-Factor Authentication (MFA), endpoint management, Mobile Device Management (MDM), and enterprise infrastructure.
  • Experience leading enterprise IT operations, technology roadmaps, incident response, disaster recovery, business continuity, vulnerability management, and security operations.
  • Proven ability to lead and mentor technical teams while remaining hands-on with technical execution in a fast-paced, high-growth environment.
  • Previous experience as a Director, or as a Senior Manager operating with Director-level scope and responsibility.
  • Experience partnering with executive leadership to develop technology strategy, evaluate risk, and communicate complex technical concepts to both technical and non-technical audiences.
  • Experience managing third-party vendors, security assessments, customer security questionnaires, and enterprise technology implementations.
  • Physical therapy, delivered.www.getluna.com
    #LUNACORP1

    Apply once. Then go straight to the hiring manager.

    After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

    MR

    Marcus Rivera

    Chief Revenue Officer

    m.rivera@company.com
    linkedin.com/in/marcusrivera
    Unlocked after you apply
    ·

    IT Security Manager Related jobs

    Other jobs at Luna Physical Therapy

    Premium

    Reach out to the hiring manager directly.

    Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

    • Full match report with fit score and gaps
    • Career diagnostics on how recruiters read you
    • Curated company matches and warm intros
    • 48h early access to new roles

    Cancel anytime.