Leads global IT, cybersecurity, information governance, business systems, resilience, and technology strategy across the UK and US. Owns infrastructure, cloud services, identity and access, security operations, incident response, business continuity, compliance controls, vendor performance, technology budgets, and executive risk advising. The role also oversees enterprise applications, integrations, AI governance, data protection, reporting, and managed-service providers.
SUMMARY
As the Director, Information Technology & Security you will be the senior leader accountable for Civia Health’s technology operations, cyber security, information governance and business systems across the UK and US. You will create a secure, resilient and scalable technology environment that enables growth, protects participant and company information, supports regulatory compliance and improves the day-to-day experience of Civia colleagues. This is a broad, high-impact role that owns the strategy and operating model for IT, cyber security, resilience, business systems and technology governance, while building trusted relationships across the executive team, sites, functions and external partners.
KEY RESPONSIBILITIES
Primary Projects & Outcomes
• Create and execute a multi-year technology, cyber security and resilience roadmap aligned with Civia’s growth strategy.
• Consolidate UK and US IT operations, partners, service levels and governance into a clear global operating model.
• Strengthen identity, device, access, data protection, security testing, incident response and business continuity controls.
• Improve integration, adoption and training across core business systems, telephony, call-centre and clinical support platforms.
• Establish proportionate governance for AI, enterprise data, reporting and future data-warehousing capabilities.
Core Accountabilities
• Lead enterprise IT strategy, infrastructure, cloud services, end-user support, device management and service performance.
• Own cyber security strategy, identity and access management, vulnerability management, penetration testing, incident response and security awareness.
• Maintain IT policies, procedures, acceptable-use and content controls, and the evidence required for audit or inspection.
• Lead business continuity and disaster recovery planning, testing, remediation and executive reporting.
• Manage business systems architecture, integrations, telephony and call-centre platforms, vendor performance, licensing and technology budgets.
• Provide practical governance for approved AI use, data access, retention, classification and enterprise reporting.
• Act as a credible executive adviser on technology investment, operational risk, resilience and digital opportunity.
• Travel to Civia locations and partner sites in the UK and US as business needs require.
EDUCATION AND EXPERIENCE
Required Education and Experience
• 10+ years of progressive technology leadership experience, including responsibility for both IT operations and information security.
• Experience operating in healthcare, life sciences, clinical research or another regulated, data-sensitive environment.
• Proven ownership of cyber security, identity and access, endpoint management, incident response, business continuity and disaster recovery.
• Experience leading cloud and Microsoft 365 environments, enterprise applications, integrations and external managed-service providers.
• Demonstrable ability to translate technical risk into concise commercial advice for executives and boards.
• Experience managing technology budgets, vendor contracts, service levels and multiple priorities across a growing organisation.
• Working knowledge of UK GDPR and data-protection obligations, with the ability to partner effectively with privacy, legal, quality and compliance specialists.
• Willingness to operate at both strategic and hands-on levels in a fast-moving, international business.
Preferred Experience
• Experience supporting operations across both the UK and US.
• Knowledge of GxP, clinical trial systems, health data, sponsor audits or regulated research operations.
• Experience establishing AI governance, enterprise data standards or analytics platforms.
• CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor or a comparable professional qualification.
• Experience supporting acquisitions, new-site integration or rapid organisational scaling.
As the Director, Information Technology & Security you will be the senior leader accountable for Civia Health’s technology operations, cyber security, information governance and business systems across the UK and US. You will create a secure, resilient and scalable technology environment that enables growth, protects participant and company information, supports regulatory compliance and improves the day-to-day experience of Civia colleagues. This is a broad, high-impact role that owns the strategy and operating model for IT, cyber security, resilience, business systems and technology governance, while building trusted relationships across the executive team, sites, functions and external partners.
KEY RESPONSIBILITIES
Primary Projects & Outcomes
• Create and execute a multi-year technology, cyber security and resilience roadmap aligned with Civia’s growth strategy.
• Consolidate UK and US IT operations, partners, service levels and governance into a clear global operating model.
• Strengthen identity, device, access, data protection, security testing, incident response and business continuity controls.
• Improve integration, adoption and training across core business systems, telephony, call-centre and clinical support platforms.
• Establish proportionate governance for AI, enterprise data, reporting and future data-warehousing capabilities.
