Important Note: The individual hired for this role must reside in the United States during the term of employment. Applicants to this role must currently have the ability to legally hold employment in the United States; Digital Harbor is unable to provide Visa sponsorship for this position.
Overview
The Chief Information Officer (CIO) leads Digital Harbor Foundation's internal information technology function. The role holds end-to-end accountability for the organization's technology stack, IT service delivery, data governance, and information security program, ensuring the confidentiality, integrity, and availability of the organization’s IT infrastructure and data. The CIO sets IT strategy and manages technology investment while also owning security policy, risk management, and incident response. The role balances the need for strong cybersecurity and data practices with the operational realities of a mission-driven nonprofit – limited budgets, lean IT staff, reliance on cloud and third-party vendors, and an obligation to safeguard sensitive information necessary for program delivery.
The CIO reports to the Chief Executive Officer, serves on the executive team, and directly manages the Director of Technical Systems, who oversees the day-to-day operations of Digital Harbor’s IT infrastructure and first-line IT support requests. This role sits within the Impact Studio, Digital Harbor Foundation's cross-cutting team encompassing IT, Finance, Operations/HR, Development/Communications, and Programs. Unlike project-specific staff, the Impact Studio works across all the organization's projects, giving the CIO unique visibility into and influence over how IT and security practices are applied consistently across the full portfolio of programs and initiatives.
Digital Harbor Foundation is dedicated to digital equity for everyone, increasing diversity in the technology sector, and advancing technology innovation for the public good. Driven by our sincere belief that access to opportunity is a basic right, we take bold yet practical actions to support making a better future now. Through a portfolio of projects focused on developing leadership within communities, we support those closest to challenges to take deliberate actions based on a design thinking approach, backed by data analysis, grounded in a practice of collective impact, and driven by a commitment to racial equity.
Education and Experience Requirements
- Bachelor's degree in Information Technology, Information Security, Computer Science, or a related field, or equivalent professional experience.
- 10+ years of progressive experience in information technology and/or information security, including at least 3 years at a senior leadership level with accountability for an organization-wide IT or security program.
- Demonstrated experience owning an enterprise technology stack, including cloud productivity platforms, CRM or donor management systems, public cloud infrastructure, identity and access management, and endpoint/device management.
- Experience overseeing data privacy, governance, and compliance requirements within a nonprofit environment.
- Experience maturing an organization’s cybersecurity posture, including experience building and implementing standards, overseeing risk management functions, leading incident response, and communicating risk to non-technical executives and Board members.
- Working knowledge of appropriate security frameworks and how to apply them at a scale appropriate to a nonprofit's size and resources.
- Experience implementing and administering an IT service management or ticketing platform and operating a support function against defined service level agreements.
- Experience supervising technical staff and managing external vendors or managed service providers.
- [Preferred] Prior experience in the nonprofit, education, or public sector preferred, with familiarity with grant compliance and funder data requirements.
- [Preferred] Experience in a fiscal sponsorship environment.
Knowledge, Skills and Abilities
- Excellent written and verbal communication, with strong interpersonal and presentation skills.
- Ability to translate technical and security risk into plain-language guidance for non-technical staff, executives, and Board members.
- Sound judgment in risk-based decision-making under resource constraints.
- Ability to think strategically and make recommendations that take into account competing needs and priorities.
- Strong knowledge of IT best practices, policies, and regulations.
- Understanding of current technology trends and a desire for continuous learning.
- Great project management skills, including organization, planning, time management, and prioritization.
- Ability to balance multiple projects in a growing and evolving environment.
- Ability to effectively collaborate on informal and formal projects with various departments within the organization, and with a positive disposition.
- A customer service orientation, and the ability to hold an IT function accountable to it.
- Strong orientation toward details
C-Level Executive Attributes
This is a senior leadership role at the Digital Harbor Foundation. We have found that effective leaders within the organization consistently:
- Think strategically and play a strong role in shaping a vision for the Foundation's future.
- Develop a plan for how their functional area will support that strategic vision.
- Rally their employees around the strategic vision.
- Prepare their teams to execute on the tasks that help achieve the Foundation's goals.
- Persuade, influence, and inspire C-suite colleagues, direct reports, managers, and employees.
- Guide their departments through changes while minimizing the negative impact of disruptions.
- Draw on deep expertise in the functional areas they oversee.
- Effectively delegate management duties.
- Assess their direct reports against key metrics to ensure quality performance and improvement.
