The Role
Leads global IT, cybersecurity, information governance, business systems, resilience, and technology strategy across the UK and US. Owns infrastructure, cloud services, identity and access, security operations, incident response, business continuity, compliance controls, vendor performance, technology budgets, and executive risk advising. The role also oversees enterprise applications, integrations, AI governance, data protection, reporting, and managed-service providers.
Summary Generated by Built In
SUMMARY
As the Director, Information Technology & Security you will be the senior leader accountable for Civia Health’s technology operations, cyber security, information governance and business systems across the UK and US. You will create a secure, resilient and scalable technology environment that enables growth, protects participant and company information, supports regulatory compliance and improves the day-to-day experience of Civia colleagues. This is a broad, high-impact role that owns the strategy and operating model for IT, cyber security, resilience, business systems and technology governance, while building trusted relationships across the executive team, sites, functions and external partners.
KEY RESPONSIBILITIES
Primary Projects & Outcomes
• Create and execute a multi-year technology, cyber security and resilience roadmap aligned with Civia’s growth strategy.
• Consolidate UK and US IT operations, partners, service levels and governance into a clear global operating model.
• Strengthen identity, device, access, data protection, security testing, incident response and business continuity controls.
• Improve integration, adoption and training across core business systems, telephony, call-centre and clinical support platforms.
• Establish proportionate governance for AI, enterprise data, reporting and future data-warehousing capabilities.
Core Accountabilities
• Lead enterprise IT strategy, infrastructure, cloud services, end-user support, device management and service performance.
• Own cyber security strategy, identity and access management, vulnerability management, penetration testing, incident response and security awareness.
• Maintain IT policies, procedures, acceptable-use and content controls, and the evidence required for audit or inspection.
• Lead business continuity and disaster recovery planning, testing, remediation and executive reporting.
• Manage business systems architecture, integrations, telephony and call-centre platforms, vendor performance, licensing and technology budgets.
• Provide practical governance for approved AI use, data access, retention, classification and enterprise reporting.
• Act as a credible executive adviser on technology investment, operational risk, resilience and digital opportunity.
• Travel to Civia locations and partner sites in the UK and US as business needs require.
EDUCATION AND EXPERIENCE
Required Education and Experience
• 10+ years of progressive technology leadership experience, including responsibility for both IT operations and information security.
• Experience operating in healthcare, life sciences, clinical research or another regulated, data-sensitive environment.
• Proven ownership of cyber security, identity and access, endpoint management, incident response, business continuity and disaster recovery.
• Experience leading cloud and Microsoft 365 environments, enterprise applications, integrations and external managed-service providers.
• Demonstrable ability to translate technical risk into concise commercial advice for executives and boards.
• Experience managing technology budgets, vendor contracts, service levels and multiple priorities across a growing organisation.
• Working knowledge of UK GDPR and data-protection obligations, with the ability to partner effectively with privacy, legal, quality and compliance specialists.
• Willingness to operate at both strategic and hands-on levels in a fast-moving, international business.
Preferred Experience
• Experience supporting operations across both the UK and US.
• Knowledge of GxP, clinical trial systems, health data, sponsor audits or regulated research operations.
• Experience establishing AI governance, enterprise data standards or analytics platforms.
• CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor or a comparable professional qualification.
• Experience supporting acquisitions, new-site integration or rapid organisational scaling.
As the Director, Information Technology & Security you will be the senior leader accountable for Civia Health’s technology operations, cyber security, information governance and business systems across the UK and US. You will create a secure, resilient and scalable technology environment that enables growth, protects participant and company information, supports regulatory compliance and improves the day-to-day experience of Civia colleagues. This is a broad, high-impact role that owns the strategy and operating model for IT, cyber security, resilience, business systems and technology governance, while building trusted relationships across the executive team, sites, functions and external partners.
KEY RESPONSIBILITIES
Primary Projects & Outcomes
• Create and execute a multi-year technology, cyber security and resilience roadmap aligned with Civia’s growth strategy.
• Consolidate UK and US IT operations, partners, service levels and governance into a clear global operating model.
• Strengthen identity, device, access, data protection, security testing, incident response and business continuity controls.
• Improve integration, adoption and training across core business systems, telephony, call-centre and clinical support platforms.
• Establish proportionate governance for AI, enterprise data, reporting and future data-warehousing capabilities.
Core Accountabilities
• Lead enterprise IT strategy, infrastructure, cloud services, end-user support, device management and service performance.
• Own cyber security strategy, identity and access management, vulnerability management, penetration testing, incident response and security awareness.
• Maintain IT policies, procedures, acceptable-use and content controls, and the evidence required for audit or inspection.
• Lead business continuity and disaster recovery planning, testing, remediation and executive reporting.
• Manage business systems architecture, integrations, telephony and call-centre platforms, vendor performance, licensing and technology budgets.
• Provide practical governance for approved AI use, data access, retention, classification and enterprise reporting.
• Act as a credible executive adviser on technology investment, operational risk, resilience and digital opportunity.
• Travel to Civia locations and partner sites in the UK and US as business needs require.
EDUCATION AND EXPERIENCE
Required Education and Experience
• 10+ years of progressive technology leadership experience, including responsibility for both IT operations and information security.
• Experience operating in healthcare, life sciences, clinical research or another regulated, data-sensitive environment.
• Proven ownership of cyber security, identity and access, endpoint management, incident response, business continuity and disaster recovery.
• Experience leading cloud and Microsoft 365 environments, enterprise applications, integrations and external managed-service providers.
• Demonstrable ability to translate technical risk into concise commercial advice for executives and boards.
• Experience managing technology budgets, vendor contracts, service levels and multiple priorities across a growing organisation.
• Working knowledge of UK GDPR and data-protection obligations, with the ability to partner effectively with privacy, legal, quality and compliance specialists.
• Willingness to operate at both strategic and hands-on levels in a fast-moving, international business.
Preferred Experience
• Experience supporting operations across both the UK and US.
• Knowledge of GxP, clinical trial systems, health data, sponsor audits or regulated research operations.
• Experience establishing AI governance, enterprise data standards or analytics platforms.
• CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor or a comparable professional qualification.
• Experience supporting acquisitions, new-site integration or rapid organisational scaling.
Skills Required
- 10+ years of progressive technology leadership experience, including responsibility for IT operations and information security
- Experience in healthcare, life sciences, clinical research, or another regulated, data-sensitive environment
- Experience owning cybersecurity, identity and access management, endpoint management, incident response, business continuity, and disaster recovery
- Experience leading cloud and Microsoft 365 environments, enterprise applications, integrations, and external managed-service providers
- Ability to translate technical risk into concise commercial advice for executives and boards
- Experience managing technology budgets, vendor contracts, service levels, and multiple priorities across a growing organization
- Working knowledge of UK GDPR and data-protection obligations
- Willingness to operate at strategic and hands-on levels in a fast-moving, international business
- Experience supporting operations across both the UK and US
- Knowledge of GxP, clinical trial systems, health data, sponsor audits, or regulated research operations
- Experience establishing AI governance, enterprise data standards, or analytics platforms
- CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, or comparable professional qualification
- Experience supporting acquisitions, new-site integration, or rapid organizational scaling
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
Civia Health is a clinical study network and digital platform that specializes in high-performance site management and patient recruitment for chronic ambulatory conditions. The company operates retail-based research sites and a participant registry, Thrive with Civia, to streamline recruitment using AI-enabled tools, aiming to make clinical trials more accessible and human-centered for underrepresented communities.