Core Accountabilities
• Lead enterprise IT strategy, infrastructure, cloud services, end-user support, device management and service performance.
• Own cyber security strategy, identity and access management, vulnerability management, penetration testing, incident response and security awareness.
• Maintain IT policies, procedures, acceptable-use and content controls, and the evidence required for audit or inspection.
• Lead business continuity and disaster recovery planning, testing, remediation and executive reporting.
• Manage business systems architecture, integrations, telephony and call-centre platforms, vendor performance, licensing and technology budgets.
• Provide practical governance for approved AI use, data access, retention, classification and enterprise reporting.
• Act as a credible executive adviser on technology investment, operational risk, resilience and digital opportunity.
• Travel to Civia locations and partner sites in the UK and US as business needs require.
EDUCATION AND EXPERIENCE
Required Education and Experience
• 10+ years of progressive technology leadership experience, including responsibility for both IT operations and information security.
• Experience operating in healthcare, life sciences, clinical research or another regulated, data-sensitive environment.
• Proven ownership of cyber security, identity and access, endpoint management, incident response, business continuity and disaster recovery.
• Experience leading cloud and Microsoft 365 environments, enterprise applications, integrations and external managed-service providers.
• Demonstrable ability to translate technical risk into concise commercial advice for executives and boards.
• Experience managing technology budgets, vendor contracts, service levels and multiple priorities across a growing organisation.
• Working knowledge of UK GDPR and data-protection obligations, with the ability to partner effectively with privacy, legal, quality and compliance specialists.
• Willingness to operate at both strategic and hands-on levels in a fast-moving, international business.
Preferred Experience
• Experience supporting operations across both the UK and US.
• Knowledge of GxP, clinical trial systems, health data, sponsor audits or regulated research operations.
• Experience establishing AI governance, enterprise data standards or analytics platforms.
• CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor or a comparable professional qualification.
• Experience supporting acquisitions, new-site integration or rapid organisational scaling.
Similar Jobs
Cloud • Security • Software • Cybersecurity • Automation
Design and evolve high-scale backend capabilities for GitLab’s container registry. Drive architecture, performance, reliability, security, APIs, testing, and operational readiness. Mentor engineers, influence technical direction, participate in incident response, and collaborate asynchronously across product, infrastructure, data, frontend, and security teams. Integrate and evaluate agentic AI systems in production engineering workflows while promoting responsible and effective use.
Top Skills:
AIAPIsBackend ArchitectureContainer RegistryData SystemsDevOpsDevsecopsModular MonolithsSystems Programming
Cloud • Software
Designs, deploys, and operates highly available, secure, multi-region cloud platforms. Responsibilities include managing AWS and Kubernetes services, automating production operations, improving reliability and scalability, participating in 24x7 incident response, and developing tooling for deployment, testing, failure recovery, and platform security. The role collaborates with application engineering teams and requires Linux administration, Python or Go development, container security, and CI/CD automation experience.
Top Skills:
ArgocdAWSCi/CdCncfDastDnsGoHTTPKubernetesLinuxOpentelemetryPrometheusPythonSastService MeshTcp/IpUnix
Cloud • Information Technology • Productivity • Security • Software • App development • Automation
Conduct outbound prospecting and qualify leads in the DACH strategic market through cold calls, personalized emails, and research. Build pipeline, convert meetings, handle objections, communicate product value, and collaborate with sales, marketing, partner, and operations teams. Use Salesforce, Gong, Outreach, LinkedIn Navigator, and AI to improve prospecting effectiveness. The role requires fluent English and German, strong communication skills, accountability, adaptability, and 1–2 years of SDR or inside sales experience preferred.
Top Skills:
Artificial IntelligenceGongLinkedin NavigatorOutreachSalesforce
What you need to know about the Edinburgh Tech Scene
From traditional pubs and centuries-old universities to sleek shopping malls and glass-paneled office buildings, Edinburgh's architecture reflects its unique blend of history and modernity. But the fusion of past and future isn't just visible in its buildings; it's also shaping the city's economy. Named the United Kingdom's leading technology ecosystem outside of London, Edinburgh plays host to major global companies like Apple and Adobe, as well as a growing number of innovative startups in fields like cybersecurity, finance and healthcare.