- Effectively communicate to a range of managerial and staff employees in various settings.
- Emulate the traits and behaviors valued by the Foundation's leadership.
Role and Responsibilities
IT Infrastructure & Technology Stack Oversight
- Hold overall accountability for Digital Harbor Foundation's technology stack, including productivity and collaboration platforms (Google Workspace, Microsoft Office 365, Slack, and Zoom), development operations platforms (Salesforce and Donorbox), finance and HR systems, project and task management, cloud infrastructure (with existing infrastructure in AWS), web properties, and the employee device fleet.
- Own the architecture and standards for the stack: which systems the organization uses, how they integrate, where authoritative data lives, and how new tools are evaluated, approved, and retired.
- Manage the Director of Technical Systems in the day-to-day administration, configuration, and maintenance of these platforms, retaining final approval on standards, exceptions, and material configuration changes.
- Lead technology selection and procurement, including scoping requirements, vendor evaluation, security and privacy review, contract and licensing negotiation, and renewal decisions.
- Own the organization's identity architecture, including the multi-year rollout of single sign-on and federated identity across all critical services, and the licensing and sequencing decisions that rollout requires.
- Ensure the standard technology stack is deployed consistently for new fiscally sponsored projects and that data and platforms transition cleanly and completely when projects spin out.
- Work with the Director of Technical Systems to oversee the device fleet, including provisioning and retrieval of organization-owned devices.
- Ensure technology systems and platforms are documented, with clear ownership for each system and SOPs for critical processes.
IT Support and Ticketing System Administration
- Provide high-satisfaction first-line IT support to all employees and contractors.
- Serve as owner and senior administrator of Digital Harbor Foundation's ticketing system (BoldDesk), and support associated internal training needs. Note:
- First-line IT support response is currently provided by the Director of Technical Systems using BoldDesk as a ticket management platform.
- Several other verticals within the organization use BoldDesk to manage various work requests (e.g., Operations, Human Resources, and Finance).
- Work with the Director of Technical Systems to establish and maintain service level agreements by request type for the technology function.
- Define, monitor, and report service metrics for IT-related tickets.
- Use ticket data to identify recurring failures, training gaps, and systemic issues, and drive root-cause remediation and documentation for self-service.
- Ensure appropriate access controls and audit logging within the ticketing system, recognizing that tickets frequently contain sensitive account, personnel, and security information.
Technology Strategy and Governance
- Develop and own a multi-year technology strategy and roadmap aligned with Digital Harbor Foundation's mission, fiscal sponsorship model, risk tolerance, and available resources.
- Ensure technology strategy accounts for the full lifecycle of fiscally sponsored projects, from onboarding onto Digital Harbor Foundation's standard stack through data and platform transition at spin-out.
- Develop and manage the organization's technology and information security budget, covering software licensing, device fleet and hardware, cloud infrastructure, insurance premiums, contracted services, and staffing.
- Establish and maintain a technology cost allocation methodology for fiscally sponsored projects, track spending and renewals, and report budget variances and forecasts to Finance leadership and the CEO.
- Identify cost-effective tools and, where relevant, pursue nonprofit technology discounts, grants, or in-kind donations.
- Develop a data governance strategy, defining data ownership and stewardship, classification levels, quality standards, and lifecycle management (operational aspects of this responsibility covered in more detail below).
- Manage various IT governance tasks: policies, standards, and procedures covering acceptable use, access control, change management, software approval and procurement, and incident response.
Security Operations
- Direct the organization's information security program, including identity and access management, endpoint protection, cloud infrastructure security, email and phishing defenses, and logging and monitoring on sensitive data.
- Develop and manage access control standards, including least privilege, role-based access, multi-factor authentication on all critical systems, privileged and administrative account management, and quarterly user access reviews across all platforms.
- Own incident response end-to-end.
- Develop and regularly test an incident response plan.
- Determine breach notification obligations in consultation with legal counsel, insurers, and impacted funders.
- Lead any breach-related communication with staff, participants, donors, and the Board during an incident.
- Oversee vulnerability and patch management, endpoint posture enforcement through MDM, periodic vulnerability scanning, and future independent security assessments.
- Work with the Director of Technical Systems to implement and monitor appropriate security controls.
- Ensure security requirements are applied consistently across all projects in the fiscally sponsored project portfolio, including projects operating tools outside the standard stack.
- Design and deliver security awareness training for staff, contractors, and Board members, including annual cybersecurity training and ongoing phishing simulation.
- Own the data backup and recovery program for critical data, ensuring it is comprehensive and regularly verified.
Data Governance, Risk Management, and Compliance
- Assess data-related risks for prospective projects; manage the IT systems and data review of all new projects joining the organization.
- Ensure contracts, MOUs, and fiscal sponsorship agreements carry appropriate technology, data protection, insurance, and indemnification terms, in coordination with Finance and legal counsel.
- Conduct an initial and ongoing audit of the data that various projects ingest, process, and store to ensure appropriate controls are in place. Additionally, confirm that projects are managing data in compliance with Digital Harbor Foundation policies and various data sharing and handling agreements.
- Ensure security and privacy practices comply with applicable laws and regulations (e.g., state data breach notification laws, state privacy statutes, FERPA, HIPAA, and grant-specific data security requirements).
- Develop and maintain a right-sized control set mapped to a recognized framework with documented evidence.
- Oversee Digital Harbor’s IT risk management function.
- Conduct regular risk assessments across systems, vendors, and data flows.
- Develop and maintain a means of tracking IT- and data-related risk. Report on risk, control gaps, and remediation progress to the CEO and Board on a defined cadence.
- Own third-party risk management, including security and privacy reviews of service providers and software solutions.
- Support the organization in developing and annually testing business continuity and disaster recovery plans.
- Manage the organization’s technology-related insurance policies (cyber liability and tech-related professional liability), including assessing coverage needs, coordinating applications and renewals with Finance and brokers, validating required security controls, monitoring policy requirements and exclusions, supporting claims, and advising leadership on coverage and gaps.
Team Leadership
- Build and lead the technology function as it grows, including future tier-one support, data, and security roles.
- Supervise the Director of Technical Systems, setting priorities and success metrics, conducting regular one-on-ones and performance reviews, and supporting professional development.
- Manage external contractors, consultants, and managed service providers that supplement internal capacity.
- Ensure appropriate separation of duties within a small team, so that no single person is both the sole administrator of a critical system and the sole reviewer of its access and security changes.
- Ensure documentation and cross-training are maintained so that critical operational knowledge is not concentrated in any single individual.
Additional Notes
This is a full-time, fully remote position with occasional in-person meetings at the Digital Harbor Foundation office as needed to fulfill the responsibilities of the position.
Other Duties
Please note that this job description is not designed to cover or contain a comprehensive listing of activities, duties, or responsibilities that are required of the employee for this job. Duties, responsibilities, and activities may change at any time, with or without notice.
Compensation
Compensation for this full-time position is $155,000 - $190,000 annually, commensurate with experience. In exceptional cases, compensation outside of this range may be considered based on the candidate’s skills, experience, and overall fit.
Digital Harbor provides a best-in-class comprehensive set of benefits to support the team. All regular, full-time employees are eligible to receive:
Health Benefits & Insurance
- Carefirst Blue Cross Blue Shield - Health, Dental, and Vision Insurance (100% of the premium paid for employees and 85% of dependents)
- Pre-Tax Health Savings Account (HSA) (with $365 monthly employer contributions)
- Pre-Tax Flexible Savings Account (FSA)
- Paid Accidental Death & Dismemberment (AD&D) Insurance
- Paid Short-Term & Long-Term Disability Insurance
- Paid Basic Life Insurance
- Supplemental Voluntary Life Insurance (Employee, Spouse & Dependent Children)
- Total Pet Plan and Supplemental Wishbone Pet Insurance
- Employee Opportunity Program (EAP) - Health and Wellness
- Wellness Reimbursement Program
Retirement
- 401k Retirement Plan (with 6% matching)
Paid Time Off
- 15 Days Paid Time Off Per Year
- 20 Days Paid Time Off Per Year (after 3rd Anniversary)
- 25 Days Paid Time Off Per Year (after 6th Anniversary)
- 16 Paid Holidays (14 common plus 2 flexible holidays, including Dec 25 - Jan 1)
- Paid Bereavement Leave
- Paid Parental Leave for Moms and Dads (two weeks after first year)
If our mission and vision align with your personal values, please apply!
A cover letter outlining your qualifications for the position along with your resume is required. Interviews will be conducted virtually.
Digital Harbor is an equal opportunity employer.
For questions about the responsibilities of this role, please reach out to Brent Watkins, Chief Technology Officer, by email at [email protected].